We are looking for an Application Security Engineer to work for our client. The ideal candidate aligns with the responsibilities and qualifications outlined below.
This is a great opportunity for a security-minded engineer to embed strong security practices directly into the development lifecycle, working closely with engineering teams to build safer software from the ground up, in a hybrid role based in Columbus, OH.
Responsibilities
- Identify, assess, and remediate vulnerabilities across web applications, APIs, mobile applications, and cloud environments
- Apply knowledge of OWASP Top 10, CWE, and common attack vectors to guide secure development practices
- Integrate SAST/DAST tools and application security testing into CI/CD and DevSecOps pipelines
- Partner directly with developers and engineering teams to communicate risk and recommend practical remediation steps
- Review code and architecture for security weaknesses, providing actionable guidance to development teams
- Support secure coding training and best-practice adoption across engineering teams
- Stay current on emerging vulnerabilities, attack techniques, and application security tooling
- Contribute to incident response efforts related to application-level security issues
- Help shape and mature the organization's overall application security program
Qualifications
- 3+ years of application security, product security, or related cybersecurity experience
- Hands-on experience identifying and remediating vulnerabilities across web applications, APIs, mobile applications, and cloud environments
- Strong understanding of OWASP Top 10, CWE, secure coding practices, and common attack vectors
- Experience with SAST/DAST tools and embedding security testing into CI/CD and DevSecOps workflows
- Strong communication skills, with the ability to influence developers without direct authority
- Excellent analytical and problem-solving skills
What Our Client Offers
- A true seat within the engineering organization, not a siloed security function
- Direct influence over how security gets built into the SDLC from day one
- Exposure across web, mobile, API, and cloud security; not a single narrow surface area
- A development team that treats security recommendations as partnership, not friction