
Application Security Engineer
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of and direct the vulnerability management lifecycle to ensure the technology stack remains devoid of known CVEs.
• Implement and oversee secure, fortified base OS images.
• Continuously perform scans, monitoring, and patching of open-source software dependencies.
• Investigate and assess open-source security solutions, including Google’s Assured Open Source Software.
• Incorporate SAST, DAST, and dependency-scanning tools into the CI/CD pipeline.
• Establish and uphold secure coding best practices.
• Create automated security validation tests to ensure vulnerability-free deployments.
• Spearhead the adoption of security solutions and develop tailored solutions as needed.
• Offer security guidance, training, and mentorship to engineering teams.
• Complete a brief AI-related exercise or discussion during the interview process.
• BA/BS in Computer Science, Cybersecurity, or a related discipline (or equivalent professional experience).
• Over 5 years of experience in application security and vulnerability management.
• Profound understanding of CVEs, OWASP Top 10, and supply chain vulnerabilities.
• Proficient with SAST, DAST, dependency scanning, and vulnerability management tools, including Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, or OWASP ZAP.
• Familiar with package managers such as npm, pip, Maven, and Go modules.
• Coding experience in Go, Python, Java, or C++.
• Practical experience with cloud-native security best practices across AWS, GCP, or Azure.
• Knowledgeable in container security, Kubernetes security, and securing microservices architectures.
• Ability to lead cross-functional initiatives and foster security adoption among engineering teams.
• Proactive in identifying security risks.
• Strong problem-solving skills and the capability to balance security with performance and usability.
• Experience in dynamic, highly collaborative environments.
• Enthusiastic about open-source security and current trends in vulnerability management.
• Medical coverage.
• Vision coverage.
• Dental coverage.
• Generous time-off policy.
• 401k plan contribution opportunity.
• Home office improvement stipend.
• Annual education stipend.
• Annual wellness stipend.
• Regular company events.
• Healthy lunches provided daily.
• Variable compensation may be available for certain positions.
• Equity may be available for certain positions.
Standard Bots
ARHS Group
Happy Cog
Get handpicked remote jobs straight to your inbox weekly.