
Senior Application Security Engineer
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in California.
• Lead the application vulnerability remediation initiative by providing prioritized developer guidance and establishing clear Service Level Agreements (SLAs).
• Collaborate with development teams to clarify findings, validate solutions, and confirm remediation efforts.
• Promote systemic root-cause resolutions instead of addressing issues individually; escalate unresolved critical and high-risk vulnerabilities.
• Define and manage the Software Development Life Cycle (SDLC), including security checkpoints and reviews during sprint and release processes.
• Ensure that SAST, DAST, and SCA tools are properly configured, optimized, and generating actionable outputs for developers.
• Integrate security requirements into product planning and architectural decision-making.
• Conduct threat modeling of new features and architectural modifications prior to code development.
• Review designs related to authentication, authorization, data flow, and cryptographic risks.
• Create written threat models that act as guidance for developers and serve as evidence for audits.
• Manage API security standards, including OAuth 2.0, mTLS, rate limiting, and prevention of abuse.
• Perform or coordinate manual secure code reviews of components that are sensitive to security.
• Oversee application penetration testing cycles, including scoping, managing testers, and validating findings.
• Establish and maintain a Security Champions program across development teams.
• Provide developer training on OWASP Top 10 vulnerabilities and secure coding practices.
• Develop runbooks, coding standards, and pattern libraries that developers can utilize independently.
• Knowledge, skills, and abilities typically acquired through 5–8 years of experience in application/product security or security-oriented software engineering.
• Experience in application penetration testing, including business logic and API assessments.
• Practical experience in tuning and operationalizing SAST, DAST, and SCA tools.
• Secure code review experience in at least two web application programming languages.
• Proficiency in threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
• Strong understanding of the OWASP Top 10 and API security risks; capability to influence development teams effectively.
• Wellness: A range of universal, supplemental, and private healthcare plan options tailored to country-specific needs.
• Financial future: Contributions to retirement/pension plans and participation in the MTK stock plan.
• Income protection: Coverage for life events and disabilities.
• Paid time off: Generous annual leave, company holidays, and volunteer time off.
• Learning: Access to e-learning licenses, tuition reimbursement, and opportunities to participate in hackathons.
• Home office setup allowance.
• Additional/optional benefits: Options for pet insurance, identity theft protection, and legal assistance.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.