
Application Security Engineer
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Integrate security measures into the SaaS platform to facilitate the swift delivery of secure features.
• Collaborate with software, DevOps, and platform teams.
• Liaise with audit partners.
• Incorporate threat modeling, automated SAST/SCA/DAST, and prompt vulnerability response throughout the software development lifecycle (SDLC).
• Implement and deploy SAST, SCA, secrets scanning, DAST, and container/IaC checks within CI/CD processes.
• Conduct threat modeling sessions, review critical pull requests (PRs), and mentor development teams on secure-by-default practices.
• Promote early detection of vulnerabilities and facilitate remediation in the SDLC.
• Address application security concerns that span both application and infrastructure layers in collaboration with DevOps.
• Assist in incident response and integrate lessons learned into code, documentation, and processes.
• Safeguard customer data, achieve compliance milestones, and enhance the overall security posture.
• Over 5 years of experience in Application/Product Security.
• Practical experience in securing web applications and automating AppSec workflows.
• Understanding of DevSecOps practices as well as container security and patching.
• Proficiency with GitHub Actions, Python, TypeScript, and JavaScript.
• Effective communicator capable of translating risk concepts for engineers.
• Health, dental, and vision insurance.
• 100% remote - work from anywhere in the US.
• 401k matching.
• Mental health benefits.
• Flexible work environment - you control your workday.
• Reimbursement for pet and child care during travel.
• Unlimited PTO.
• Equity.
3M
Lenze
Compose.ly
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.