Application Security Engineer ( Only USC Or GC)

LinQ Global Group

Philadelphia (Philadelphia County)

Hybrid

USD 110,000 - 160,000

Full time

15 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

LinQ Global Group seeks an Application Security Engineer to lead the security model across a decentralized product engineering organization undergoing cloud modernization. You will design risk-tiering, integrate security gates into CI/CD, and guide secure coding practices.

This role focuses on threat modeling, secure authentication, container security, and collaboration with developers to remediate findings while building a Security Champions network across distributed teams.

Qualifications

  • Bachelor's degree or equivalent practical experience in CS/Info Security.
  • 4+ years of combined software, cloud, or AppSec experience with hands-on security.
  • Experience translating threat modeling findings into developer tasks.
  • Knowledge of OWASP Top 10/ASVS and modern web attack patterns.

Responsibilities

  • Catalog applications, pipelines, repos, and security tools to establish baseline.
  • Create and deploy a risk-tiering framework prioritizing high-risk apps.
  • Define and socialize a minimum AppSec baseline across engineering leads.
  • Build and lead a Security Champions network across teams.

Skills

Threat modeling
Security architecture
Communicating risk
Security strategy
Cloud security
Vulnerability assessment

Education

Bachelor's degree in CS or Information Security

Tools

GitHub Actions
Azure DevOps
GitLab CI
Jenkins
Docker
Kubernetes

Job description

Application Security Engineer ( Only USC Or GC)

Job Title: Application Security Engineer

Location: Philadelphia, PA 19103 (Hybrid)

Type: 6-Month Contract-to-Hire (CTH)

Job Summary

We are seeking an Application Security Engineer to join our Cyber Defense & Engineering (CDE) team who will be responsible to establish, scale, and own the Application Security operating model across a decentralized product engineering organization undergoing cloud modernization. They will be focused on creating a scalable AppSec capability rather than managing a legacy program. They will design risk-tiering frameworks, integrate automated security gates into CI/CD pipelines, lead threat modeling for cloud migrations, and establish a Security Champions network to embed secure coding practices directly into development teams.

Key Responsibilities
  • Catalog applications, development pipelines, source repositories, and existing security tools across decentralized teams to establish an accurate baseline.
  • Create and deploy a risk-tiering framework to prioritize security efforts and resources on high-risk applications.
  • Define, publish, and socialize a minimum application security baseline across engineering leadership regardless of team tooling or SDLC variations.
  • Build, launch, and lead a Security Champions network across distributed product engineering teams to scale security practices natively.
  • Lead threat modeling exercises (STRIDE/PASTA) for monolith-to-microservices re-architecture, containerization, and cloud migration projects.
  • Provide technical architectural guidance during cloud migration decisions to identify security trade-offs before architecture is locked.
  • Integrate static and dynamic security testing tools seamlessly into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins).
  • Triage, validate, and prioritize vulnerabilities from automated scanners, penetration tests, bug bounty programs, and detection alerts.
  • Partner with Security Operations and Incident Response teams on application-layer incidents, analyzing attack paths and exploit feasibility.
  • Define and track key performance indicators for application coverage, risk tiering, vulnerability density, and remediation velocity.
  • Evaluate and enforce secure authentication and authorization implementation, including OAuth 2.0, OIDC, SAML, and session management.
  • Review unfamiliar codebases across diverse languages, configure security scanning engines, and partner with developers to guide remediation.
Required Skills & Experience
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
  • 4+ years of combined experience in software engineering, cloud engineering, or application security, including direct hands-on security responsibilities.
  • Demonstrated capability in executing threat modeling frameworks (STRIDE, PASTA, or equivalent) and translating findings into actionable developer tasks.
  • Strong technical depth in OWASP Top 10, OWASP ASVS, CWE Top 25, and modern attack patterns against web applications, REST APIs, and microservices.
  • Experience embedding security tooling into modern CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins).
  • Solid working knowledge of enterprise authentication and authorization standards (OAuth 2.0, OIDC, SAML) and session security.
  • Familiarity with containerization and cloud-native architecture (Docker, Kubernetes) and their associated security vectors.
  • Ability to communicate risk and remediation guidance to engineering audiences in language they will accept and act on.
Preferred Qualifications
  • Experience configuring and tuning enterprise code scanning platforms (Fortify, Veracode, Wiz Code).
  • Exposure to Azure/AWS security controls, CSPM, and CNAPP tooling (e.g., Wiz).
  • Hands-on experience with API security testing, runtime application protection (RASP), and WAF tuning.
  • Active professional security certifications such as OSCP, OSWE, GWAPT, GPEN, or CISSP.
  • Familiarity with supply chain security frameworks (SLSA, S2C2F, OpenSSF Scorecard).
  • Prior work in a distributed, multi-tenant, or franchise-like operational environment.

Equal Opportunity Employer, including disabled and veterans.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Engineering Manager
Application Security Engineering Manager

Glocomms • Philadelphia

Hybrid
USD 150,000 - 210,000
14% match 401(k)
Comprehensive benefits and rewards
Opportunity to shape security for enterprise-scale applications
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Senior Application Security Engineer DevSecOps and CICD
Senior Application Security Engineer DevSecOps and CICD

3Core Systems, Inc • Chicago (IL), Northern (KY)

Hybrid
USD 120,000 - 150,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Application Security Engineer
Application Security Engineer

Experienced Recruiting Partners, LLC. • City of Albany (NY)

On-site
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Eliassen Group • Washington

On-site
USD 90,000 - 120,000
Application Security Engineer
Application Security Engineer

Hampton North • United States

Remote
USD 110,000 - 150,000
Security Application Engineer-Need GC and USC
Security Application Engineer-Need GC and USC

USM • Seattle (WA)

On-site
USD 80,000 - 120,000