Skip to content

Open nowPosted 10 hours ago

Sr. Application Security Engineer

Jobgether4,394 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Application Security EngineerJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 10 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States.

This is a highly technical Application Security role focused on protecting software products, APIs, and cloud-native applications throughout the development lifecycle. You will work hands-on with Java, Python, and Go codebases to identify vulnerabilities, trace root causes, assess exploitability, and guide secure remediation. The role bridges Information Security and Engineering, giving you significant ownership while keeping you deeply connected to software development teams. You will help strengthen the Secure SDLC through security gates, threat modeling, automated controls, and developer-focused security workflows. The position also covers SAST, DAST, SCA, API security, dependency risk, cloud-native architectures, and hands-on vulnerability validation. Beyond addressing individual findings, you will build preventative controls and secure coding practices that reduce recurring vulnerability classes. This opportunity is ideal for an experienced Application Security professional who enjoys solving complex technical problems and influencing engineering teams through practical security expertise.

Accountabilities:

  • Perform hands-on security analysis of applications, APIs, services, and supporting components.
  • Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths.
  • Reproduce and validate vulnerabilities independently, assessing exploitability, reachability, exposure, data sensitivity, business criticality, and compensating controls.
  • Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure.
  • Maintain remediation SLAs and escalate unresolved Critical and High findings when appropriate.
  • Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities.
  • Mature security gates and review checkpoints across architecture, design, sprint, and release processes.
  • Integrate preventative security controls into developer workflows and CI/CD pipelines.
  • Configure, operate, and tune SAST, DAST, and SCA tooling to deliver actionable security feedback.
  • Assess software dependency and supply-chain risks using application context, reachability, exploitability, and remediation options.
  • Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies.
  • Review authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, data flows, trust boundaries, cryptographic controls, and abuse scenarios.
  • Evaluate application security across AWS, Kubernetes/EKS, containers, Linux/Ubuntu, distributed services, and cloud-native architectures.
  • Partner with Engineering as a technical advisor, providing clear and actionable remediation guidance.
  • Deliver secure-coding guidance and training based on real vulnerabilities and recurring security patterns.
  • Help establish and mature a Security Champions program across development teams.
  • Create security runbooks, standards, and reusable development patterns that teams can apply independently.
  • Validate application and API vulnerabilities through hands-on testing and coordinate external penetration-testing engagements.
  • Drive first-year improvements in vulnerability remediation, threat modeling, dependency security, secure development practices, and the overall effectiveness of the Application Security function.
  • 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
  • Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Strong hands-on coding and secure code review experience with Java, Python, and Go.
  • Ability to read, debug, and reason about production application code and communicate technical findings clearly to software engineers.
  • Proven ability to reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
  • Hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows.
  • Strong knowledge of software dependency and supply-chain security.
  • Experience prioritizing vulnerabilities based on application and business context rather than scanner severity alone.
  • Strong understanding of the OWASP Top 10 and OWASP API Security risks.
  • Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
  • Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
  • Strong communication and collaboration skills, with the ability to influence developers, architects, and engineering leadership.
  • Hands-on application and API penetration-testing experience is preferred.
  • Experience in financial services, fintech, identity, fraud, regulated SaaS, or other highly regulated environments is a plus.
  • Familiarity with PCI-DSS application security requirements is preferred.
  • Experience building or leading a Security Champions program is a plus.
  • Experience developing Application Security automation or internal security tooling is desirable.
  • OSCP, GWEB, CSSLP, or a similar technical security certification is preferred.
  • Salary: $130,000–$190,000 per year, with individual compensation varying based on experience, professional competencies, and geographic differentials.
  • Remote flexibility: A virtual-first working environment designed to support remote work from a home office as well as in-person collaboration.
  • Career growth: Opportunities for professional development, meaningful technical ownership, and work in an innovative, collaborative environment.
  • Healthcare: Universal, supplemental, or private healthcare plan options depending on geographic location.
  • Financial future: Retirement or pension contributions and participation in a stock plan.
  • Income protection: Life event and disability coverage.
  • Paid time off: Generous annual leave, company holidays, and volunteer time off.
  • Learning: E-learning resources, tuition reimbursement, and opportunities to participate in hackathons.
  • Home office: Home office setup allowance.
  • Additional benefits: Optional benefits may include pet insurance, identity theft protection, and legal assistance.
  • Technical scope: Exposure to internet-facing financial software, complex API integrations, cloud-native environments, and a dual US/EU regulatory context.
  • Visibility and ownership: Direct collaboration with senior Security and Engineering leadership and meaningful ownership of Application Security initiatives.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.