Remote job
Application Security Engineer
Job details
About this role
Role overview
This role focuses on elevating application security practices across multiple client engineering teams without becoming a blocker to delivery. The work centers on producing actionable findings, offering developer-friendly remediation guidance, and driving measurable risk reduction over time. It suits a security practitioner who has operated on both sides of the fence—identifying weaknesses and helping teams resolve them—while communicating tradeoffs clearly to engineers, product managers, and client stakeholders.
Responsibilities
- Review application architectures and source code with a focus on authentication flows, webhook handlers, file upload paths, multi-tenant data isolation, and third-party integrations - Help standardize dependency scanning, secrets detection, and penetration-test remediation workflows across client projects - Translate discovered issues into prioritized, actionable guidance that engineering teams can act on quickly - Track remediation progress and report on changes in risk posture over time - Collaborate with engineers, product managers, and client stakeholders to align security decisions with delivery goals
Requirements
- Demonstrated experience performing application security reviews and helping teams remediate findings - Familiarity with common vulnerability classes affecting web applications, APIs, and integrated services - Ability to communicate clearly with engineers, product managers, and external stakeholders, especially when tradeoffs are involved - A pragmatic mindset that balances risk reduction with shipping velocity