
Security Engineer, Application Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Act as the main security partner for the software engineering team.
• Oversee application security throughout the Software Development Life Cycle (SDLC).
• Advocate for secure design and development methodologies alongside DevSecOps practices.
• Establish security requirements for the safe and responsible integration of Gen AI and agentic AI tools.
• Conduct security-by-design sessions for features, APIs, platform initiatives, and infrastructure modifications.
• Execute secure code reviews and offer actionable insights and remediation strategies.
• Collaborate with architecture and platform teams to create secure REST and GraphQL API patterns.
• Uphold secure coding guidelines, API security standards, and security architectural frameworks.
• Produce documentation and facilitate engineering workshops or lunch-and-learn sessions.
• Integrate and sustain security tools within CI/CD pipelines.
• Enforce security quality gates and enhance the robustness of GitHub Actions and runner environments.
• Discover AI opportunities that boost engineering productivity and enhance agentic security workflows.
• Collaborate with DevOps to secure AWS infrastructure using Terraform, Kubernetes, and Infrastructure as Code (IaC).
• Apply and verify controls for containerized workloads.
• Assist in implementing Web Application Firewall (WAF) and Content Delivery Network (CDN) security controls to protect application endpoints.
• Manage the application's vulnerability management lifecycle.
• Assess and prioritize findings from GitHub Advanced Security (GHAS), NowSecure, Wiz, BugCrowd, and penetration tests.
• Identify systemic risks and promote cross-functional root-cause initiatives.
• Monitor security KPIs such as Mean Time to Recovery (MTTR), vulnerability density, and CI/CD security coverage.
• Convey security risks to engineering and business stakeholders.
• Participate in the weekly on-call rotation.
• Report to the Security Engineering Manager.
• Minimum of 3 years in application security engineering.
• Experience in developing and managing internal security developer platforms or tools that minimize developer friction.
• Capability to utilize AI/ML-driven tools to improve security effectiveness and scalability.
• Proven experience leading threat modeling engagements and designing paved roads.
• Familiarity with integrating security tools into CI/CD pipelines.
• Solid understanding of the OWASP Top 10 for web, mobile, API, and Large Language Models (LLM).
• Practical experience securing AWS deployments with container and Kubernetes security, IaC scanning, and policy-as-code methodologies.
• Proficiency in security-by-design principles using TypeScript, Swift, and/or Kotlin.
• Demonstrated success in implementing secure primitives within iOS/Android ecosystems.
• Preferred certifications include AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.
• Must reside in the United States, excluding AK, DE, HI, IA, LA, MS, MT, OK, and SC.
• Must have legal authorization to work in the United States.
• Must be at least 18 years of age.
• Work remotely across the US or from the modern office located in Manhattan, NY.
• Enjoy an unlimited vacation policy.
• Access to paid volunteer opportunities.
• Receive a technology stipend of $4,000 every two years.
• Get a work-from-home stipend of $500 annually.
• Monthly stipend for physical, mental, wellness, and learning opportunities through Holisticly.
• Monthly lifestyle stipend through Fringe.
• Comprehensive health benefits covering medical, dental, vision, prescription, FSA, HRA, HSA, and family/dependent coverage.
• Participate in Traditional and Roth 401K plans through Vanguard, with immediate company matching.
• Basic, supplemental, and dependent life insurance options available.
• Short-term and long-term disability coverage.
• Company-paid parental leave—up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.
• Family-building benefits provided through Progyny.
• Discounts available at DICK'S Sporting Goods and its family of brands.
• Incentives and equity are included in the total compensation package for eligible roles.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.