Senior Application Security Engineer
$111,000–$144,400 year
RemoteUnited States or Reno, Nevada, United States
Job Summary
Conduct application security testing across all software development life cycle phases to identify vulnerabilities in applications and secure coding practices. Assess discovered weaknesses and recommend risk-mitigating solutions, leveraging automation to streamline testing and remediation. Lead AI security initiatives by threat modeling production LLM stacks for prompt injection risks and auditing third-party models and APIs. Collaborate with architects and development teams to drive secure design practices, fully defining and following an automated security review process. Train developers on common weaknesses to avoid and monitor the security community for emerging tactics. Communicate findings and implementation progress against defined service-level agreements while addressing legacy and emerging security issues in business-to-business and vendor environments.
Required Qualifications
- 4+ years of related experience
- Bachelor's Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience
- Highly technical and analytical, with a background in software development, and scripting (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP)
- Expertise in application security testing, including hands-on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools
- Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments
- Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent
- Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.