Senior App Security Engineer - Threat Modeling & Secure SDLC

Technology Resource Management

United States

Remote

USD 140,000 - 200,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TRM Labs is seeking an experienced Application Security Engineer to build mission-critical security for our AI-powered products. You will lead reviews, threat modeling, and secure code practices across engineering teams.

You will own vulnerability management, coordinate penetration testing, and advance our Secure SDLC while mentoring developers and shaping security champions across TRM.

Qualifications

  • Minimum 8 years of experience in Software Development and testing.
  • BS in Computer Science, Computer Engineering, or related field.
  • Proficiency in Python, NodeJS, React.
  • Strong understanding of encryption, authentication, and authorization protocols.
  • Deep experience with OWASP and CWE, testing methodologies, and security tooling.
  • Experience with cloud providers (GCP and AWS) and Secure SDLC, threat modeling, and best practices.
  • Experience conducting code security reviews on a regular basis.
  • Experience triaging/remediating vulnerabilities in software packages or libraries.
  • Experience with security tools such as GitHub Advanced Security, SAST, DAST, and SCA.
  • Experience with web testing frameworks such as BurpSuite, OWASP ZAP.
  • Experience with threat modeling tools such as OWASP Threat Dragon.
  • Experience in agile-based software development.
  • Experience Red Teaming or penetration testing applications/infrastructure.
  • Familiarity with security frameworks (NIST SP 800-171 SSDF) is a plus.

Responsibilities

  • Lead application security reviews and threat modeling, including secure code review, architectural design, and testing.
  • Develop automated testing and mature our Secure SDLC.
  • Own and perform application security vulnerability management.
  • Coordinate penetration testing engagements.
  • Support software engineers and product teams by developing application security best practices.
  • Develop and maintain the bug bounty program.
  • Bootstrap platform security initiatives that help protect TRM data.
  • Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.

Skills

Python
NodeJS
React
Cloud platforms (GCP/AWS)
OWASP / CWE knowledge
Security testing tooling (SAST/DAST/S4

Education

BS in Computer Science / Computer Engineering

Tools

BurpSuite
OWASP ZAP
Threat modeling tools (OWASP Threat Dragon)
GitHub Advanced Security

Job description

TRM Labs is seeking an experienced Application Security Engineer to build mission-critical security for our AI-powered products. You will lead reviews, threat modeling, and secure code practices across engineering teams.

You will own vulnerability management, coordinate penetration testing, and advance our Secure SDLC while mentoring developers and shaping security champions across TRM.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead App Security Engineer: Threat Modeling & SDLC
Lead App Security Engineer: Threat Modeling & SDLC

Apply • Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior AppSec Engineer: Threat Modeling & Secure SDLC
Senior AppSec Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Lead Application Security Engineer: Threat Modeling & Secure SDLC
Lead Application Security Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • Burlington (VT), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior App Security Engineer: Threat Modeling & Secure SDLC
Senior App Security Engineer: Threat Modeling & Secure SDLC

H&R Block, Inc. • Northern (KY)

Hybrid
USD 140,000 - 180,000
Senior App Security Engineer: Secure SDLC & AI Risk Lead
Senior App Security Engineer: Secure SDLC & AI Risk Lead

Clear Capital • Reno (NV)

On-site
USD 111,000 - 144,400
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Senior AppSec Engineer - Threat Modeling & Automation
Senior AppSec Engineer - Threat Modeling & Automation

Jobs in JS • Stamford (CT)

Hybrid
USD 116,000 - 170,000
401K with corporate match
Health insurance
PTO and holidays
+3
Remote Senior AppSec Engineer - SDLC & Threat Modeling
Remote Senior AppSec Engineer - SDLC & Threat Modeling

Mitek Systems • United States

Remote
USD 140,000 - 190,000
AppSec ownership
Competitive compensation
Security-focused culture
+2
Senior App Security Engineer – AI-Driven Threat Modeling
Senior App Security Engineer – AI-Driven Threat Modeling

Spring Health • United States

Remote
USD 140,000 - 210,000
Application Security Engineer — Threat Modeling & Secure SDLC
Application Security Engineer — Threat Modeling & Secure SDLC

Anthropic • New York (NY)

Hybrid
USD 300,000 - 405,000
Competitive compensation
Flexible working hours
Generous vacation and parental leave
Senior AppSec Architect: Threat Modeling & Secure SDLC
Senior AppSec Architect: Threat Modeling & Secure SDLC

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000