Staff Application Security Engineer

atShield AIRemoteUS flagUnited StatesFull-timeApplication EngineerLead$143k – $214k/year

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Establish, uphold, and continually enhance secure SDLC policies, standards, control objectives, procedures, and the required supporting evidence across the organization.

• Convert security policies into clear, actionable requirements for development, product, and platform teams.

• Evaluate the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and guide improvement roadmaps.

• Create secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and materials to empower developers.

• Collaborate with development teams to identify, triage, prioritize, remediate, and verify findings related to application security.

• Assess, implement, optimize, and operationalize security tools such as SAST, DAST, SCA, secrets detection, infrastructure-as-code security scanning, container/image scanning, API, and cloud-native security controls.

• Ensure that security tools yield actionable insights while minimizing false positives.

• Lead or facilitate activities such as threat modeling, defining security requirements, and conducting secure design or architecture reviews.

• Implement risk-based vulnerability management, establish remediation SLOs, apply compensating controls, and manage risk acceptance, escalation, and exceptions.

• Develop processes for identifying, tracking, and rectifying vulnerable third-party, open-source, and transitive dependencies.

• Establish governance for open-source software, including component inventory, license identification and review, approval workflows, and policy enforcement.

• Enhance software supply-chain security practices, encompassing SBOMs, VEX, build and release provenance, artifact/package/container/binary signing, artifact verification, trusted promotion, secure repositories, approved dependency sources, and SLSA-aligned controls.

• Collaborate with DevOps and platform engineering to secure CI/CD pipelines, source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.

• Aid in vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage, and product-security incident response.

• Create and manage a security champions program that includes secure-coding guidance, training, office hours, practical tools, and timely security engagement.

• Generate executive-ready metrics and reports regarding secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.

• Support customer, regulatory, audit, and assurance activities related to secure development and software supply-chain practices.


⛳️ Requirements

• A minimum of 7 years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related discipline.

• Proven experience in designing, implementing, or advancing a secure SDLC or application-security program across various engineering teams.

• Strong foundational knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.

• Experience collaborating directly with developers to elucidate findings, guide remediation efforts, and enhance secure-development practices.

• Practical experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tools.

• Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.

• Experience in performing or facilitating threat modeling, security design reviews, architecture reviews, or defining security requirements.

• Knowledge of authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.

• Familiarity with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.

• Experience managing risks associated with open-source software, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.

• Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or similar frameworks.

• Ability to read and evaluate production code and scripts in one or more contemporary programming languages.

• Excellent written and verbal communication skills.

• Preferred: experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls.

• Preferred: experience with VEX, CSAF, SPDX, CycloneDX, and component or vulnerability intelligence workflows.

• Preferred: experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.

• Preferred: experience with source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.

• Preferred: experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or equivalent technologies.

• Preferred: experience with regulatory requirements such as NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other compliance frameworks.

• Preferred: relevant certifications like CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.

• Offers contingent upon a cleared background and possible reference check.


🏝️ Benefits

• Bonus

• Benefits package

• Equity

• Temporary benefits package applicable after 60 days of employment (for temporary employees)

• Remote work arrangement

• Commitment to equal employment opportunity and support for workplace accommodations

People also viewed

CivicPlus1 day ago

Application Security Engineer

US flagUnited States OnlyFull-timeApplication Engineer$70.3k – $101.3k/year
ApplyView job
Airbnb1 day ago

Software Engineer, Application Platform

US flagUnited States OnlyFull-timeApplication Engineer$162k – $190k/year
ApplyView job
Oregon Health & Science University Foundation1 day ago

Clinical Data Engineer – Application Engineer

US flagUnited States OnlyFull-timeApplication Engineer$107.4k – $162.6k/year
ApplyView job
Clario1 day ago

Lead Mobile Application Engineer – .NET MAUI, Xamarin

CA flagCanada OnlyFull-timeApplication Engineer
ApplyView job
ABB1 day ago

Electrification Services Application Engineer

US flagArizona, +3 more statesFull-timeApplication Engineer$98.7k – $157.9k/year
ApplyView job
Nord Security1 day ago

Senior Application Security Engineer

PL flagPoland OnlyFull-timeApplication EngineerPLN 23k – PLN 30k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers