Architects and automates application security within the SDLC, including AI-enabled secure code scanning, hardened baseline automation, and SAST, DAST, and SCA integration into enterprise CI/CD pipelines. Reviews complex Java and Python code, provides remediation guidance, develops secure coding patterns and automated runbooks, tunes security tools, and supports threat modeling and AI-assisted vulnerability triage. The role requires autonomous execution in a remote financial services program.
AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.
WHY JOIN US
If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!
ABOUT THE ROLE
We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration within a large-scale financial services program. You will work primarily in Python to build automated security runbooks, deploy and tune scanning tools, and provide code-level remediation guidance to development teams — operating with full autonomy and no daily supervision. AppSec and DevSecOps experience is strongly preferred; SAST/DAST/SCA and Java expertise are a plus.
WHAT YOU WILL DO
- Engineer and deploy AI-enabled secure code scanning capabilities and "Golden Images" to drive secure-from-the-start adoption.
- Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows.
- Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise.
- Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance.
MUST HAVES
- 5+ years combining software engineering experience, security implementation and/or architecture experience.
- Strong coding and architectural proficiency in Python (for security automation and scripting).
- Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks.
- Upper-Intermediate English level.
NICE TO HAVES
- Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems.
- Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation.
- Advanced application threat modeling experience.
- Ability to confidently read, review, and secure enterprise source Java code.
PERKS AND BENEFITS
- Growth without limits: build your skills through mentorship, internal TechTalks, challenging projects, and a dedicated annual learning budget
- Competitive compensation: get recognition that reflects your skills and impact, with regular performance and compensation reviews
- Flexibility: work 100% remotely with flexible hours that support focus, autonomy, and a healthy work rhythm
- Meaningful, modern projects: build impactful products using modern technologies alongside global teams and leading brands
- Collaborative culture: join a supportive environment with zero micromanagement where ideas are welcomed and contributions are recognized
- Well-being & support: access local well-being programs and people-focused support tailored to your location
Similar Jobs
eCommerce • Information Technology • Software
The Senior Application Security Engineer ensures the security of systems and data by monitoring vulnerabilities, responding to incidents, and promoting security best practices within the organization.
Top Skills:
Aws CloudCloudflareDockerDynamoDBGitlabKubernetesLaravelMySQLNode.jsPHPServerless FrameworkSysdigVantaVue
Fintech • Payments • Financial Services
Lead and build a Hardware Partner Engineering team, manage day-to-day technical relationships with terminal OEMs, drive issue resolution and OEM accountability, create tooling and processes to scale quality, align cross-functionally on prioritization, and establish operating model and senior partner relationships.
Top Skills:
AutomationEmbedded FirmwareEmbedded SystemsHardware Partner EngineeringOem TerminalsTooling
Fintech • Information Technology • Financial Services
The Salesforce Administrator oversees day-to-day Salesforce administration, configuration, and support in a multi-org setup, collaborating with stakeholders to optimize business processes and user experience.
Top Skills:
ApexAppexchangeDevOpsFlowsLightningProcess BuildersSalesforce
What you need to know about the San Francisco Tech Scene
San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine



