
Staff Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Establish, uphold, and continually enhance secure SDLC policies, standards, control objectives, procedures, and the required supporting evidence across the organization.
• Convert security policies into clear, actionable requirements for development, product, and platform teams.
• Evaluate the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and guide improvement roadmaps.
• Create secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and materials to empower developers.
• Collaborate with development teams to identify, triage, prioritize, remediate, and verify findings related to application security.
• Assess, implement, optimize, and operationalize security tools such as SAST, DAST, SCA, secrets detection, infrastructure-as-code security scanning, container/image scanning, API, and cloud-native security controls.
• Ensure that security tools yield actionable insights while minimizing false positives.
• Lead or facilitate activities such as threat modeling, defining security requirements, and conducting secure design or architecture reviews.
• Implement risk-based vulnerability management, establish remediation SLOs, apply compensating controls, and manage risk acceptance, escalation, and exceptions.
• Develop processes for identifying, tracking, and rectifying vulnerable third-party, open-source, and transitive dependencies.
• Establish governance for open-source software, including component inventory, license identification and review, approval workflows, and policy enforcement.
• Enhance software supply-chain security practices, encompassing SBOMs, VEX, build and release provenance, artifact/package/container/binary signing, artifact verification, trusted promotion, secure repositories, approved dependency sources, and SLSA-aligned controls.
• Collaborate with DevOps and platform engineering to secure CI/CD pipelines, source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
• Aid in vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage, and product-security incident response.
• Create and manage a security champions program that includes secure-coding guidance, training, office hours, practical tools, and timely security engagement.
• Generate executive-ready metrics and reports regarding secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
• Support customer, regulatory, audit, and assurance activities related to secure development and software supply-chain practices.
• A minimum of 7 years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related discipline.
• Proven experience in designing, implementing, or advancing a secure SDLC or application-security program across various engineering teams.
• Strong foundational knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
• Experience collaborating directly with developers to elucidate findings, guide remediation efforts, and enhance secure-development practices.
• Practical experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tools.
• Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
• Experience in performing or facilitating threat modeling, security design reviews, architecture reviews, or defining security requirements.
• Knowledge of authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.
• Familiarity with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
• Experience managing risks associated with open-source software, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.
• Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or similar frameworks.
• Ability to read and evaluate production code and scripts in one or more contemporary programming languages.
• Excellent written and verbal communication skills.
• Preferred: experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls.
• Preferred: experience with VEX, CSAF, SPDX, CycloneDX, and component or vulnerability intelligence workflows.
• Preferred: experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
• Preferred: experience with source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.
• Preferred: experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or equivalent technologies.
• Preferred: experience with regulatory requirements such as NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other compliance frameworks.
• Preferred: relevant certifications like CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.
• Offers contingent upon a cleared background and possible reference check.
• Bonus
• Benefits package
• Equity
• Temporary benefits package applicable after 60 days of employment (for temporary employees)
• Remote work arrangement
• Commitment to equal employment opportunity and support for workplace accommodations
CivicPlus
Airbnb
Oregon Health & Science University Foundation
Clario
Get handpicked remote jobs straight to your inbox weekly.