
Senior Application Security Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Texas.
• Report directly to the Chief Information Security Officer while collaborating with software development and production operations teams across 10 SaaS platforms.
• Design and implement software security tools and integrate security measures into the software development lifecycle.
• Lead projects and initiatives aimed at enhancing security within application development processes.
• Assess and optimize security tools, investigating technologies that can bolster security posture and scalability.
• Perform internal penetration testing and conduct thorough code reviews.
• Oversee and advance the vulnerability management program.
• Create, revise, and maintain threat models associated with software projects.
• Utilize AI to automate processes and enhance operational efficiencies.
• Provide guidance to software developers on secure coding techniques and strategies for vulnerability remediation.
• Develop and manage source-code analysis initiatives to detect and address vulnerabilities.
• Prepare security project and program status updates for stakeholders and leadership.
• Contribute to the development of security training materials and support internal software development teams.
• Lead responses to security incidents.
• Coordinate external penetration testing efforts and related mitigation strategies.
• Facilitate the integration of tools, provide stakeholder support for mitigation strategies, and work towards reducing security technical debt.
• 3-5 years of experience in scripting and development, ideally supporting web applications.
• 2-3 years of experience in cloud engineering, preferably utilizing Infrastructure as Code, with a focus on AWS.
• Familiarity with Claude AI and other AI tools, as well as leveraging agentic AI for automation purposes.
• Experience with NIST and HIPAA is advantageous.
• Proven ability to exercise sound judgment in evaluating and prioritizing technical risks.
• Understanding of security best practices and standards, including OWASP, OWASP ASVS, S-SDLC, and BSIMM.
• Strong communication skills, capable of conveying complex security concepts to both technical and non-technical stakeholders with an inclusive approach.
• Ability to identify and eliminate bottlenecks for team members in processes and technologies.
• Familiarity with a diverse range of security tools, technologies, and methodologies.
• Unlimited PTO policy.
• Competitive medical, dental, and vision healthcare coverage.
• 401k matching.
• Paid holidays.
• Volunteer time off.
• Paid parental leave.
• Remote work stipend.
3M
Lenze
Compose.ly
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.