
Senior Application Security Engineer
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in Mexico.
• Oversee the advancement of Technosylva's Application Security program and its strategic roadmap.
• Define and enhance secure Software Development Life Cycle (SDLC) processes across all engineering teams.
• Implement security-by-design methodologies integrated into development workflows.
• Promote the adoption of secure coding standards, threat modeling, and conduct security architecture reviews.
• Develop measurable Application Security Key Performance Indicators (KPIs) and leadership reporting mechanisms.
• Enhance security capabilities and integrations within GitLab/GitHub, focusing on SAST, DAST, dependency scanning, container scanning, secrets detection, and Infrastructure as Code (IaC) security workflows.
• Integrate security into Continuous Integration/Continuous Deployment (CI/CD) pipelines and establish risk-based security gates and exception procedures.
• Collaborate with developers, architects, and technical leads to address vulnerabilities, convert security requirements into actionable tasks, and perform code reviews.
• Create application vulnerability management processes that encompass triage, business-risk prioritization, Service Level Agreements (SLAs), closure tracking, and executive reporting.
• Lead Application Security initiatives from planning to execution across Engineering, Infrastructure, Product, and Security teams.
• Generate documentation and implementation strategies.
• Provide secure coding guidance, workshops, awareness sessions, and mentorship for junior engineers.
• Serve as a trusted security advisor to both technical and non-technical stakeholders.
• A minimum of 10 years of experience in Application Security, Secure SDLC/DevSecOps, or Software Engineering/Security Engineering.
• Demonstrated success in driving Application Security programs within medium to large organizations in modern SDLC, cloud-native, and SaaS environments.
• In-depth technical knowledge of the OWASP Top 10, API security, multi-tenant application security, threat modeling, and security architecture reviews.
• Practical experience in securing CI/CD pipelines, including SAST/DAST, Software Composition Analysis (SCA), secrets management, container/Kubernetes security, and IaC security.
• Strong comprehension of software engineering practices and contemporary development frameworks/APIs.
• Capability to read and review production-grade code.
• Experience in project management, executive-level reporting, documentation practices, and prioritizing tasks based on business risk.
• Exceptional communication, coordination, and interpersonal abilities.
• High degree of ownership, autonomy, maturity, and proactive problem-solving skills.
• Preferred experience in penetration testing, red teaming, or offensive security.
• Experience in leading vulnerability management initiatives, security automation, and scripting is preferred.
• Practical experience with AI/ML tools in development and cybersecurity is a plus.
• Specialized knowledge of GitLab/GitHub Security features is preferred.
• Security certifications such as CSSLP, CISSP, OSCP, GIAC, or Azure/AWS certifications are preferred.
• Competitive annual salary.
• Private health insurance.
• Flexible benefits plan, enabling you to customize part of your compensation package to meet your personal needs.
• Annual bonus based on individual performance and company outcomes.
• Flexible working hours.
• Options for remote work.
Compose.ly
GE Vernova
GE Vernova
Navy Federal Credit Union
Get handpicked remote jobs straight to your inbox weekly.