Cybersecurity Application Security Engineer
Core
Application Security Engineer responsible for secure code review, penetration testing, automation, and safeguarding applications and AI/LLM components from design through production.
Role type
Application Security Engineer (AppSec)
Builds
Secure applications, services, and AI-driven components
Domain
Fintech / Education / Cybersecurity
Deliverable
production ML models | product features
Required skills
Manual source code review, SAST/DAST scanning, threat modeling (STRIDE, attack trees), CI/CD pipeline integration, scripting/automation (Python, Bash, Node), AI/LLM security (prompt injection, RAG vulnerabilities), web/API security concepts
Preferred skills
Secure code review tooling development, mobile security, reverse engineering, security certifications (OSWE, OSCP, GWAPT, GCSA, GCPN), mentoring developers
Technologies
Java, JavaScript/TypeScript, C#, PHP, Python, Bash, Node, SAST, SCA, DAST, container scanners, secrets-detection tools, AI-security scanning platforms
Responsibilities
Perform manual source code review, execute SAST/DAST scanning, expand Security Champions program, develop automated source code review processes, collaborate with product teams on secure SDLC, provide detailed vulnerability reports
Seniority
Mid-level, hands-on IC
