Application Security Engineer

Tential Solutions

United States

On-site

USD 120,000 - 180,000

Full time

26 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

PTO
Benefits package
Career growth

Job summary

Tential Solutions is seeking an experienced Application Security Engineer to serve as a trusted security advisor embedded within our Agile development organization. This role partners with software engineering teams to integrate security throughout the SDLC, ensuring applications and APIs are designed, built, and deployed securely.

This role will advance application security practices, drive DevSecOps maturity, and help development teams proactively identify and remediate security risks.

Qualifications

  • 5+ years in Application Security, Secure Software Development, DevSecOps, or related cybersecurity discipline.
  • Hands-on in threat modeling and security architecture reviews.
  • Strong understanding of vulnerability management and remediation processes.
  • Experience with security testing programs using SAST, DAST, and SCA.
  • Knowledge of OWASP Top 10, SANS/CWE vulnerabilities, and secure coding principles.
  • Experience partnering directly with software development teams.

Responsibilities

  • Serve as the primary Application Security advisor for development teams.
  • Embed security best practices throughout the SDLC.
  • Conduct threat modeling and security risk assessments for applications and APIs.
  • Review architectures, data flows, and new features for security.
  • Validate, triage, and remediate vulnerabilities from security tools.
  • Support sprint planning and Agile ceremonies to embed security requirements.
  • Promote secure coding practices and maturity of DevSecOps programs.
  • Translate security risks into actionable business recommendations.

Skills

Threat modeling
Security architecture reviews
Vulnerability management
SAST/DAST/SCA
OWASP Top 10
DevSecOps
Secure SDLC
Code analysis
Communication

Tools

Burp Suite
OWASP ZAP
Wireshark
Nessus
Qualys
Metasploit

Job description

Our client is seeking an experienced Application Security Engineer to serve as a trusted security advisor embedded within our Agile development organization. This role will partner closely with software engineering teams to integrate security throughout the Software Development Lifecycle (SDLC), helping ensure applications and APIs are designed, built, and deployed securely.

This individual will play a critical role in advancing application security practices, driving DevSecOps maturity, and helping development teams proactively identify and remediate security risks. The ideal candidate combines strong application security expertise with the ability to collaborate effectively with developers and technical stakeholders.

About The Team
  • Support approximately 100 software engineers across multiple engineering teams.
  • Partner directly with 6 Scrum teams in an Agile environment.
  • Join a highly visible Application Security function with significant opportunity to influence processes and strategy.
  • Work primarily within a Microsoft-based technology ecosystem featuring C#, .NET Framework, SOAP services, APIs, and enterprise applications.
  • Help drive the evolution and maturity of a growing DevSecOps and Application Security program.
Key Responsibilities
  • Serve as the primary Application Security advisor for development teams.
  • Embed security best practices throughout the Software Development Lifecycle (SDLC).
  • Conduct threat modeling exercises and security risk assessments for applications and APIs.
  • Review application architectures, designs, data flows, and new feature implementations from a security perspective.
  • Validate, triage, and prioritize vulnerabilities identified through:
    • SAST tools
    • DAST tools
    • Software Composition Analysis (SCA)
    • Vulnerability assessments
    • Penetration testing activities
  • Provide remediation guidance and work directly with development teams to resolve security findings.
  • Participate in sprint planning sessions and Agile ceremonies to ensure security requirements are incorporated early in the development process.
  • Support the deployment, tuning, and ongoing effectiveness of application security testing programs.
  • Promote secure coding practices and mentor engineering teams on application security concepts.
  • Assist in developing and maturing DevSecOps processes, standards, and automation capabilities.
  • Translate technical security risks into actionable business recommendations.
Required Qualifications
  • 5+ years of experience in Application Security, Secure Software Development, DevSecOps, or a related cybersecurity discipline.
  • Hands-on experience performing threat modeling and security architecture reviews.
  • Strong understanding of vulnerability management and remediation processes.
  • Experience supporting security testing programs utilizing:
    • SAST
    • DAST
    • SCA
  • Knowledge of OWASP Top 10, SANS/CWE vulnerabilities, and secure coding principles.
  • Experience partnering directly with software development teams.
  • Understanding of secure SDLC methodologies and DevSecOps practices.
  • Ability to analyze source code and identify security concerns.
  • Strong verbal and written communication skills.
Preferred Qualifications
  • Experience working in C#/.NET or Java development environments.
  • Previous experience as a software engineer who transitioned into security.
  • Experience securing APIs, web applications, and enterprise software platforms.
  • Familiarity with security tools such as:
    • Burp Suite
    • OWASP ZAP
    • Wireshark
    • Nessus
    • Qualys
    • Metasploit
  • Experience with WAF technologies, API security platforms, and API gateways.
  • Exposure to Azure and/or AWS security controls.
  • Knowledge of security frameworks such as NIST, ISO 27001, OWASP SAMM, Microsoft SDL, or BSIMM.
  • Experience integrating security controls into CI/CD pipelines.
What We're Looking For

The ideal candidate is a security-first professional who understands how modern applications are built and can effectively influence engineering teams. While familiarity with software development is valuable, we are prioritizing deep Application Security expertise, including threat modeling, vulnerability management, security testing, and secure SDLC practices.

Why Join Us?
  • Opportunity to help shape and influence the Application Security program.
  • High-visibility role with direct impact across engineering teams.
  • Strong executive support for cybersecurity and technology initiatives.
  • Collaborative, growth-oriented culture.
  • Company-wide focus on innovation and AI-driven transformation.
  • Competitive compensation, benefits, and PTO.
  • Opportunity to make a meaningful impact while helping mature security capabilities across a large development organization.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Ringside Talent • Columbus (OH)

On-site
USD 110,000 - 140,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Irving (IA)

On-site
USD 130,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • West Palm Beach (FL)

Hybrid
USD 140,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Tampa (FL)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Dallas (TX)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Texas City (IL)

Hybrid
USD 140,000 - 200,000
Professional growth
Competitive compensation (USD)
Exciting projects with Fortune 500s
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Blacksburg (SC)

Hybrid
USD 130,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Boston (MA)

On-site
USD 140,000 - 190,000
Professional growth
Competitive USD-based compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Boca Raton (FL)

Hybrid
USD 120,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1