Application Security Engineer

Australia-Employment

New York (NY)

On-site

USD 83,000 - 96,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobot in New York, NY is seeking an experienced Application Security Engineer to build and scale an enterprise AppSec program, spanning discovery, tooling, CI/CD integrations and secure coding practices.

You will work across diverse tech stacks, apply AI-assisted security workflows, and influence engineering leaders while delivering measurable reductions in risk. This on-site consulting role offers high visibility and meaningful impact in shaping secure development across the organization.

Qualifications

  • 7+ years of experience in application security, product security, or security engineering.
  • 3+ years of experience supporting complex environments with multiple independent business units, brands, product groups, or engineering organizations.
  • Hands-on experience implementing and operating modern AppSec tools such as Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security, or similar platforms.
  • Code-level proficiency in at least three commonly used programming languages such as Python, JavaScript/TypeScript, Java, C#, or Go, with the ability to review code and effectively validate security findings.
  • Strong scripting and automation skills, ideally in Python or a comparable language.
  • Experience building integrations using REST APIs and working within CI/CD environments such as GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
  • Demonstrated success influencing engineering teams and driving security adoption without direct authority.
  • Strong understanding of the OWASP Top 10, modern application attack patterns, software supply chain risks, and threat modeling methodologies such as STRIDE or PASTA.

Responsibilities

  • Lead application discovery and inventory efforts across multiple business units, including ownership mapping, technology stack profiling, and risk tiering.
  • Implement, integrate, and operate modern application security tooling, including SAST, SCA, secrets scanning, container security, and IaC scanning.
  • Embed security tooling and controls directly into CI/CD pipelines to make security part of the development lifecycle.
  • Design and implement AI-assisted triage workflows to prioritize findings, reduce false positives, and prevent alert fatigue.
  • Establish and evolve secure SDLC standards, threat modeling practices, security requirements, and development gates.
  • Partner with engineering and development leaders to create practical AppSec playbooks that improve security while enabling speed of delivery.
  • Shape the organization’s approach to AI within application security, evaluating AI-assisted code review, automated testing, and remediation guidance.
  • Develop meaningful metrics and executive-level reporting linking AppSec initiatives to risk reductions.

Skills

Python
JavaScript/TypeScript
Java
C#
Go
CI/CD
Code review
Threat modeling

Tools

Semgrep
Snyk
Checkmarx
Veracode
Apiiro
Ox Security
GitHub Advanced Security
REST APIs

Job description

Application Security Engineer

$60 - $70 per hour | New York, NY | On-site | Consulting

A bit about us:

We are a large, diversified organization with a broad portfolio of businesses, brands, and digital products operating across multiple industries. Our technology and cybersecurity teams support a complex enterprise environment while giving individual business units the flexibility to operate and innovate within their own markets.

As our application security program continues to evolve, we are investing in modern security tooling, automation, and AI-assisted capabilities that help development teams build and deploy securely without slowing delivery.

Why join us?

Build, don’t just maintain. You’ll have an opportunity to help shape and mature an enterprise AppSec program rather than simply inherit a fully established environment.

Work across a highly diverse technology ecosystem. The organization supports multiple businesses and development teams, creating exposure to a wide variety of applications, technology stacks, and security challenges.

Bring AI into real-world security workflows. This team is actively exploring how AI can improve application security operations, from smarter triage to automated testing and remediation.

High visibility and meaningful impact. Your work will influence how development teams across the organization approach secure software development and will be visible to senior technology and security leadership.

Technical depth with strategic influence. This role combines hands‑on engineering with the opportunity to establish standards, influence development leaders, and help determine the future direction of the AppSec program.

Job Details

We are seeking an experienced Application Security Engineer to play a key role in building and scaling our application security program.

This position will have visibility across the full AppSec lifecycle, from discovering and inventorying applications across the enterprise to implementing security tooling, integrating controls into CI/CD pipelines, and helping development teams adopt secure engineering practices.

This is not a purely heads‑down technical role. The right person will be equally comfortable working with security tools and code as they are partnering with engineering leaders across independent business units. Success will require technical depth, strong communication skills, and the ability to influence teams without direct authority.

This is a hybrid position requiring three days per week onsite at one of our designated offices.

What You’ll Do
  • Lead application discovery and inventory efforts across multiple business units, including application ownership mapping, technology stack profiling, and risk tiering.
  • Implement, integrate, and operate modern application security tooling, including SAST, SCA, secrets scanning, container security, and Infrastructure-as-Code scanning.
  • Embed security tooling and controls directly into CI/CD pipelines to make security part of the development lifecycle rather than a separate process.
  • Design and implement AI-assisted triage workflows to help prioritize findings, reduce false positives, and prevent development teams from becoming overwhelmed by security alerts.
  • Establish and evolve secure SDLC standards, threat modeling practices, security requirements, and development gates.
  • Partner closely with engineering and development leaders to create practical AppSec playbooks that improve security while supporting speed of delivery.
  • Help shape the organization’s approach to AI within application security, including evaluating emerging capabilities such as AI-assisted code review, agentic security testing, automated security requirements, and remediation guidance.
  • Develop meaningful metrics and executive-level reporting that connect application security initiatives to measurable reductions in business and technology risk.
Required Qualifications
  • 7+ years of experience in application security, product security, or security engineering.
  • 3+ years of experience supporting complex environments with multiple independent business units, brands, product groups, or engineering organizations.
  • Hands‑on experience implementing and operating modern AppSec tools such as Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security, or similar platforms.
  • Code‑level proficiency in at least three commonly used programming languages such as Python, JavaScript/TypeScript, Java, C#, or Go, with the ability to review code and effectively validate security findings.
  • Strong scripting and automation skills, ideally in Python or a comparable language.
  • Experience building integrations using REST APIs and working within CI/CD environments such as GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
  • Demonstrated success influencing engineering teams and driving security adoption without direct authority.
  • Strong understanding of the OWASP Top 10, modern application attack patterns, software supply chain risks, and threat modeling methodologies such as STRIDE or PASTA.
Preferred Qualifications
  • Experience incorporating LLM or AI‑based capabilities into security workflows, including alert triage, finding summarization, remediation guidance, or security automation.
  • Familiarity with security and compliance frameworks such as HITRUST, HIPAA, NIST AI RMF, or SOC 2.
  • Experience working within a regulated, healthcare, or healthcare‑adjacent environment.
  • Strong cloud security knowledge across AWS, Azure, or GCP.
  • Contributions to the broader application security community through open‑source projects, conference presentations, research, detection rules, or similar work.

Jobot is an Equal Opportunity Employer. We provide an inclusive work environment that celebrates diversity and all qualified candidates receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, age (40 and over), disability, military status, genetic information or any other basis protected by applicable federal, state, or local laws. Jobot also prohibits harassment of applicants or employees based on any of these protected categories. It is Jobot’s policy to comply with all applicable federal, state and local laws respecting consideration of unemployment status in making hiring decisions.

Sometimes Jobot is required to perform background checks with your authorization. Jobot will consider qualified candidates with criminal histories in a manner consistent with any applicable federal, state, or local law regarding criminal backgrounds, including but not limited to the Los Angeles Fair Chance Initiative for Hiring and the San Francisco Fair Chance Ordinance.

Information collected and processed as part of your Jobot candidate profile, and any job applications, resumes, or other information you choose to submit is subject to Jobot's Privacy Policy, as well as the Jobot California Worker Privacy Notice and Jobot Notice Regarding Automated Employment Decision Tools which are available at jobot.com/legal.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Full Stack Engineer
Senior Full Stack Engineer

Australia-Employment • New York (NY)

On-site
USD 215,000 - 275,000
401k with 3% company match
Medical, dental and vision benefits
Annual team offsites
+1
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

BBG Ventures, LLC • New York (NY)

Hybrid
USD 120,000 - 180,000
Medical, Dental, and 401k (no match)
Security Engineer, Application Security
Security Engineer, Application Security

OpenAI • San Francisco (CA)

Hybrid
USD 234,000 - 385,000
Hybrid work model
Relocation assistance
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
DevSecOps Manager
DevSecOps Manager

Jobot • Fairfax (VA)

On-site
USD 150,000 - 190,000
Medical, Dental, Vision
Competitive compensation
Favorable PTO
Cyber Security Analyst
Cyber Security Analyst

Australia-Employment • Town of Oyster Bay (NY)

On-site
USD 80,000 - 105,000
Generous Compensation
Medical, Vision, Dental
Career Growth
+3
Lead Engineer (Breach & Attack Simulation)
Lead Engineer (Breach & Attack Simulation)

Australia-Employment • Los Angeles (CA)

Remote
USD 250,000 - 400,000
Senior NHI Product Analyst/Manager
Senior NHI Product Analyst/Manager

Jobot • New York (NY)

On-site
USD 138,000 - 179,000
Security Engineer, Application Security
Security Engineer, Application Security

Slope • New York (NY)

On-site
USD 100,000 - 150,000
Relocation assistance
Hybrid work model
Application Security Engineer II
Application Security Engineer II

The Trade Desk, Inc. • Bellevue (WA)

On-site
USD 103,200 - 189,200
Stock Purchase Plan
Comprehensive healthcare
401k match