Application Security Engineer: Threat Modeling & Automation

Embedded Shishya

United States

Remote

USD 180,000 - 200,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible PTO
Learning & Development stipend
Headspace access
401K + stock options
Full medical, dental, vision

Job summary

Virtru is seeking an Application Security Engineer to join our product security team. You will help secure our platform built on Go and JavaScript, collaborating with development and SRE to strengthen security across the software development lifecycle.

An ideal candidate has 4+ years in secure development, a strong foundation in cryptography, and hands-on experience with bug bounty, vulnerability management, threat modeling, and SAST/DAST/IAST tooling within cloud environments.

Qualifications

  • 4+ years in secure development or application security.
  • Deep knowledge of authentication and web architecture.
  • Experience with Node.js and Go.
  • Experience running bug-bounty, pentesting, vulnerability scanning programs.
  • Experience setting up and maintaining SAST, DAST, IAST and SCA tooling.
  • Familiarity with security tools such as Burp, ZAP, Qualys, Nessus.

Responsibilities

  • Security Engineering and collaboration with development, SRE, and stakeholders to promote security across the SDLC.
  • Identify and implement security improvements independently.
  • Implement, manage, and automate vulnerability management processes.
  • Prioritize and remediate vulnerabilities from internal scans, pentests, and bug bounties.
  • Conduct threat modeling, code audits, and design reviews with engineers.
  • Establish and automate threat hunting capabilities; enhance security event logging.
  • Integrate and manage dynamic and static code analysis tools; ensure tooling operates in the pipeline.

Tools

Burp
ZAP
Qualys
Nessus

Job description

Virtru is seeking an Application Security Engineer to join our product security team. You will help secure our platform built on Go and JavaScript, collaborating with development and SRE to strengthen security across the software development lifecycle.

An ideal candidate has 4+ years in secure development, a strong foundation in cryptography, and hands-on experience with bug bounty, vulnerability management, threat modeling, and SAST/DAST/IAST tooling within cloud environments.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer: Threat Modeling & Patches
Senior Security Engineer: Threat Modeling & Patches

Stravexa Private Limited • United States

On-site
USD 140,000 - 210,000
Product Security Engineer — Threat Modeling & Open Source
Product Security Engineer — Threat Modeling & Open Source

Vercel • United States

Hybrid
USD 208,000 - 312,000
Competitive compensation package
Flexible Time Off
Mentorship and professional development
Application Security Engineer — Hands-on Threat Modeling
Application Security Engineer — Hands-on Threat Modeling

Omnissa, LLC in • Atlanta (GA)

Hybrid
USD 112,000 - 186,000
Employee ownership
Health insurance
401k with matching
Application Security Engineer - Secure SaaS at Scale
Application Security Engineer - Secure SaaS at Scale

InvestedintheMission • United States

Remote
USD 160,000 - 210,000
Health insurance
100% remote - work from anywhere in US
401k matching
+4
Product Security Engineer: Threat Modeling & Open Source
Product Security Engineer: Threat Modeling & Open Source

Vercel • San Francisco (CA)

On-site
USD 208,000 - 312,000
Competitive compensation package, including equity.
Inclusive Healthcare Package.
Flexible Time Off.
Product Security Engineer - Threat Modeling & Secure Dev
Product Security Engineer - Threat Modeling & Secure Dev

Insight Global • North Reading (MA)

Hybrid
USD 70,000 - 117,000
Senior Application Security Engineer: Threat Modeling & Automation
Senior Application Security Engineer: Threat Modeling & Automation

Amazon • Seattle (WA)

On-site
USD 178,000 - 227,000
Health insurance
RSU eligibility
401(k) matching
+1
Staff Engineer, Application Security
Staff Engineer, Application Security

BetterCloud • Buffalo (NY)

On-site
USD 110,000 - 170,000
Application Security Engineer - Threat Modelling & Secure Coding
Application Security Engineer - Threat Modelling & Secure Coding

Open Systems Technologies • New York (NY)

On-site
USD 150,000 - 200,000
Senior DevSecOps Engineer: Secure Cloud & Automation
Senior DevSecOps Engineer: Secure Cloud & Automation

Virtuous • United States

Remote
USD 150,000 - 190,000
Competitive pay and Carta data-based另外
Bonus and recognition (Bonusly)
401(k) with company matching
+5