Fragomen Logo

Fragomen

Security Engineer - Application Security

Posted One Month Ago
Remote
Hiring Remotely in Corporal, CA, USA
Senior level
Remote
Hiring Remotely in Corporal, CA, USA
Senior level
Build, deploy, and maintain AppSec tooling; integrate security into SDLC; triage SAST/DAST findings; automate penetration testing; lead secure coding and threat modeling; support vulnerability detection, remediation, and incident response.
The summary above was generated by AI

Job Description

Fragomen is seeking a Security Engineer – Application Security to join our talented Cyber Security team in our Technology Innovation Lab in Pittsburgh. 
Our industry-leading, immigration specific software and supporting infrastructure is undergoing tremendous transformation and security is on the critical path to success in that endeavor. A professional, who is passionate about security, capable of effecting change, and ready to build a strong AppSec program, is what we seek. You will be joining a small team of Security Engineers who make security a distinguishing factor in our technological offerings.  A successful candidate will help engineer solutions to secure software development, identify threats and mitigate vulnerabilities throughout our environment.

What an Application Security Engineer does at Fragomen:

  • Build, deploy and maintain tooling to validate and track security controls in and around our code
  • Work closely with application development and infrastructure architectural teams to create code which is secure by design and default
  • Triage programmatic source code findings and automate penetration testing to decrease potential introduction of vulnerabilities
  • Lead and collaborate with developers on secure coding techniques and threat modeling
  • Contribute to vulnerability detection and remediation of technological offerings
  • Deploy developed or OTS security applications to support our efforts
  • Participate in a cross-functional response to cyber security incidents
  • Work closely the security team to establish prevention, detection and mitigation techniques
  • Support the scoping and rules of engagement of our penetration testing regime

Let’s talk if you have the following experience, knowledge, skills and education:

  • A passionate team player who builds knowledge and solves complex problems
  • 5+ years of web application development (.net, python, java, etc.)
  • Secure SDLC (Software Development Life Cycle), DAST (Dynamic Application Security Testing), and SAST (Static Application Security Testing) experience
  • Demonstrated understanding of web application penetration testing, secure coding and source code analysis
  • Strong, professional communication skills that maintain under pressure

These things are great, but not required:

  • Experience in developing highly automated detection and triage tools
  • Deep understanding of cyber security techniques
  • Technical certification demonstrating technical prowess in secure software development e.g. Certified Secure Software Lifecycle Professional (CSSLP), or Certified Application Security Engineer (CASE) or similar
  • BA degree in a related field or a combination of related experience is a must

Benefits:

At Fragomen, we know that great people make a great organization. We value our people and offer employees a broad range of benefits which includes:

  • 22 PTO days + Federal holidays
  • Medical, Dental, and Vision plans + FSA & HSA Plans
  • 401K plan, with company matching

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position’s location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI‑assisted tools for administrative screening purposes only - never for decision‑making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.

Fragomen San Francisco, California, USA Office

555 Montgomery St, San Francisco, CA, United States

Fragomen San Jose, California, USA Office

San Jose, United States

Fragomen Santa Clara, California, USA Office

2121 Tasman Drive, Santa Clara, CA, United States, 95070

Similar Jobs

2 Hours Ago
Remote or Hybrid
US
160K-180K Annually
Senior level
160K-180K Annually
Senior level
Cloud • eCommerce • Information Technology • Professional Services • Software
Owns Cleo’s application and product security strategy across SaaS and customer-hosted products. Responsibilities include maturing the SSDLC, threat modeling, security scanning, vulnerability triage, penetration testing, coordinated disclosure, CVE management, product security controls, customer-facing advisories, and NIST CSF evidence. The role also leads security enablement, roadmap prioritization, AI security reviews, and hands-on exploit reproduction and patch validation while guiding engineers and security partners.
Top Skills: APIsAWSBurp SuiteCi/CdContainer ScanningCyclonedxEksGitGithub Advanced SecurityGoIac ScanningJavaJenkinsKubernetesNist Ai RmfNist CsfOwasp AsvsOwasp SammOwasp Top 10 For Llm ApplicationsPolicy-As-CodePythonRbacSAMLSastScaSecrets ScanningSemgrepSlsaSnykSpdxSsoTerraformTypescriptVex
9 Days Ago
Remote
United States
140K-180K Annually
Junior
140K-180K Annually
Junior
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Conduct application security assessments, discover and validate vulnerabilities, analyze complex codebases, build custom security tooling, perform threat modeling and architecture reviews, and deliver actionable findings to clients. Independently own assessment workstreams, develop proof-of-concept exploits, communicate technical conclusions, review team work, and contribute to security research, open-source tools, and technical writing.
Top Skills: AnsibleCC++GoHelmJavaScriptKubernetesPythonRustTerraformTypescript
9 Days Ago
Remote
United States
100K-160K Annually
Junior
100K-160K Annually
Junior
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Conduct application security assessments, discover and validate vulnerabilities, analyze code and architectures, perform threat modeling, build security tooling, and develop proof-of-concept exploits. Own scoped assessment components from discovery through client delivery, communicate findings and remediation guidance, and contribute to security research, open-source tools, and technical documentation. The role requires hands-on coding, vulnerability research, memory-corruption knowledge, operating-system familiarity, and independent technical investigation.
Top Skills: AnsibleAslrCC++CfiGoHelmJavaScriptKubernetesMteNx/DepPythonRustTerraformTypescript

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account