Application Security Engineer

RedStream Technology

Charlotte (NC)

On-site

USD 120,000 - 150,000

Full time

8 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

RedStream Technology is seeking an experienced Application Security Engineer to drive end-to-end AppSec programs across multiple business units within our cybersecurity organization. You will lead discovery, implement tooling, and embed security controls into DevOps pipelines while influencing stakeholders without direct authority.

The role requires 7+ years in app security, hands-on experience with modern AppSec tooling, and strong scripting in Python.

Qualifications

  • 7+ years in application security, product security, or security engineering.
  • Hands-on experience deploying and operating modern AppSec tooling.
  • Strong scripting and automation skills in Python; comfortable building integrations against REST APIs.
  • Demonstrated ability to influence engineering organizations without direct authority.
  • Understanding of OWASP Top 10, threat modeling methodologies, and modern attack patterns.

Responsibilities

  • Application discovery and inventory across all business units, including ownership mapping and risk tiering.
  • Stand up and operate the AppSec tooling stack integrated into CI/CD pipelines.
  • Design and implement AI-assisted triage workflows on top of AppSec tooling.
  • Define secure SDLC requirements and threat modeling practices adopted by business units.
  • Partner with development leaders to build relationships and playbooks to operationalize AppSec.
  • Contribute to AI security strategy and evaluate emerging tools for adoption or deferment.
  • Produce executive-ready metrics linking AppSec activity to business risk reduction.

Skills

AppSec influence
Python scripting
CI/CD automation

Tools

Semgrep
Snyk
Checkmarx
Veracode
Apiiro
Ox Security
GitHub Advanced Security

Job description

Our client’s Cybersecurity Organization is seeking an Application Security Engineer.

This role will be an integral component of the application security program end-to-end, from discovery and inventory of business unit applications, through tooling implementation, through embedding security and AI-assisted controls into business unit DevOps pipelines.

This is as much a relationship and influence role as it is a technical role; success requires partnering effectively with the client’s subsidiaries.

Responsibilities:
  • Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering.
  • Standing up and operating the AppSec tooling stack — SAST, SCA, secrets scanning, and container/IaC scanning — integrated into business unit CI/CD pipelines.
  • Designing and implementing AI-assisted triage workflows on top of AppSec tooling so that finding volume does not overwhelm developers and false positives are filtered before reaching engineering teams.
  • Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process.
  • Partnering with business unit development leaders to build the relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.
  • Contributing to AI security strategy — evaluating emerging tools (AI code review assistants, agentic security testing, automated security requirement generation) and recommending what to operationalize and what to defer.
  • Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction.
Required Qualifications:
  • 7+ years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.
  • Hands-on experience deploying and operating modern AppSec tooling (e.g., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security).
  • Strong scripting and automation skills in Python or equivalent; comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
  • Demonstrated ability to influence engineering organizations without direct authority — negotiating standards, driving adoption, and partnering with development leaders.
  • Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks.
Preferred Qualifications:
  • Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).
  • Familiarity with one or more compliance frameworks relevant to the client’s environment (HITRUST, HIPAA, NIST AI RMF, SOC 2).
  • Prior experience working in a regulated or healthcare-adjacent environment.
  • Cloud security depth in at least one major provider (AWS, Azure, GCP).
  • Public contribution to the AppSec community — OSS, conference talks, published research, or detection/rule contributions.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Application Security Specialist
Senior Application Security Specialist

CLS Group • Woodbridge Township (NJ)

On-site
USD 140,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Arizona

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

Hybrid
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

BBG Ventures, LLC • New York (NY)

Hybrid
USD 120,000 - 180,000
Medical, Dental, and 401k (no match)
Manager Application Security
Manager Application Security

Citizens • Woodbridge Township (NJ)

On-site
USD 133,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

TKO • New York (NY)

Hybrid
USD 180,000 - 240,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000