Senior Application Security Engineer
Core
Senior Application Security Engineer configuring, tuning, and operating SAST/SCA/Secret/DAST scanners and backend automation to integrate security into enterprise CI/CD pipelines.
Role type
Senior IC application security engineer (web/API security)
Builds
Automated security scanning pipelines, centralized findings management, and remediation workflows for web applications and APIs
Domain
Enterprise software development, application security, CI/CD integration
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SAST/SCA/Secrets/DAST configuration and tuning, manual triage of security findings, web/API security reviews (OWASP Top 10 & API Top 10), Python/Go for automation, CI/CD integration (GitHub Actions, GitLab, Jenkins), backend service development, cloud/container platforms (AWS, Azure, GCP, Docker, Kubernetes), API security (OAuth 2.0, JWT, OpenID Connect)
Preferred skills
Mobile application security tooling and integrations
Technologies
Burp Suite, Postman, curl, GitHub Actions, GitLab CI/CD, Azure DevOps, Jenkins, CircleCI, AWS, Azure, GCP, Docker, Kubernetes, REST APIs, webhooks, queues, databases
Responsibilities
Configure and tune SAST/SCA/Secret/DAST scanning tools and DAST profiles; manually triage findings, reproduce issues, and assess exploitability; perform targeted security reviews of web apps and APIs; develop and maintain SAST rules, policies, and quality gates; integrate security scanning into CI/CD and developer workflows; build and support backend automation for scan orchestration and result normalization; establish risk-based prioritization and remediation workflows; develop metrics and KPIs for platform reliability and scan coverage
Seniority
Senior, hands-on IC