Remote job
Senior Application Security Engineer
Job details
About this role
Role overview A Senior Application Security Engineer will embed security across a portfolio of roughly ten SaaS platforms serving human services organizations. Reporting to the CISO, the role partners closely with software development and production operations to architect security tooling, integrate security into the SDLC, and mature vulnerability management practices.
Responsibilities - Lead initiatives that strengthen security across the application development lifecycle and drive continuous improvement of secure coding practices. - Evaluate and optimize existing security tools and explore new technologies to scale the security posture across the platform portfolio. - Conduct internal penetration testing, code reviews, and source code analysis to identify and support remediation of vulnerabilities. - Lead and mature the vulnerability management program, including threat modeling for a wide variety of software projects. - Leverage AI and automation to streamline security workflows and improve efficiency across the security program. - Work directly with software developers on secure coding guidance, vulnerability remediation, and proactive security improvements. - Lead incident response efforts and draft communications that keep stakeholders informed on security programs and projects. - Develop security training material and provide ongoing guidance for internal software development teams.
Requirements - 3-5 years of scripting and development experience supporting web applications. - 2-3 years of cloud engineering experience using Infrastructure as Code, with an emphasis on AWS. - Familiarity with AI tools and an interest in leveraging agentic AI for automation. - Working knowledge of security best practices and standards such as OWASP, OWASP ASVS, S-SDLC, and BSIMM. - Demonstrated judgment in assessing and prioritizing technical risk. - Strong communication skills with the ability to explain complex security issues to both technical and non-technical collaborators, and a track record of removing bottlenecks for teammates.
Nice to have - Hands-on experience applying NIST and HIPAA in a cloud-based SaaS environment.
Benefits and work setup - Remote position. - Compensation of $125,000-$145,000 OTE, with unlimited PTO, competitive medical, dental, and vision coverage, 401(k) matching, paid holidays, volunteer time off, paid parental leave, and a remote work stipend.