AgileEngine Logo

AgileEngine

Senior Application Security Engineer ID87004

Posted Yesterday
Be an Early Applicant
In-Office
New York, NY
Senior level
In-Office
New York, NY
Senior level
Strengthen application security and DevSecOps practices by deploying and tuning SAST, DAST, and IAST tools, conducting threat modeling, prioritizing vulnerability remediation, and integrating security controls into CI/CD pipelines. The role partners with engineering teams, develops automation, establishes security metrics, documents processes, and communicates risks to technical and nontechnical stakeholders. AWS/cloud security, software development, infrastructure-as-code, and modern web application security experience are required.
The summary above was generated by AI
AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.

WHY JOIN US
If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!

ABOUT THE ROLE
We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across engineering teams. This person deploys and tunes SAST, DAST, and IAST tools, conducts threat modeling, and integrates security controls into CI/CD pipelines. Comfort working across Python, JavaScript, or Java and cloud infrastructure such as AWS is essential.

WHAT YOU WILL DO
- Be a part of a bleeding-edge security organization that enables the agile development of secure and reliable applications and products.
- Deploy and tune code scanning solutions such as SAST, DAST, and IAST.
- Interpret code scanning results to ensure the team is focused on remediation of the highest-risk vulnerabilities.
- Perform threat modeling of applications to identify potential threat vectors in the technology stack that could be used by attackers and cause disruption or a potential data breach.
- Collaborate with technology stakeholders to establish metrics that demonstrate application security proficiency across all engineering teams.
- Steer the development of tools to improve the security of applications through automation and other means, allowing for faster and easier security gains by teams.
- Ensure processes associated with key systems are documented, maintained, and archived.

MUST HAVES
- You must be authorized to work for ANY employer in the US (e.g., Green card holders, TN visa holders, GC EAD, H4 EAD, U4U with EAD), as we are unable to sponsor or take over employment visa sponsorship at this time;
- Strong hands-on Application Security experience in a modern software-development environment of at least 4 years.
- Software engineering foundation with the ability to read, understand, and discuss code in Python, JavaScript, Java, or similar languages.
- Deep experience deploying, tuning, and interpreting SAST and DAST tools; IAST experience is a plus.
- Demonstrated experience conducting threat modeling and translating findings into practical security requirements.
- Experience integrating security testing and controls into CI/CD pipelines and developer workflows.
- Working knowledge of AWS/cloud application security, APIs, authentication/authorization, secrets management, and common web-application vulnerabilities.
- Experience with infrastructure-as-code and automation tools such as Terraform, CloudFormation, Ansible, Puppet, Chef, or Salt.
- Ability to prioritize true security risk, reduce scanner noise, and drive timely remediation of meaningful vulnerabilities.
- Strong communication and influence skills: able to explain complex security issues clearly to engineers, engineering leaders, and nontechnical stakeholders.
- Collaborative, solutions-oriented approach; must be able to build trust with development teams and improve security without unnecessarily slowing product delivery.
- Upper-intermediate English level.

NICE TO HAVES
- Familiarity with security tools such as Nessus, Burp, and web application firewalls.
- Experience with Static/Dynamic Application Security Testing methodologies and tools.
- Experience with automation tools such as Terraform, Puppet, Chef, Salt, Ansible, or CloudFormation.
- Experience conducting a detailed threat model exercise.
- Experience with CI/CD pipelines and how to assess them from a security perspective, including the integration of security tools with the pipeline.
- Experience working with cloud-based infrastructure and technologies, preferably AWS.
- A collaborator who will partner across the engineering organization to drive the establishment of a security posture.
- Results oriented and believes in steady continuous improvement.
- Curious and always goes beyond what is happening to discover why.
- An effective communicator with a solution-oriented mindset.
- A strategic thinker who focuses on integrating current initiatives and ideating on ways to improve while still meeting the needs of the business.

PERKS AND BENEFITS
- Professional growth: Accelerate your professional journey with mentorship, TechTalks, and personalized growth roadmaps.
- Competitive compensation: We match your ever-growing skills, talent, and contributions with competitive USD-based compensation and budgets for education, fitness, and team activities.
- A selection of exciting projects: Join projects with modern solutions development and top-tier clients that include Fortune 500 enterprises and leading product brands.
- Flextime: Tailor your schedule for an optimal work-life balance, by having the options of working from home and going to the office – whatever makes you the happiest and most productive.

Similar Jobs

25 Days Ago
In-Office or Remote
USA
Senior level
Senior level
eCommerce • Information Technology • Software
The Senior Application Security Engineer ensures the security of systems and data by monitoring vulnerabilities, responding to incidents, and promoting security best practices within the organization.
Top Skills: Aws CloudCloudflareDockerDynamoDBGitlabKubernetesLaravelMySQLNode.jsPHPServerless FrameworkSysdigVantaVue
2 Minutes Ago
Hybrid
Sunnyvale, CA, USA
140K-215K Annually
Senior level
140K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead strategy and execution for CrowdStrike's Identity Protection product: detect and prioritize identity risk across human and non-human identities, define identity graph models, drive remediation automation and verification, and surface identity risk across the security stack. Use AI agents and rapid prototyping to iterate specs and partner with engineering, customers, and stakeholders to deliver usable identity risk solutions.
Top Skills: A2AAws IamAzure RbacClaude CodeEntra IdGcp IamLovableMcpOauthOidcOktaPingReplitSAMLSIEMSoarSpiffe/Spire
2 Minutes Ago
Easy Apply
Hybrid
Easy Apply
32-43 Annually
Junior
32-43 Annually
Junior
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Qualify inbound marketing leads, collaborate with Account Executives and Marketing, develop prospecting strategies, manage a sales pipeline using CRM and outreach tools, track performance metrics, test content, and meet or exceed activity and revenue goals in a high-volume environment.
Top Skills: Linkedin Sales NavigatorOutreachSFDCZoominfo

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account