Application Security Engineer

Talentify

Philadelphia (Philadelphia County)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Talentify is seeking an Application Security Engineer in Philadelphia, a 6-month contract to hire. You will inventory applications and pipelines, define risk tiers, and socialize a minimum AppSec baseline across decentralized engineering teams.

You will lead threat modeling, build a Security Champions program, and guide migrations with secure-by-design guidance while coordinating remediation with development teams.

Qualifications

  • 4+ years in software engineering, cloud engineering, or application security with hands-on security work.
  • Experience threat modeling (STRIDE, PASTA) or translating findings into engineering actions.
  • Strong software or cloud engineering ability with security instincts.
  • AppSec depth: OWASP Top 10/ASVS, CWE Top 25, modern web/API security patterns.
  • Experience integrating security tooling into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins).
  • Knowledge of authentication/authorization patterns: OAuth 2.0, OIDC, SAML, session management.
  • Familiarity with Docker/Kubernetes and cloud-native security considerations.
  • Ability to communicate risk to engineers in actionable terms.
  • Bachelor's degree or equivalent practical experience.

Responsibilities

  • Inventory and assess the environment by cataloging applications, pipelines, repos, and AppSec tooling.
  • Create a risk-tiering model to focus security efforts on high-risk applications.
  • Define a minimum AppSec baseline and socialize it with engineering leadership.
  • Build and lead a Security Champions program across engineering teams.
  • Lead threat modeling for modernization, including monolith-to-microservices re-architecture.
  • Provide secure-by-design guidance on migration decisions before architecture is locked.
  • Own inventory, risk tiers, and coverage metrics, plus remediation metrics.
  • Triage vulnerabilities from tooling, pen tests, bug bounties, and alerts; drive remediation with teams.
  • Partner with Security Operations on incidents and validate remediation paths.

Skills

4+ years
Threat modeling
Cloud engineering
AppSec depth
CI/CD security tooling
Authn/Authz patterns
Containerization/cloud-native
Security communication
BSCS or related field

Education

Bachelor's degree in computer science or related field

Tools

Fortify
Veracode
Wiz Code

Job description

Application Security Engineer
PHILADELPHIA, PA 19103
6 Months - Contract to Hire
What You'l Do
  • Inventory and assess the environment by cataloging applications, development pipelines, source repositories, and existing AppSec tooling across the decentralized engineering organization, so standardization starts from an accurate picture rather than an assumption.
  • Create an application risk-tiering model that focuses limited application security effort on the applications carrying the most risk, so time is spent where it changes outcomes.
  • Define a minimum AppSec baseline that every development team is expected to meet, regardless of their tooling or SDLC, and socialize it with engineering leadership as the common standard.
  • Build and lead a Security Champions program across the decentralized product engineering teams.
  • Lead threat modeling for modernization and migration including the new trust boundaries and attack surfaces introduced by monolith-to-microservices re-architecture containerization, and re-platforming.
  • Provide secure-by-design guidance on migration decisions so security tradeoffs are understood before architecture is locked.
  • Own application inventory, risk-tiering, and coverage metrics, alongside vulnerability and remediation metrics, so leadership can see reach and gaps across the portfolio.
  • Triage and validate vulnerabilities surfaced through tooling, penetration tests, bug bounty submissions, and detection alerts, and drive remediation with the responsible engineering teams.
  • Partner with Security Operations and incident response on application-layer incidents, providing technical depth on attack paths, exploit feasibility, and remediation validation.
Qualifications/Certifications
What You'l Bring
  • 4+ years in software engineering, cloud engineering, or application security, including hands-on security work.
  • Experience wit hthreat modeling (STRIDE, PASTA, or equivalent), or a strong demonstrated ability to translate findings into engineering action.
  • Strong software or cloud engineering ability paired with real, load-bearing security instincts.
  • Enough application security depth to define what good looks like, including OWASP Top 10, OWASP ASVS, CWE Top 25, and modern attack patterns against web applications, APIs, and cloud-native services.
  • Experience integrating security tooling into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or equivalent).
  • Working knowledge of authentication and authorization patterns, including OAuth 2.0, OIDC, SAML, and modern session management.
  • Ability to communicate risk and remediation guidance to engineering audiences in language they will accept and act on.
  • Familiarity with containerization and cloud-native design (Docker, Kubernetes, etc.) and their security considerations.
  • Ability to win credibility with engineers and communicate risk in language they will act on.
  • Bachelor's degree in computer science, information security, or a related field, or equivalent practical experience.
Nice to Have
  • Experience working with code scanner platforms such as Fortify, Veracode, or Wiz Code
  • Cloud security experience in Azure and AWS, including hands-on time with CSPM and CNAPP tooling such as Wiz.
  • Exposure to API security testing, runtime application protection, and modern WAF tuning.
  • Industry certifications such as OSCP, OSWE, GWAPT, GPEN, or CISSP.
  • Experience with software supply chain security frameworks (SLSA, S2C2F, OpenSSF Scorecard).
  • Prior work in a distributed, multi-tenant, or franchise-like operational environment.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Specialist
Senior Application Security Specialist

A-Line Staffing Solutions • Charlotte (NC)

Hybrid
USD 56,000 - 94,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • United States

Remote
USD 83,000 - 152,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
Application Security or Security Engineer / Philadelphia
Application Security or Security Engineer / Philadelphia

Motion Recruitment Partners, LLC • Philadelphia

Hybrid
USD 110,000 - 170,000
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

WorkForce Unlimited • Salem (VA)

On-site
USD 110,000 - 150,000