Enable job alerts via email!

Application Security Specialist 100% Remote working

Shtudy

New York (NY)

Remote

USD 80,000 - 120,000

Full time

22 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking an Application Security Specialist to enhance security practices in the software development lifecycle. This role involves collaborating with engineering, DevOps, and product teams to identify and mitigate vulnerabilities in web, mobile, and cloud applications. You will lead security assessments, manage vulnerability reports, and develop secure coding guidelines. This position allows you to work remotely from anywhere in the U.S., offering a flexible schedule and a supportive environment focused on professional development and inclusion. Join a team dedicated to fostering a proactive security culture and ensuring products are secure by design.

Benefits

100% Remote Work
Competitive Salary and performance-based bonuses
Comprehensive Benefits Package
Generous Paid Time Off
Professional Development Support
Home Office Stipend
Inclusive Culture

Qualifications

  • 3+ years of experience in Application Security or Secure Software Development.
  • Strong knowledge of web application vulnerabilities and mitigation techniques.

Responsibilities

  • Integrate security best practices into CI/CD pipelines with development teams.
  • Conduct application threat modelling and security assessments.

Skills

Application Security
Secure Software Development
Web Application Vulnerabilities
Threat Modelling
Security Testing
DevSecOps

Education

3+ years of experience in Application Security
Industry certifications (OSCP, GWAPT, etc.)

Tools

Burp Suite
OWASP ZAP
Veracode
Checkmarx
Snyk
GitHub Actions
GitLab CI
Jenkins
Microsoft Threat Modelling Tool
Postman

Job description

Application Security Specialist 100% Remote working

New York, United States | Posted on 04/16/2025

Job Title: Application Security Specialist

Location: Remote (USA-based)

Job Type: Full-Time

Department: Information Security / DevSecOps

About the role:

As an Application Security Specialist, you will play a critical role in integrating security practices into our software development lifecycle. You’ll work closely with engineering, DevOps, product, and QA teams to identify, remediate, and prevent vulnerabilities across web, mobile, and cloud-based applications. Your expertise will help shape a proactive security culture and ensure our products are secure by design.

Key Responsibilities
  1. Collaborate with development teams to integrate security best practices into CI/CD pipelines.
  2. Conduct application threat modelling, architecture reviews, and code analysis to identify security gaps.
  3. Perform manual and automated application security assessments (SAST, DAST, IAST, SCA).
  4. Provide clear and actionable remediation guidance to development and product teams.
  5. Manage and triage vulnerability reports from internal tools and third-party sources (e.g., bug bounty programs, penetration testing).
  6. Develop and maintain secure coding guidelines and training for engineers.
  7. Stay current with emerging security threats, tools, and technologies.
  8. Lead security incident investigations related to application vulnerabilities and support root cause analysis.
  9. Contribute to the development of security standards, policies, and risk assessments.
Requirements
  1. 3+ years of experience in Application Security, Secure Software Development, or similar roles.
  2. Strong knowledge of web application vulnerabilities (e.g., OWASP Top 10) and related mitigation techniques.
  3. Experience with security testing tools like Burp Suite, OWASP ZAP, Veracode, Checkmarx, Snyk, or similar.
  4. Familiarity with DevSecOps practices and integrating security into CI/CD workflows (GitHub Actions, GitLab CI, Jenkins, etc.).
Preferred Qualifications
  1. Industry certifications such as OSCP, GWAPT, CSSLP, CEH, or similar.
  2. Experience with container and Kubernetes security.
  3. Exposure to threat modelling tools like Microsoft Threat Modelling Tool or IriusRisk.
  4. Experience with API security testing tools (e.g., Postman, OWASP API Security Top 10).
Benefits
  1. 100% Remote Work: Work from anywhere in the U.S. with flexible hours.
  2. Competitive Salary and performance-based bonuses.
  3. Comprehensive Benefits Package including medical, dental, and vision insurance.
  4. Generous Paid Time Off including vacation, sick leave, holidays, and volunteer time.
  5. Professional Development Support including certifications, training, and conference opportunities.
  6. Home Office Stipend to set up your ideal remote workspace.
  7. Inclusive Culture that values diversity, equity, and belonging.

We celebrate diversity and are committed to creating an inclusive environment for all employees regardless of race, color, religion, gender identity or expression, sexual orientation, national origin, disability, age, or veteran status.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.