
Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Implement and assist in the maintenance of secure development practices, incorporating code reviews and security testing within CI/CD pipelines.
• Identify, assess, and prioritize application vulnerabilities through both automated and manual testing methods.
• Support development teams in adopting secure coding methodologies and address findings through Shift Left initiatives.
• Contribute to the Security Champions program, including delivering training and addressing daily inquiries.
• Aid developers in reproducing vulnerabilities, conducting risk analyses, and providing remediation guidance.
• Elevate complex or high-risk issues to the Senior Application Security Engineer.
• Operate, fine-tune, and manage Application Security program tools, including open-source options.
• Collaborate with product, engineering, DevOps, and compliance teams to embed security requirements into application design.
• Assist incident response teams in investigating and resolving application-related security incidents.
• Engage in threat modeling exercises and security design reviews.
• Conduct recurring security testing and vulnerability assessments; maintain documentation and evidence of security controls.
• Apply secure design patterns to AI-enabled applications, including LLM integrations, RAG pipelines, and agentic workflows.
• Implement, configure, test, and monitor AI guardrails, such as prompt injection defenses, input/output filtering and validation, least-privilege scoping, and data loss prevention.
• Conduct AI/LLM red-team tests addressing prompt injection, jailbreaks, sensitive data disclosure, insecure output handling, and excessive agency.
• Document AI security findings and remediation guidance following OWASP Top 10 for LLM Applications and MITRE ATLAS.
• Assist in security reviews of new AI use cases and third-party AI features, ensuring controls over nonpublic personal information.
• Help enforce secure usage standards for AI coding assistants, including human review and scanning of AI-generated code.
• Stay updated on emerging application and AI security threats while supporting compliance and security awareness initiatives.
• Bachelor's degree in Computer Science, Software Engineering, Cyber Security, or a related field is preferred.
• A combination of education and experience may be considered in lieu of the Bachelor’s degree.
• A minimum of three years' experience in software development or a related field.
• Preferred qualifications include: Burp Suite Certified Practitioner, Hack the Box Certified Web Exploitation Specialist (HTB CWES), Practical Web Pentest Professional (PWPP).
• Strong ability to organize and manage multiple priorities simultaneously.
• Capable of working effectively both independently and as part of a team.
• Ability to handle sensitive matters with discretion.
• Excellent interpersonal communication skills.
• Strong verbal and written communication abilities.
• Highly organized and detail-oriented; adept at working in a fast-paced, metrics-driven environment.
• Proficiency in Microsoft Office Suite, including Word, Excel, Wiki, collaborative cloud-based programs, and various third-party software applications.
• Ability to learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions.
• Competence in operating standard office equipment and keyboards.
• Ability to accurately perceive, distinguish, and interpret visual and audio information.
• Availability to work primarily Monday through Friday during business hours.
• Willingness to travel 5% or less.
• Medical insurance
• Dental insurance
• Vision insurance
• Life insurance
• AD&D insurance
• LTD insurance
• 401(k) with employer match
• Competitive compensation
• Pleasant work environment
• Remote work from home
Intetics
New Charter Technologies
GE Vernova
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.