Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

The Mom Project

Charlotte (NC)

Hybrid

USD 140,000 - 190,000

Full time

5 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical
Dental
401k

Job summary

The Mom Project is seeking a Technical Application Security Engineer on a 6-month contract to hire basis in a hybrid role, with options in New York, NY or Charlotte, NC. The role focuses on deploying and operating modern AppSec tooling, defining secure SDLC requirements, and guiding AI-assisted triage workflows.

You will partner with business units to integrate security into pipelines, evaluate emerging security tooling, and deliver executive-ready metrics linking AppSec activity to risk

Qualifications

  • 7+ years in application security, product security, or security engineering.
  • Hands-on experience deploying modern AppSec tooling.
  • Proficient in multiple languages and CI/CD integrations.

Responsibilities

  • Inventory applications across units and map ownership.
  • Operate AppSec tooling integrated into CI/CD pipelines.
  • Design AI-assisted triage workflows to reduce noise.
  • Define secure SDLC requirements and threat modeling practices.
  • Collaborate with development leaders to operationalize AppSec.

Skills

Python
JavaScript/TypeScript
Java
C#
CI/CD

Tools

Semgrep
Snyk
Checkmarx
Veracode
Apiiro
GitHub Advanced Security

Job description

  • Please note, that all applicants applying for US job openings must be legally authorized to work in the United States.***
  • Please note, that all applicants applying for US job openings must be legally authorized to work in the United States.***

Our Customer is a leading global, diversified information, services and media company with more than 360 businesses. Its major interests include various financial services, medical information and services businesses, and lastly, ownership in cable television networks such as A&E, HISTORY, Lifetime and ESPN; 33 television stations; 24 daily and 52 weekly newspapers; digital services businesses; and nearly 250 magazines around the world.

We are seeking a Technical Application Security Engineer on a contract basis to support their business needs. This role is hybrid in either New York, NY or Charlotte, NC. This is a 6-month contract to hire position.

Responsibilities
  • Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering.
  • Standing up and operating the AppSec tooling stack — SAST, SCA, secrets scanning, and container/IaC scanning — integrated into business unit CI/CD pipelines.
  • Designing and implementing AI-assisted triage workflows on top of AppSec tooling so that finding volume does not overwhelm developers and false positives are filtered before reaching engineering teams.
  • Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process.
  • Partnering with business unit development leaders to build the relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.
  • Contributing to AI security strategy — evaluating emerging tools (AI code review assistants, agentic security testing, automated security requirement generation) and recommending what to operationalize and what to defer.
  • Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction.
Required Qualifications
  • 7+ years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.
  • Hands-on experience deploying and operating modern AppSec tooling (e.g., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security).
  • Working code-level proficiency in at least three commonly-used languages (e.g., Python, JavaScript/TypeScript, Java, C#, Go) sufficient to read, review, and triage findings.
  • Strong scripting and automation skills in Python or equivalent; comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
  • Demonstrated ability to influence engineering organizations without direct authority — negotiating standards, driving adoption, and partnering with development leaders.
  • Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks.
Preferred Qualifications
  • Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).
  • Familiarity with one or more compliance frameworks relevant to our environment (HITRUST, HIPAA, NIST AI RMF, SOC 2).
  • Prior experience working in a regulated or healthcare-adjacent environment.
  • Cloud security depth in at least one major provider (AWS, Azure, GCP).
  • Public contribution to AppSec community — OSS, conference talks, published research, or detection/rule contributions.

We offer a competitive salary range for this position. Most candidates who join our team are hired at the median of this range, ensuring fair and equitable compensation based on experience and qualifications.

Perks are available through our 3rd Party Employer of Record

Available upon completion of waiting period for eligible engagements.

  • Medical
  • Dental
  • 401k (no match)

Please note: In order to create a safe, productive work environment, our client is requiring all contractors who plan to be onsite to be fully vaccinated according to the CDC guidelines. Prior to coming into our offices, contractors will be required to attest that they are fully vaccinated.

An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

The Mom Project • New York (NY)

Hybrid
USD 140,000 - 190,000
Medical
Dental
401k (no match)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

BBG Ventures, LLC • New York (NY)

Hybrid
USD 120,000 - 180,000
Medical, Dental, and 401k (no match)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

BBG Ventures, LLC • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Medical, Dental, and 401k (no match)
Application Security Engineer
Application Security Engineer

Australia-Employment • New York (NY)

On-site
USD 83,000 - 96,000
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Jobot Consulting • Charlotte (NC)

Hybrid
USD 83,000 - 96,000
Application Security Engineer
Application Security Engineer

Jobot Consulting • New York (NY)

Hybrid
USD 125,000 - 146,000
Application Security Engineer - Chandler, AZ
Application Security Engineer - Chandler, AZ

Motion Recruitment Partners LLC • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Application Security Engineer-68257
Application Security Engineer-68257

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Senior Product Security Engineer
Senior Product Security Engineer

Gofractional • Northern (KY)

Hybrid
USD 83,000 - 165,000
Medical coverage
Dental coverage
Vision coverage
+7