Application Security Engineer

Softswiss

Town of Poland (NY)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private health insurance
Sports benefits
Free English lessons (online)
Paid time off
Maternity leave support
Referral program rewards

Job summary

SOFTSWISS is seeking an Application Security Engineer to ensure secure software deployment and hardened applications throughout the SDLC. You will partner with product teams to identify and mitigate vulnerabilities, driving secure coding practices and proactive risk management.

You will perform in-depth security reviews, tune scanning tools, and develop automation to streamline security tasks while collaborating across engineering teams to improve the overall security posture.

Qualifications

  • 3+ years of experience in application security or related roles.
  • Knowledge of web application security mechanisms (SOP, CORS, CSP).
  • Understanding of OWASP Top 10 and mitigation strategies.
  • Secure-by-design principles and secure software development lifecycle.

Responsibilities

  • Partner with product teams during design to perform threat modeling and risk assessments.
  • Conduct manual code reviews to identify vulnerabilities in critical applications.
  • Tune automated security scanning tools to reduce false positives and improve detection.
  • Develop scripts to automate security workflows and streamline analysis.
  • Assist developers in understanding security risks from risk assessments and threat modeling.
  • Coordinate triage of vulnerabilities from bug bounty program with researchers and engineers.
  • Provide security guidance to Dev/QA teams throughout SDLC and maintain internal security knowledge base.

Skills

Application security
Threat modeling
Code reviews
Security awareness

Education

University degree in Computer Science or Information Security

Tools

SAST/DAST tools

Job description

Security | Application Security Engineer

SOFTSWISS is growing, and we are seeking a skilled Application Security Engineer to join our team. If you are driven by excellence and share our values, we would love to hear from you.

Purpose of the role

Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers.

As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products.

Key responsibilities
  • Partner with product teams during the design phase to facilitate threat modeling and risk assessment sessions.
  • Perform in-depth manual code reviews on critical applications to identify logical vulnerabilities as part of white-box security assessments.
  • Tune and adjust rulesets for automated security scanning tools to reduce false positives and improve detection rates.
  • Develop scripts and automation tools to streamline workflows and free up time for more complex analysis.
  • Assist developers in understanding security risks and threats discovered during risk assessments, threat modeling, and dynamic testing.
  • Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws.
  • Collaborate with Dev/QA teams throughout the development lifecycle to enhance the application’s security posture by providing dedicated security consulting, continuous knowledge sharing, and actionable guidance.
  • Develop and maintain the internal security knowledge base, including comprehensive secure coding guidelines and technical manuals for standard security features.
Required Experience
  • 3+ years of experience in application security, software development, or related technical roles.
  • Knowledge of web application security mechanisms and controls (e.g., SOP, CORS, CSP).
  • Comprehensive understanding of common web vulnerabilities (e.g., OWASP Top 10) and their practical mitigation strategies.
  • Knowledge of secure system and application architecture alongside secure-by-design principles.
  • Practical, hands‑on expertise in identifying vulnerabilities through manual security assessments and secure code reviews.
  • Ability to clearly articulate and explain the business impact of identified threats and vulnerabilities to developers and product teams.
  • A strong security‑first mindset with a continuous drive to learn and achieve excellence in the cybersecurity field.
  • University degree in Computer Science, Information Security, or a related field (or an equivalent combination of education and practical experience).
  • English and Russian proficiency at an upper‑intermediate level (B2+)
Nice to have
  • Passion about programming.
  • Technical knowledge of network and operating systems security.
  • Practice of participation in bug bounty programs and/or CTFs.
  • Knowledge of SAST/DAST tools, including customization.
Main Advantages
  • Private health insurance
  • Sports benefits
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Specialist
Security Specialist

Softswiss • Georgia

Hybrid
USD 70,000 - 110,000
Private health insurance
Sports benefits
Free English lessons (online)
+5
Product Security Engineer
Product Security Engineer

GoMining • United States

Hybrid
USD 120,000 - 190,000
Courses & conferences support (up to )
Remote or hybrid format with flexible,
Paid time off and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Hybrid
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

Hybrid
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Application Security Engineer
Application Security Engineer

ManpowerGroup Global, Inc. • Phoenix (AZ)

Hybrid
Medical and Prescription Drug Plans
Dental Plan
Vision Plan
+3
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Application Security Manager
Application Security Manager

Alter Domus • New York (NY)

On-site
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
24/7 Employee Assistance Program
Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan
Security Engineer (AppSec)
Security Engineer (AppSec)

SysLogic, Inc. • Town of Brookfield (WI)

On-site
USD 80,000 - 110,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (401k)
Life Insurance (Basic, Voluntary & AD&D)
+6