Application Security Engineer
Core
Embed security throughout the software development lifecycle, lead application security testing, and protect cloud-native and SaaS applications against evolving threats.
Role type
Application Security Engineer (IC)
Builds
Secure cloud-native and SaaS applications
Domain
Cybersecurity / Software Development
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security testing (SAST, DAST, IAST), Threat modeling, Secure coding practices, OWASP Top 10 knowledge, CI/CD pipeline integration, Cloud-native environments, Vulnerability assessment and remediation, Secure design principles
Preferred skills
Security certifications (Security+, GSEC, GSSP), Bachelor's degree in CS/Cybersecurity, Experience with C#, Go, Java, JavaScript, or Python, AI tool usage for security analysis
Technologies
SAST, DAST, IAST, CI/CD pipelines, Cloud-native platforms, AI security tools
Responsibilities
Perform security code reviews, threat modeling, and architecture reviews; Partner with engineering teams to integrate secure design principles; Lead application security testing activities; Identify, document, track, and validate security vulnerabilities; Coordinate external penetration testing; Integrate security practices into code review and change management; Promote secure development practices across technical teams
Seniority
Mid-level (3–7 years experience), hands-on IC