Application Security Engineer — Threat Modeling & Secure CI/CD

Jobtailor

California (MO)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Application Security Engineer to shape secure product decisions from day one and lead the security program across engineering teams.

You will drive threat modeling, design secure architectures, implement SAST/DAST in CI/CD, perform code reviews, and partner with developers to embed secure coding standards and AI security practices to accelerate secure software delivery.

Qualifications

  • Minimum 4 years of hands-on experience in application security engineering.
  • Proven track record of securing large-scale production systems.
  • Understanding of developer experience and developer workflows for shipping features and products.
  • Technical expertise in at least two programming languages: Python, Java, Go, or JavaScript/TypeScript.
  • Ability to read and review code across multiple languages, understanding business logic and security implications.
  • Knowledge of SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices.
  • Excellent communication skills for translating complex security concepts to technical and non-technical audiences.
  • Alignment with WRITER's values of Connect, Challenge, and Own.
  • Role open to Mid, Sr. and Staff level candidates.

Responsibilities

  • Conduct threat modeling sessions with product teams
  • Design secure architectures for new features
  • Ensure security considerations shape product decisions from day one
  • Own and evolve the application security program
  • Establish and maintain SAST/DAST scanning in CI/CD pipelines
  • Conduct security code reviews for critical changes
  • Build automation to catch vulnerabilities before production
  • Partner with engineering teams to establish secure coding standards
  • Create reusable security patterns and libraries
  • Design and recommend security features and products for customer environments
  • Integrate and leverage AI agents to increase security-team and engineering velocity
  • Lead security assessments and penetration testing of applications, AI services, and APIs
  • Identify vulnerabilities and collaborate with teams on remediation at scale
  • Design and implement security controls for data pipelines, model training environments, and customer-facing AI agents
  • Research emerging LLM and generative-AI attack vectors and build proactive defenses
  • Report to the head of security engineering

Skills

Threat Modeling
Secure Architecture
Vulnerability Management
Security Assessments
Penetration Testing
Vulnerability Automation
Security Controls
Code Review
AI Security
Security Testing
DevSecOps
Communication Skills

Tools

SAST/DAST Tools

Job description

Jobtailor is seeking an experienced Application Security Engineer to shape secure product decisions from day one and lead the security program across engineering teams.

You will drive threat modeling, design secure architectures, implement SAST/DAST in CI/CD, perform code reviews, and partner with developers to embed secure coding standards and AI security practices to accelerate secure software delivery.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer: Threat Modeling & Static Analysis
Senior Security Engineer: Threat Modeling & Static Analysis

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
AI Security Engineer - Threat Modeling & Secure Deployments
AI Security Engineer - Threat Modeling & Secure Deployments

Jobtailor • Brooklyn Park (MN)

On-site
USD 120,000 - 150,000
Application Security Engineer: Threat Modeling & Secure SDLC
Application Security Engineer: Threat Modeling & Secure SDLC

CrowdStrike • United States

On-site
USD 120,000 - 180,000
Market-leading compensation
Wellness programs
PTO & holidays
+4
Senior AppSec Engineer: AI-Driven Secure SDLC Lead
Senior AppSec Engineer: AI-Driven Secure SDLC Lead

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Application Security Engineer — Hands-On, CI/CD & Threat Modeling
Application Security Engineer — Hands-On, CI/CD & Threat Modeling

Motion Recruitment Partners LLC • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Application Security Engineer — Secure Coding & Threat Modeling
Application Security Engineer — Secure Coding & Threat Modeling

OpenAI • Washington

Hybrid
USD 140,000 - 190,000
Relocation assistance
Hybrid work model
Lead Application Security Engineer: Threat Modeling & Secure SDLC
Lead Application Security Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • Burlington (VT), Northern (KY)

Hybrid
USD 120,000 - 160,000
Application Security Engineer II - Build Secure, Scalable Apps
Application Security Engineer II - Build Secure, Scalable Apps

Talanto • Northern (KY)

Hybrid
USD 7,500 - 11,000
Health insurance
401(k) plan and match
Annual performance bonus
+3
Senior DevSecOps Security Auditor
Senior DevSecOps Security Auditor

Jobtailor • Missouri

On-site
USD 120,000 - 180,000
Remote Product Security Engineer: Threat Modeling
Remote Product Security Engineer: Threat Modeling

YipitData • United States

Remote
USD 162,000 - 198,000
401K match
Parental leave
Flexible vacation
+1