
Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Manage the daily operations of application security vulnerability oversight.
• Assess findings from SAST, SCA, DAST, and mobile security tools.
• Determine severity levels and due dates, recommend remediation strategies, and facilitate ticket resolutions through the SVM process.
• Oversee and expand the bug bounty program, which includes defining engagement scopes, evaluating researcher submissions, confirming findings, and collaborating with vendors.
• Leverage AI and automated tools to expedite vulnerability assessment, enhancement, automated remediation assistance, and secure AI-driven development.
• Develop and sustain security automation using SOAR platforms and Python.
• Standardize vulnerability intake, manage notifications and SLAs, and generate program metrics and reports.
• Collaborate with product engineering teams on remediation efforts and engage in triage and refinement discussions.
• Conduct security evaluations for new features, services, and third-party integrations.
• Offer practical, risk-focused security guidance.
• Promote secure coding practices and assist in the creation of security documentation and training for developers.
• Manage and optimize application security tools throughout the SDLC.
• Assess and adopt new security technologies.
• Aid in identity and access management processes and their associated automation.
• 2–4 years of experience in security engineering, application security, software engineering, or a comparable role.
• Familiarity with application security assessment methods, including SAST, DAST, SCA, and penetration testing.
• Understanding of secure development protocols for web and mobile applications, including OWASP Top 10 and OWASP MASVS.
• Experience with AI-driven or agent-assisted tools, AI coding assistants, LLM-powered workflows, or automated agentic solutions.
• Proven experience in security triage, investigation, and vulnerability management.
• Knowledge of auto-scaling cloud microservices, containerization, Kubernetes, and infrastructure as code.
• Strong communication skills and ability to collaborate across functions.
• Capable of producing clear technical documentation for both technical and non-technical audiences.
• Eager and capable of quickly learning new product lines and technologies.
• Educational background equivalent to a BS in Computer Science or an information systems-related field.
• Certifications such as GIAC, OSCP, CSSLP, Security+, or vendor-specific credentials are advantageous.
• Experience in automating security processes using Python, SOAR platforms, or workflow automation is highly preferred.
• Familiarity with security scanning in CI/CD pipelines and orchestration tools like GitHub Actions is a plus.
• Previous experience managing or triaging a bug bounty program is a plus.
• Comprehensive healthcare benefits, including medical, dental, and vision coverage.
• Parental planning support and paid maternity and paternity leave.
• Mental health benefits along with dedicated mental health days.
• Annual performance-based bonuses.
• 401(k) retirement plan with employer matching contributions.
• Responsible Time Off flexible leave policy.
• Two volunteer days off each calendar year for full-time employees.
• Monthly wellness allowance.
• Monthly technology allowance.
• Opportunities for face-to-face team bonding and an annual company gathering.
• Mentorship program available.
• Assistance related to fertility.
• Peer recognition and rewards platform.
• Access to MyFitnessPal Premium.
• Virtual learning and development resources.
• Training opportunities provided.
• Commitment to an inclusive workplace and DEI initiatives.
Medtronic
Tekpoint GmbH
SMT Inc.
Nord Security
Get handpicked remote jobs straight to your inbox weekly.