Staff Application Security Engineer

Posted Aug 7

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee and enhance the organization's application security strategy, roadmap, and daily operations.

• Act as the key AppSec collaborator for development teams focusing on Ruby on Rails web applications, React Native mobile applications, as well as Python and Go projects.

• Offer security advice throughout the design, development, and code review processes.

• Promote secure coding practices and threat modeling within engineering teams.

• Administer and optimize tools such as GitHub Advanced Security, Invicti, Hadrian, AppDome, and Cloudflare WAF.

• Enhance automation of security tools and integration within CI/CD pipelines.

• Develop secure development standards, playbooks, and training resources.

• Collaborate with engineering teams during sprint planning and feature design to proactively manage risks.

• Execute security reviews, code assessments, and vulnerability triage.

• Work alongside DevOps to ensure secure deployments and configurations within AWS infrastructure.

• Strengthen ECS, IAM, networking, and associated cloud services.

• Create and maintain secure CI/CD workflows.

• Lead or assist in the investigation and resolution of application-level vulnerabilities.

• Monitor, prioritize, and manage SAST, DAST, and ASM findings.

• Partner with engineering for prompt and effective remediation of issues.


⛳️ Requirements

• Over 8 years of experience in Application Security, Product Security, or similar engineering positions.

• Solid understanding of secure coding methodologies, OWASP Top 10, and contemporary SDLC.

• Proficient in cloud-native application environments, preferably AWS.

• Knowledge of SSL certificates and the management of cryptographic keys.

• Practical experience with SAST, DAST, WAFs, and/or mobile application security tools.

• Capability to collaborate with developers and influence secure design choices.

• Familiar with GitHub workflows and CI/CD pipelines.

• Development background in Ruby on Rails or similar dynamic programming languages (preferred).

• Understanding of AWS ECS/EKS, container security, secrets management, and infrastructure-as-code using CloudFormation or Terraform (preferred).

• Experience in establishing or advancing an AppSec program from its inception (preferred).

• Familiarity with SOAR automation and scripting (preferred).

• Experience in a PCI-compliant setting with annual reporting requirements (preferred).


🏝️ Benefits

• Significant employer contributions towards health, dental, and vision insurance plans.

• Generous paid time off (PTO), paid holidays, and parental leave.

• 401(k) matching program.

• Opportunities for merit-based advancement.

• Career development and training opportunities.

• Eligibility for annual bonuses.

• Supportive and collaborative workplace culture.

• A sense of community, connection, and belonging throughout the organization.

People also viewed

Lumentum1 day ago

Field Application Engineer

US flagWashington OnlyFull-timeApplication Engineer$149.9k – $214.2k/year
ApplyView job
Peraton1 day ago

Senior Platform Engineer – Application Enablement Lead

US flagUnited States OnlyFull-timeApplication Engineer$112k – $179k/year
ApplyView job
3M1 day ago

Field Application Engineer – High Speed Interconnects

US flagMinnesota OnlyFull-timeApplication Engineer$145.7k – $178k/year
ApplyView job
ITW3 days ago

Applications Engineer – Mold Release

US flagOhio OnlyFull-timeApplication Engineer$115k/year
ApplyView job
Eversheds Sutherland4 days ago

IT Engineer, Applications

US flagUnited States OnlyFull-timeApplication Engineer$90k – $130k/year
ApplyView job
ITW4 days ago

Applications Engineer – Mold Release

US flagIllinois, +3 more statesFull-timeApplication Engineer$115k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers