SENIOR APPLICATION SECURITY ENGINEER
Jobgether
Full-timesenior€150,000-196,000/year
Job description
Accountabilities:
The Senior Application Security Engineer will play a critical role in strengthening application security by integrating security into every phase of software development. This position focuses on vulnerability assessment, secure architecture, penetration testing, developer enablement, and continuous improvement of security processes and tools.
• Perform manual and automated application security assessments to identify and remediate vulnerabilities across enterprise applications.
• Conduct secure code reviews and analyze application source code to improve software security.
• Evaluate software development lifecycle (SDLC) processes and recommend improvements to strengthen application and software supply chain security.
• Partner with engineering teams to integrate secure coding practices and security controls throughout development workflows.
• Design, develop, and maintain internal security testing tools and automation capabilities.
• Perform penetration testing and validate security controls across applications and supporting infrastructure.
• Conduct threat modeling, security architecture reviews, and secure design assessments for new features and platforms.
• Define, document, and promote secure development standards, policies, and best practices.
• Collaborate with security teams to investigate attack patterns, identify indicators of compromise, and improve defensive capabilities.
• Document security findings, communicate remediation recommendations, and support risk prioritization across technical and business stakeholders.
• Mentor junior security team members and contribute to knowledge sharing and continuous improvement initiatives.
Requirements:
The ideal candidate combines deep application security expertise with strong software development knowledge and the ability to collaborate effectively across engineering and security teams. They are comfortable balancing technical depth with clear communication and strategic thinking.
• Bachelor's, Master's, or Associate degree in Computer Science, Engineering, or a related technical field, combined with relevant professional experience in application security, penetration testing, or software development.
• Strong hands-on experience performing application security assessments, vulnerability analysis, and secure code reviews.
• Experience conducting threat modeling and translating findings into practical remediation strategies.
• Solid understanding of secure software development lifecycle (SSDLC) principles and secure-by-design methodologies.
• Proficiency with C# and .NET development, including secure coding practices and code review techniques.
• Experience performing web application penetration testing and vulnerability validation.
• Knowledge of application architecture, software security testing tools, and common attack vectors.
• Familiarity with security compliance frameworks such as SOC 2, FedRAMP, or similar industry standards.
• Strong analytical, troubleshooting, and problem-solving skills with the ability to manage multiple priorities.
• Excellent written and verbal communication skills, with the ability to explain technical concepts to both technical and non-technical audiences.
• Offensive security certifications such as OSCP, GPEN, GXPN, or equivalent are considered an advantage.
Benefits:
• Fully remote position available within the United States.
• Competitive base salary ranging from $150,000 to $196,000 , based on experience, skills, and location.
• Additional variable compensation opportunities where applicable.
• Comprehensive medical, dental, vision, and life insurance coverage.
• Short-term and long-term disability benefits.
• 401(k) retirement savings plan.
• Paid vacation and company holidays.
• Professional development and ongoing training opportunities.
• Collaborative culture focused on innovation, customer success, and continuous learning.
• Opportunity to work on impactful enterprise security initiatives within a growing technology organization.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Skills
C#NETOSCPGPENGXPSOC 2FedRAMP