
Staff Application Security Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in United States.
• Oversee and enhance the organization's application security strategy, roadmap, and daily operations.
• Act as the key AppSec collaborator for development teams focusing on Ruby on Rails web applications, React Native mobile applications, as well as Python and Go projects.
• Offer security advice throughout the design, development, and code review processes.
• Promote secure coding practices and threat modeling within engineering teams.
• Administer and optimize tools such as GitHub Advanced Security, Invicti, Hadrian, AppDome, and Cloudflare WAF.
• Enhance automation of security tools and integration within CI/CD pipelines.
• Develop secure development standards, playbooks, and training resources.
• Collaborate with engineering teams during sprint planning and feature design to proactively manage risks.
• Execute security reviews, code assessments, and vulnerability triage.
• Work alongside DevOps to ensure secure deployments and configurations within AWS infrastructure.
• Strengthen ECS, IAM, networking, and associated cloud services.
• Create and maintain secure CI/CD workflows.
• Lead or assist in the investigation and resolution of application-level vulnerabilities.
• Monitor, prioritize, and manage SAST, DAST, and ASM findings.
• Partner with engineering for prompt and effective remediation of issues.
• Over 8 years of experience in Application Security, Product Security, or similar engineering positions.
• Solid understanding of secure coding methodologies, OWASP Top 10, and contemporary SDLC.
• Proficient in cloud-native application environments, preferably AWS.
• Knowledge of SSL certificates and the management of cryptographic keys.
• Practical experience with SAST, DAST, WAFs, and/or mobile application security tools.
• Capability to collaborate with developers and influence secure design choices.
• Familiar with GitHub workflows and CI/CD pipelines.
• Development background in Ruby on Rails or similar dynamic programming languages (preferred).
• Understanding of AWS ECS/EKS, container security, secrets management, and infrastructure-as-code using CloudFormation or Terraform (preferred).
• Experience in establishing or advancing an AppSec program from its inception (preferred).
• Familiarity with SOAR automation and scripting (preferred).
• Experience in a PCI-compliant setting with annual reporting requirements (preferred).
• Significant employer contributions towards health, dental, and vision insurance plans.
• Generous paid time off (PTO), paid holidays, and parental leave.
• 401(k) matching program.
• Opportunities for merit-based advancement.
• Career development and training opportunities.
• Eligibility for annual bonuses.
• Supportive and collaborative workplace culture.
• A sense of community, connection, and belonging throughout the organization.
Lumentum
Peraton
3M
ITW
Get handpicked remote jobs straight to your inbox weekly.