Enable job alerts via email!

Security Engineer - Application Security

n3xt Inc.

United States

Remote

USD 150,000 - 210,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

N3XT Inc. seeks a passionate Security Engineer specializing in Application Security to enhance their development lifecycle with robust security practices. Ideal candidates will have 5+ years of experience, focusing on security architecture, vulnerability fixing, and collaboration with development teams for secure software delivery.

Qualifications

  • 5+ years in security engineering focused on application security.
  • Proficiency in JavaScript/TypeScript, specifically Next.js/Node.js.
  • Understanding of common application vulnerabilities (OWASP Top 10).

Responsibilities

  • Drive security best practices into the SDLC.
  • Implement and manage automated application security tools.
  • Conduct regular application security testing and vulnerability remediation.

Skills

Secure coding
Threat modeling
Vulnerability assessment
Application security testing
Scripting for automation

Education

Bachelor's degree in Computer Science or related field

Tools

Burp Suite
OWASP ZAP
GitHub Advanced Security

Job description

Security Engineer - Application Security

Join to apply for the Security Engineer - Application Security role at N3XT

Continue with Google Continue with Google

Security Engineer - Application Security

Join to apply for the Security Engineer - Application Security role at N3XT

Get AI-powered advice on this job and more exclusive features.

Sign in to access AI-powered advices

Continue with Google Continue with Google

Continue with Google Continue with Google

Continue with Google Continue with Google

Continue with Google Continue with Google

Continue with Google Continue with Google

Continue with Google Continue with Google

Liberating Money

Liberating Money

Security Engineer - Application Security

We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle (SDLC), from design to deployment. This role is key to building secure, resilient applications while fostering a culture where security is a seamless part of innovation.

We're seeking candidates with at least five years of experience in software development and application security in a production environment. This isn't just about identifying issues; you'll be on the front lines, directly involved in fixing vulnerabilities and implementing secure code changes. Responsibilities will vary based on experience, with senior engineers leading strategic initiatives and automation, and others focusing on foundational practices. This is a collaborative role, balancing security with developer velocity and operational efficiency, ensuring security enables fast delivery of secure software.

Responsibilities

  • Drive security best practices into the SDLC, including security architecture reviews, threat modeling, and secure coding guidance.
  • Implement and manage automated application security tools (SAST, DAST, SCA) in CI/CD pipelines for credential scanning, static/dynamic analysis, and dependency scanning.
  • Conduct regular application security testing, coordinate third-party assessments, and actively participate in fixing identified vulnerabilities.
  • Configure and maintain Web Application Firewalls (WAF) to protect applications.
  • Design and implement security controls for APIs, including authentication, authorization, and API gateway policies.
  • Implement security controls for cloud-deployed applications, leveraging cloud-native security services for threat detection.
  • Deploy and manage application-focused SIEM detections, centralize application log collection, and support security monitoring. Participate in incident response for application-specific threats.
  • Develop and maintain application security policies, standards, and guidelines (e.g., OWASP Top 10, NIST, ISO 27001).
  • Work closely with Full Stack Engineers to educate them on secure coding practices, provide training, and empower them to build secure applications.
  • Collaborate with product engineering, DevOps, and SRE teams to implement secure, usable, and efficient security solutions.

Required Experience

  • 5+ years in security engineering, with a strong focus on application security.
  • Demonstrated software development background with proficiency in writing and fixing code, ideally in languages like JavaScript/TypeScript (Next.js/Node.js). You'll be expected to contribute directly to codebases to implement security fixes and features.
  • Expertise in SSDLC principles including threat modeling, secure design patterns, and secure coding.
  • Hands-on experience with commercial and open source application security scanning tools (e.g., GitHub Advanced Security, Pnpm audit, Nodejsscan, Burp Suite, Invicti, OWASP ZAP, Gitleaks) for SAST, DAST, SCA, and secret detection.
  • Strong understanding and practical experience with Web Application Firewalls (WAFs).
  • Proficiency in cloud security controls for applications (e.g., GCP, Cloud Armor, Security Command Center, IAM hardening, Cloud Logging).
  • Solid understanding of API security best practices and experience securing RESTful, tRPC and GraphQL APIs.
  • Proficiency in SIEM & log management for application security, including log aggregation, correlation, visualization and threat detection.
  • Proficiency in scripting for automation and integrating security tools into CI/CD pipelines.
  • Strong understanding of common application vulnerabilities (e.g., OWASP Top 10).
  • Excellent communication and collaboration skills to effectively convey security concepts to developers and other stakeholders.

Preferred Experience

  • Offensive security experience (e.g., bug bounty participation, CTFs) is a plus. Penetration testing experience is welcome but not mandatory.
  • Security certifications such as CISSP, CSSLP, OSCP, or GIAC GWEB.
  • Hands-on experience with containerization (Docker, Kubernetes) and securing containerized applications.
  • Experience with compliance frameworks relevant to application security (SOC 2 Type 2, ISO 27001) and supporting related audits.
  • Experience in financial services or other regulated industries with stringent application security requirements.

The Pay Range For This Role Is

150,000 - 210,000 USD per year(Remote (United States))

150,000 - 212,000 CAD per year(Remote (Canada))

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Technology, Information and Internet

Referrals increase your chances of interviewing at N3XT by 2x

Get notified about new Application Security Engineer jobs in United States.

Application Security Engineer [Remote-US]
Sr. Application Security Engineer (Remote)
Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

Boston, MA $116,258 - $155,011 3 weeks ago

United States
$120,000.00
-
$150,000.00
3 weeks ago

Chicago, IL
$120,000.00
-
$150,000.00
3 weeks ago

New York, NY
$120,000.00
-
$150,000.00
3 weeks ago

Atlanta, GA
$120,000.00
-
$150,000.00
3 weeks ago

Austin, TX
$120,000.00
-
$150,000.00
3 weeks ago

Boston, MA
$120,000.00
-
$150,000.00
3 weeks ago

Senior Application Security Engineer (Remote - USA)

United States
$192,200.00
-
$225,810.00
2 weeks ago

San Francisco, CA
$120,000.00
-
$150,000.00
3 weeks ago

Application Security (AppSec) and DevSecOps Engineer
Senior Application Security Engineer - Secure Code Analysis

Seattle, WA
$120,000.00
-
$150,000.00
3 weeks ago

Cyber Security Detection Engineer - (Fulltime)100% Remote
Application Security Engineer - Veracode

United States
$116,000.00
-
$175,000.00
2 days ago

Pennsylvania, United States
$35.00
-
$45.00
2 days ago

Senior Application Security Engineer (Remote - USA)

Atlanta, GA
$192,200.00
-
$225,810.00
7 hours ago

United States $190,000 - $220,000 2 weeks ago

United States $160,000 - $210,000 2 weeks ago

United States $125,000 - $170,000 2 weeks ago

Senior Application Security Engineer (Remote - USA)

Salt Lake City, UT $192,200 - $225,810 7 hours ago

Senior Application Security Engineer (Remote - USA)

Richmond, VA $192,200 - $225,810 7 hours ago

United States $203,000 - $225,000 2 weeks ago

Sr. Application Security Engineer (Remote)

United States $162,900 - $191,600 3 weeks ago

Senior Application Security Engineer (Remote - USA)

Concord, NH $192,200 - $225,810 7 hours ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Engineer - Application Security

N3XT

null null

Remote

Remote

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant

Security Engineer - Application Security

N3XT

null null

Remote

Remote

USD 150,000 - 210,000

Full time

3 days ago
Be an early applicant

Senior Security Engineer, Application Security

Trail of Bits

null null

Remote

Remote

USD 150,000 - 200,000

Full time

14 days ago

Senior Security Engineer, Application & Cloud

Rad AI

null null

Remote

Remote

USD 150,000 - 180,000

Full time

6 days ago
Be an early applicant

Senior Application Security Engineer

Sprout Social

null null

Remote

Remote

USD 146,000 - 220,000

Full time

14 days ago

Senior Security Engineer, Application Security

Trail of Bits Inc.

null null

Remote

Remote

USD 150,000 - 200,000

Full time

12 days ago

Application Security Engineer

Physna

null null

Remote

Remote

USD 110,000 - 220,000

Full time

16 days ago

Senior Security Engineer II, Application Security

Opportunity Financial, LLC.

null null

Remote

Remote

USD 123,000 - 185,000

Full time

11 days ago

Senior Application Security Engineer

Davita Inc.

null null

Remote

Remote

USD 146,000 - 242,000

Full time

16 days ago