Application Security Engineer
The job description
Tech stack. Burp Suite, SAST tools (Checkmarx, Semgrep), DAST tooling, OWASP Top 10 and ASVS, threat modeling, Python or Java, GitHub Advanced Security, API security testing tools
About the role
You will embed with product engineering teams at a software company to find and fix vulnerabilities before code ever ships, acting as a trusted security partner rather than a last-minute gatekeeper. The application security team runs the secure SDLC: threat models, code review, and testing pipelines woven into how engineers already work. You will review designs, test running applications, and teach developers to avoid entire bug classes. This role matters because the cheapest vulnerability to fix is the one that never reaches production, and your partnership with developers is what keeps the backlog shrinking instead of growing.
What you will achieve
- Threat-model every major feature launch alongside engineering, closing 100 percent of high-risk findings before the release ships to customers.
- Integrate SAST and secret scanning into CI pipelines so vulnerable code is flagged within minutes of commit rather than discovered weeks later.
- Drive the OWASP Top 10 finding backlog down 60 percent through developer-focused remediation guidance, office hours, and secure code examples.
- Perform manual penetration tests on flagship applications each release cycle, then verify every fix with rigorous retesting.
- Build secure coding training that measurably reduces repeat vulnerability classes quarter over quarter, tracked with real metrics.
What you will bring
Must-haves
- 2 to 5 years in application security, penetration testing, or software engineering with a dedicated security focus.
- Hands-on ability with Burp Suite or OWASP ZAP for manual web application testing that goes beyond scanner output.
- Strong knowledge of the OWASP Top 10, common web vulnerability classes, and the correct remediation for each.
- Experience reviewing code in at least one of Python, Java, JavaScript, or Go, producing security-relevant findings.
- Familiarity with SAST, DAST, and SCA tools and how to tune them for real, large, fast-moving codebases.
- Ability to write findings developers respect: clear impact statements, reliable reproduction steps, and concrete fix guidance.
- Patience and teaching skill; you make developers better at security rather than making them dread your reviews.
Nice-to-haves
- GWAPT, OSWE, or a similar application security certification.
- Experience with API security testing, including GraphQL and gRPC assessment techniques.
- Background in bug bounty programs, either as an active hunter or as a triage engineer.
- Familiarity with mobile application security testing on iOS and Android.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta