Application Security Engineer

PACCAR

Renton (WA)

On-site

USD 90,000 - 141,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401k with company match
Employee Stock Purchase Program (ESPP)
Pension plan
Generous PTO and holidays
Tuition reimbursement
Health, dental, and vision plans
FSA/HSA

Job summary

PACCAR’s Information Technology Division in Renton, WA seeks an Application Security Engineer to guide development teams in secure coding, perform code reviews, and lead security testing for applications and APIs. You will promote a shift-left security culture and strengthen governance across the SDLC.

Join a team that emphasizes collaboration, continuous improvement, and practical risk-based approaches to protect PACCAR’s software portfolio, using tools like Burp Suite, OWASP ZAP, Fortify, and

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.
  • 5+ years of professional experience in application or software security, including hands-on work in secure code review, vulnerability assessment, threat analysis, or secure development practices.
  • Hands-on experience with application security testing tools, including DAST platforms (e.g., Burp Suite, WebInspect, OWASP ZAP) and SAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube).

Responsibilities

  • Perform source code reviews using manual analysis and SAST tools to identify vulnerabilities.
  • Execute web security assessments on websites, web applications, web services, and APIs using DAST tools.
  • Review test results from automated security tools and remove false positives.
  • Engage with development teams to provide vulnerability remediation support and guidance.
  • Integrate secure coding practices and security tooling into CI/CD pipelines.

Skills

C#
JavaScript
Python
Web security
OWASP Top 10
SDLC
Git / GitHub
Azure DevOps

Education

Bachelor's degree in CS/IS/SE/Cybersecurity

Tools

Burp Suite
OWASP ZAP
Fortify
Checkmarx
SonarQube

Job description

Company Information

PACCAR is a Fortune 500 company established in 1905. PACCAR Inc is recognized as a global leader in the commercial vehicle, financial, and customer service fields with internationally recognized brands such as Kenworth, Peterbilt, and DAF trucks. PACCAR is a global technology leader in the design, manufacture and customer support of high-quality light-, medium- and heavy-duty trucks under the Kenworth, Peterbilt and DAF nameplates. PACCAR designs and manufactures advanced diesel engines and also provides customized financial services, information technology and truck parts related to its principal business. Whether you want to design the transportation technology of tomorrow, support the staff functions of a dynamic, international leader, or build our excellent products and services - you can develop the career you desire with PACCAR. Get started!


Division Information

PACCAR's Information Technology Division (ITD), located in Renton, WA utilizes cutting-edge technology to provide systems development, consulting, voice and data communications services to the entire Corporation, which has high visibility in the technology sector.


Requisition Summary

As an Application Security Engineer, you will be a key member of the Global Security group within the IT Division at PACCAR and will be reporting directly to the Principal Engineer. You will provide security guidance to development teams, including secure code review and scanning, vulnerability assessments, and security testing to help application teams build and deploy secure applications and APIs.


In this role, you will support security governance and help ensure adherence to application security controls and risk analysis across the organization's application portfolio throughout the SDLC. This includes internally developed applications, third-party developed applications, commercial off-the-shelf (COTS) solutions, and open-source software.


You will utilize a risk-based methodology and \"shift-left\" approach to engage early in the software development lifecycle, working alongside engineering teams to help prevent security defects before they are introduced. You will contribute to a team culture that values openness, teamwork, continuous improvement, learning, commitment, and empathy.


Job Functions / Responsibilities

Security Assessments & Testing


  • Perform source code reviews using manual analysis and Static Application Security Testing (SAST) tools to identify vulnerabilities.

  • Execute web security assessments on websites, web applications, web services, and APIs using Dynamic Application Security Testing (DAST) tools.

  • Review test results from automated security tools, ensure automated tests complete successfully, and identify and remove false positives from tool reports.

  • Participate in developing and reviewing threat models to proactively identify security risks.


Developer Engagement & Remediation


  • Engage with development teams to provide vulnerability remediation support through consultation or hands‑on assistance.

  • Assist developers with understanding security defects, associated risk, and defining acceptable solutions to fix defects.

  • Collaborate with teams to integrate secure coding practices and security tooling into CI/CD pipelines.

  • Contribute to code reviews and design discussions with a security lens.


Security Governance & Standards


  • Support adherence to application security controls and contribute to risk analysis of applications across the SDLC.

  • Participate in the creation, maintenance, and communication of PACCAR secure coding standards, guidelines, and examples.

  • Support the implementation of secure design principles according to organizational policies, standards, and application security patterns.

  • Assist in creating technical security documents including assessment reports and remediation guidance.


Training & Culture


  • Share application security knowledge with the engineering team through brown bags, secure coding tournaments, and developer outreach activities.

  • Actively participate in improving security culture and awareness throughout the organization.

  • Participate in security incident response when needed.


Tooling & Automation


  • Help maintain and tune Secure SDLC tools including SAST, DAST, and Software Composition Analysis (SCA) platforms.

  • Support the integration of security tooling and automated security checks within CI/CD pipelines.

  • Stay current with security technologies, products, and emerging trends relevant to application security.


Qualifications


  • Basic Qualifications



    • Bachelors degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.

    • 5+ years of professional experience in application or software security, including hands‑on work in areas such as secure code review, vulnerability assessment, threat analysis, or secure development practices.



    • Hands-on experience with application security testing tools, including DAST platforms (e.g., Burp Suite, WebInspect, OWASP ZAP) and SAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube).

    • Proficiency in one or more programming languages: C#, JavaScript, and/or Python.

    • Strong working knowledge of web application technologies including HTTP, HTML, CSS, JavaScript.

    • Expert-level understanding of the OWASP Top 10 and common web application vulnerabilities and website security concepts such as headers, cookies, CORS, XSS, CSRF.

    • Familiarity with web authentication technologies such as OAuth and/or SAML.

    • Experience with Software Development Life Cycle (SDLC) and development methodologies such as Waterfall and Agile.

    • Experience with control systems: Git, GitHub, Azure DevOps


    Preferred Experience



    • Experience working in a large enterprise environment.

    • Experience with penetration testing or security tools (e.g., Kali Linux, Nmap).

    • Familiarity with cloud environments such as Azure, AWS, or GCP.

    • Certified Secure Software Lifecycle Professional (CSSLP)

    • Certified Information Systems Security Professional (CISSP)

    • CompTIA Security+



Additional Job Board Information

PACCAR Benefits

As a U.S. PACCAR employee, you have a full range of benefit options including:



  • 401k with up to a 5% company match

  • Employee Stock Purchase Program (ESPP)

  • Fully funded pension plan that provides monthly benefits after retirement

  • Comprehensive paid time off - minimum of 10 paid vacation days (additional days are provided with additional seniority/years of service), 12 paid holidays, and sick time

  • Tuition reimbursement for continued education

  • Medical, dental, and vision plans for you and your family

  • Flexible spending accounts (FSA) and health savings account (HSA)

  • Paid short-and long-term disability programs

  • Life and accidental death and dismemberment insurance

  • EAP services that include wellness plans, estate planning, financial counseling and more


PACCAR is an Equal Opportunity Employer/Protected Veteran/Disability. At PACCAR, we value talent and promote growth and development. We carefully consider numerous compensation factors, including your education, training, or experience. Applicants and employees for this position will not be sponsored for work authorization, including, but not limited to H-1B visas, now or in the future. The salary range for this position is $90,000 - $141,000 annually. Additionally, this role is eligible for the full range of benefit options listed above.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

PACCAR Inc • Renton (WA), Northern (KY)

Hybrid
USD 90,000 - 141,000
401k with up to 5% company match
Employee Stock Purchase Program (ESPP)
Pension plan
+1
2027 Winter Internship - Security Operations Intern
2027 Winter Internship - Security Operations Intern

PACCAR • Renton (WA)

On-site
USD 34,000 - 41,000
401k with company match
Sick Leave
Medical, dental, vision
+5
Financial Systems Analyst
Financial Systems Analyst

PACCAR • Bellevue (WA)

On-site
USD 104,000 - 160,000
Fully funded pension plan
401(k) with company match
Vacation days and holidays
+5
Software Development Manager (GR 32)
Software Development Manager (GR 32)

PACCAR • Bellevue (WA)

On-site
USD 119,000 - 186,000
Competitive salary
401k with company match
Pension plan
+3
Cybersecurity Engineer
Cybersecurity Engineer

PACCAR • Kirkland (WA)

On-site
USD 81,000 - 121,000
401k with up to a 5% company match
Pension plan
Paid time off and holidays
+5
Software Developer
Software Developer

PACCAR • McKinney (TX)

On-site
USD 90,000 - 120,000
401k with company match
Fully funded pension plan
Paid time off
Software Developer
Software Developer

Dynacraft, A PACCAR Company • Louisville (KY)

Hybrid
USD 85,000 - 120,000
401k with up to 5% company match
Fully funded pension plan
Paid time off and holidays
+7
Software Developer
Software Developer

PACCAR Inc • Louisville (KY), Northern (KY)

On-site
USD 85,000 - 110,000
401k match
Pension plan
Paid time off
+6
Software Developer
Software Developer

Paccar • McKinney (AR)

On-site
USD 90,000 - 120,000
401k with up to a 5% company match
Fully funded pension plan
Comprehensive PTO, holidays, and sick
+7
Senior Embedded Software Engineer
Senior Embedded Software Engineer

PACCAR • Sunnyvale (CA)

On-site
USD 135,000 - 212,000
401k with company match
Pension plan
Paid time off
+7