Sr. Application Security Engineer
JobgetherRemote · US
At a glance
- Location
- Remote · US
- Workplace
- Remote
- Pay
- $104K – $194K (from listing text)
- Employment type
- Full time
- Experience
- 3+ years
- Education
- No degree requirement stated
- Job family
- Security and safety
- Seniority
- Senior
- Posted by employer
- 7 September 2026
- Last verified open
- 7 September 2026
- Work from
- US
- Region and country
- US
- Team
- Security & IT
- Listed via
- Lever
What the employer wrote
Accountabilities: • Partner with DevOps and engineering teams to design, implement, and maintain secure CI/CD pipelines with security controls and testing integrated throughout the software development lifecycle.
• Implement, configure, and continuously improve automated security testing, including SAST, DAST, software composition analysis (SCA), vulnerability scanning, and container security.
• Deploy and support API security solutions while ensuring security findings are consistently captured, centralized, tracked, and addressed.
• Collaborate with development teams to promote secure coding practices and provide practical security guidance throughout application design, development, testing, and deployment.
• Establish and strengthen application security practices for cloud-native environments, including appropriate controls for identity, networking, encryption, secrets, and infrastructure.
• Evaluate the secure adoption of agentic and AI-assisted coding tools across engineering teams and establish appropriate guardrails, governance, detection, and risk-mitigation strategies.
• Identify and address AI-specific application security risks, including hallucinated or vulnerable dependencies, insecure code generation, malicious code injection, and insufficient human oversight.
• Support compliance with applicable security and privacy standards, including PCI-DSS, GDPR, CCPA, and SOC 2.
• Develop application security KPIs, metrics, dashboards, and reporting to demonstrate program effectiveness and communicate findings to leadership.
• Conduct or support threat modeling, security assessments, penetration testing, and risk analysis across applications and technology environments.
• Contribute to security architecture decisions and help engineering teams build resilient, secure applications and APIs.
• Mentor junior security engineers and developers while promoting a security-first culture across engineering organizations.
• Support emerging security initiatives involving AI/ML systems, model security, data pipeline protection, and AI/ML supply-chain risks.
• Stay current on application security threats, emerging technologies, development practices, and industry trends to continuously improve the security program.
Requirements
• 5+ years of professional software development experience, with strong proficiency in three or more programming or scripting languages such as Python, Go, Java, C#, Ruby, JavaScript/TypeScript, Bash, PowerShell, Swift, Kotlin, Objective-C, or Dart.
• 3+ years of hands-on experience in application security, DevSecOps, or a closely related security engineering discipline.
• Strong understanding of the OWASP Top 10 and modern secure software development practices.
• Deep knowledge of API security, authentication protocols, authorization, and secure API design.
• Strong cloud security expertise with at least one major cloud platform such as AWS, Azure, or GCP; multi-cloud experience is highly valuable.
• Understanding of cloud-native security concepts including IAM, network security, encryption, secrets management, workload protection, and compliance.
• Hands-on experience with CI/CD technologies such as Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or Azure DevOps.
• Experience with infrastructure-as-code, containerization, and orchestration technologies such as Terraform, Docker, Kubernetes, Helm, or Ansible.
• Familiarity with application security tools including SAST/DAST scanners, SCA solutions, WAFs, SIEM platforms, vulnerability scanners, and secrets-management technologies.
• Experience with AI-assisted or agentic development tools such as GitHub Copilot, Cursor, Claude Code, or similar technologies, along with a strong understanding of their security implications.
• Experience establishing governance and guardrails for safe adoption of AI-assisted software development tools.
• Knowledge of threat modeling methodologies, security risk assessment frameworks, and the ability to communicate technical risks effectively to both technical and non-technical stakeholders.
• Knowledge of compliance requirements and frameworks including PCI-DSS, GDPR, CCPA, and SOC 2.
• Background in penetration testing, red-team operations, or offensive security is highly valuable.
• Familiarity with MLSecOps, including model security, data pipeline protection, and AI/ML supply-chain security.
• Security certifications such as CISSP, GIAC, OSCP, AWS Security Specialty, Azure Security Engineer, or equivalent are advantageous.
• Experience in travel, hospitality, e-commerce, or another high-volume digital industry is a plus.
• Strong communication, mentoring, collaboration, and problem-solving skills, with the ability to influence engineering teams and promote security best practices.
• Ability to work independently while partnering effectively across engineering, DevOps, security, and other technology functions.
Benefits
• Base salary: $104,300–$193,700 USD annually, with actual compensation based on role scope, complexity, experience, skills, knowledge, and work location.
• Eligibility for a discretionary annual bonus based on individual and organizational performance.
• Comprehensive U.S. benefits programs covering health and welfare, retirement, parental leave, adoption assistance, and wellbeing resources.
• Flexible benefits designed to support employees and their families.
• Travel-related employee perks, including access to deals on flights, hotels, cruises, car rentals, and other travel services.
• Access to 20,000+ learning courses , leadership development programs, and ongoing professional development opportunities.
• Opportunities to grow technical and leadership skills within a collaborative global environment.
• Remote work opportunity within the United States.
• Inclusive workplace culture that values collaboration, diverse perspectives, and employee development.
• Reasonable accommodations available for qualified individuals with disabilities throughout the recruitment process.
• Opportunity to work with modern cloud-native technologies, application security tooling, DevSecOps practices, and emerging AI security capabilities.
• Opportunity to influence security strategy and help shape secure software development practices at scale.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
Where this record came from
Read from Jobgether's own Lever job board on , and last confirmed still open on . The employer published it on 7 September 2026. Jobsearch.ing did not write, edit or rank this posting, and does not vet the employer. View the original posting.
More roles like this one
Senior Security Operations Analyst (Detection & Response)
Point Digital Finance, Inc.
Remote · US
3 days ago