
Application Security Engineer
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in United States.
• Perform secure code evaluations on application logic, API endpoints, CMS modules, and backend integrations.
• Execute API security assessments focusing on authentication, authorization, data handling, and boundary protections.
• Assist in hardening CMS by examining templates, modules, configurations, and custom components.
• Embed security requirements into CI/CD pipelines utilizing SAST/DAST tools, dependency scanning, and automated controls.
• Oversee secrets management, encryption policies, and the secure storage of API keys, tokens, and credentials.
• Carry out static and dynamic application security testing alongside vulnerability assessments.
• Confirm the remediation of vulnerabilities.
• Offer secure coding advice to developers, architects, and product teams.
• Work collaboratively with DevSecOps and cloud engineers to establish secure build and deployment practices.
• Conduct threat modeling and suggest mitigations for high-risk application features.
• Review and verify authentication processes, SSO integrations, and identity protections.
• Aid in security documentation, which includes test outcomes, remediation plans, and secure configuration records.
• Facilitate ongoing monitoring, log analysis, and triage of application-layer security alerts.
• Engage in sprint teams, code review cycles, and architectural discussions to integrate security from the outset.
• Must possess an active Top Secret clearance, backed by a Tier 5 background investigation.
• Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related technical discipline.
• At least 7 years of experience in application security engineering, secure software development, or cybersecurity.
• Experience in conducting code reviews, application penetration testing, or API security testing.
• Familiarity with static and dynamic testing tools, dependency scanning, and software composition analysis.
• Experience in integrating secure CI/CD pipelines and implementing DevSecOps practices.
• Proficiency in secure secrets management, encryption, and authentication protections.
• Strong knowledge of OWASP Top 10, secure coding principles, and application-layer attack vectors.
• Experience with SAST/DAST tools, dependency scanners, and workflows for code review.
• Understanding of API security, token-based authentication, and secure data handling methodologies.
• Familiarity with CMS architectures, template security, and module-level risk assessments.
• Knowledge of identity and access management, certificate management, and secure authentication flows.
• Required certification: Security+ or CISSP or CCSP.
• Preferred: AWS Security Specialty; GIAC secure coding or cloud security certifications; Certified Ethical Hacker (CEH).
• Preferred experience with AWS cloud-native application security tools, container security, Kubernetes workload protections, microservices security, modern CI/CD platforms, and DevSecOps automation.
• Strong analytical and problem-solving abilities.
• Capability to communicate technical risks, secure coding advice, and remediation suggestions clearly.
• High attention to detail.
• Ability to collaborate effectively with developers, cloud engineers, PMO personnel, and mission stakeholders.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Retirement savings plans with company matching.
• Opportunities for professional development and certifications.
• Flexible work hours and remote work options.
• A collaborative and inclusive company culture.
PowerSchool
PowerSchool
Thermal Scientific Works
Shure Incorporated
Get handpicked remote jobs straight to your inbox weekly.