
Application Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Acting as a readily available contact for engineering teams, assisting them in comprehending and adhering to secure development lifecycle protocols.
• Aiding developers in the evaluation and analysis of alerts generated by static analysis and software composition analysis tools, including differentiating between genuine vulnerabilities and false positives.
• Offering clear and actionable advice for addressing common application security vulnerabilities, including those related to the OWASP Top 10.
• Assisting in the upkeep of internal security documentation, developer playbooks, and secure coding training resources to ensure compliance expectations are both clear and attainable.
• Supporting application security governance by monitoring key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
• Overseeing application security metrics, such as vulnerability patch timelines and policy exceptions, to facilitate regular reporting to leadership.
• Engaging with advanced GenAI tools and technologies while supporting AI governance frameworks and ensuring AI-enabled workflows comply with privacy and security guidelines.
• Significant experience in an information security role, software engineering position, or IT audit function with a focus on application security.
• A foundational comprehension of software development processes and the integration of security in agile environments.
• Familiarity with code review principles and the ability to read at least one major programming language commonly used in cloud settings, such as Python, JavaScript, Go, or Java.
• Basic exposure to cloud platforms such as AWS, GCP, or Azure, along with an understanding of Git workflows.
• A conceptual grasp of vulnerability classifications and web application security standards.
• A keen interest in emerging technology trends, particularly regarding AI security risks and automated workflows.
• Required: the capability to incorporate generative AI tools into everyday workflows to automate tasks, encourage innovation, and enhance productivity.
• A degree in Computer Science, Cybersecurity, or a related technical discipline is preferred, although equivalent hands-on experience or certifications such as Security+, GSEC, or CEH are also highly regarded.
• Exceptional communication abilities, humility, and a collaborative mindset for supporting stakeholders across engineering and security.
• Flexible work environment
• Unlimited Vacation
• 100% paid employee health benefit options (including medical, dental, and vision)
• 401(k) with employer funded match
• Corporate wellness program with Wellhub
• Sabbatical leave (for employees with 5+ years of service)
• Competitive paid parental leave and fertility/family planning reimbursement
• Cell phone reimbursement
• Employee Resource Groups and ZocClubs to promote shared community and belonging
• Great Place to Work Certified
Red River
Gainwell Technologies
Capital Project Intelligence
Jobs2web
Get handpicked remote jobs straight to your inbox weekly.