Senior Application Security Engineer

Jobtailor

Colorado

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Application Security Engineer to lead security across the SDLC for multiple applications and cloud workloads. You will perform AI-assisted and traditional security assessments and drive remediation from discovery to closure, while collaborating with architects, developers, and DevOps teams.

You will apply OWASP Top 10, API Security Top 10, and secure coding principles, build security metrics and dashboards, and mentor teams to foster a security-first culture

Qualifications

  • 5–7 years of hands‑on application security / DevSecOps experience.
  • Strong working understanding of Secure SDLC, DevSecOps, Agile, and Scrum methodologies.
  • Experience with Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling.
  • Ability to read, analyze, test, and modify production application code in Java and Python.
  • Knowledge of OWASP Top 10, API Security Top 10, authentication/authorization controls, and secure coding principles.
  • Familiarity with cloud security, identity and access management, and modern application architectures.
  • Experience using AI‑assisted development and security tools safely and effectively.
  • Excellent communication, stakeholder management, presentation, and documentation skills.
  • Ability to work independently across multiple applications, teams, portfolios, and technology stacks.
  • Collaborative and influential, able to negotiate priorities and remove blockers across teams.
  • Coaching others and championing a security‑first culture.

Responsibilities

  • Define, implement, and improve security processes across the SDLC.
  • Perform AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure.
  • Manage source code analysis, secret scanning, dependency analysis, and infrastructure review coverage.
  • Triage findings by exploitability, business impact, and severity.
  • Drive remediation from discovery through verified closure, including backlog management, ownership assignment, retesting, and evidence collection.
  • Identify and reduce security debt, dependency vulnerabilities, outdated libraries, and software supply chain risk.
  • Build security metrics, coverage reporting, and executive dashboards.
  • Leverage AI tools for security analysis, threat modeling, code review, and documentation under governance controls.
  • Perform manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review methodologies.
  • Apply OWASP Top 10, API Security Top 10, authentication/authorization controls, and secure coding principles.
  • Support remediation through code fixes, configuration changes, and compensating controls.
  • Partner with architects, developers, DevOps engineers, product owners, and business stakeholders to communicate risk, negotiate priorities, and remove blockers.
  • Maintain Agile work items and participate in Scrum ceremonies.
  • Stay current on emerging threats and AI-related security risks.
  • Coach and mentor application teams to build a security-first culture.

Skills

Secure SDLC
DevSecOps
Burp Suite
CodeQL
GitHub Security
SAST
SCA
Secret Scanning
Dependency Analysis
CI/CD Security
Java
Python
Threat Modeling
OWASP Top 10
API Security
Cloud Security
IAM
AI Tools

Education

Bachelor's Degree in Computer Science
Master's Degree in Cybersecurity
Information Systems Certification

Tools

Burp Suite
GitHub Advanced Security
CodeQL
AI-Assisted Dev Tools
API Testing Platforms

Job description

  • Define, implement, and continuously improve application security processes, standards, and workflows throughout the SDLC
  • Perform AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
  • Manage source code analysis, secret scanning, dependency analysis, and infrastructure review coverage
  • Triage findings by exploitability, business impact, and severity
  • Drive remediation from discovery through verified closure, including backlog management, ownership assignment, retesting, and evidence collection
  • Identify and reduce security debt, dependency vulnerabilities, outdated libraries, and software supply chain risk
  • Build security metrics, coverage reporting, and executive dashboards
  • Leverage AI tools for security analysis, threat modeling, code review, and documentation under governance controls
  • Perform manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review methodologies
  • Apply OWASP Top 10, API Security Top 10, authentication, authorization, and secure coding principles
  • Support remediation through code fixes, configuration changes, and compensating controls
  • Partner with architects, developers, DevOps engineers, product owners, and business stakeholders to communicate risk, negotiate priorities, and remove blockers
  • Maintain Agile work items and participate in Scrum ceremonies
  • Stay current on emerging threats and AI-related security risks
  • Coach and mentor application teams to build a security-first culture
Requirements
  • Bachelor's and/or Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent practical experience)
  • 5–7 years of hands‑on application security / DevSecOps experience
  • Strong working understanding of Secure SDLC, DevSecOps, Agile, and Scrum methodologies
  • Experience with Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • Ability to read, analyze, test, and modify production application code in Java and Python
  • Knowledge of OWASP Top 10, API Security Top 10, authentication/authorization controls, and secure coding principles
  • Familiarity with cloud security, identity and access management, and modern application architectures
  • Experience using AI‑assisted development and security tools safely and effectively
  • Skilled in vulnerability triage and validation, including exploitability, business impact, severity, compensating controls, and security metrics/dashboards
  • Excellent communication, stakeholder management, presentation, and documentation skills
  • Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • Strong problem‑solving mindset balancing security, usability, and business objectives
  • Collaborative and influential, able to negotiate priorities and remove blockers across teams
  • Comfortable coaching others and championing a security‑first culture
Core Competencies

Demonstrates expertise in Application Security and DevSecOps, with a strong focus on Secure SDLC, vulnerability management, and the application of OWASP and API Security principles. Proficient in leveraging AI tools for security analysis and maintaining effective communication with cross‑functional teams to foster a security‑first culture.

Highest-signal resume keywords
  • Application Security
  • DevSecOps
  • Secure SDLC
  • Burp Suite
  • Vulnerability Triage
Hard Skills
  • Java
  • Python
  • SAST
  • SCA
  • Secret Scanning
  • Dependency Analysis
  • CI/CD Security Tooling
  • Security Metrics
  • Threat Modeling
  • Secure Coding Principles
Soft Skills
  • Excellent Communication
  • Stakeholder Management
  • Problem‑Solving Mindset
  • Collaborative
  • Coaching
Certifications & Qualifications
  • Bachelor's Degree in Computer Science
  • Master's Degree in Cybersecurity
  • Information Systems Certification
Industry Keywords
  • Agile
  • Scrum
  • OWASP Top 10
  • API Security Top 10
  • Cloud Security
  • Identity and Access Management
Tools & Technologies
  • Burp Suite
  • GitHub Advanced Security
  • CodeQL
  • AI-Assisted Development Tools
  • API Testing Platforms
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Senior Application Security Engineer DevSecOps and CICD
Senior Application Security Engineer DevSecOps and CICD

3Core Systems, Inc • Chicago (IL), Northern (KY)

Hybrid
USD 120,000 - 150,000
Software Engineer – Java, Python
Software Engineer – Java, Python

Jobtailor • Dallas (TX)

On-site
USD 85,000 - 125,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Application Offensive Security Consultant
Application Offensive Security Consultant

StaffWorthy • Jersey City (NJ)

On-site
USD 90,000 - 120,000
Director Application Security
Director Application Security

Vibehackers • Austin (TX), Northern (KY)

Hybrid
USD 180,000 - 250,000
Medical Insurance
Dental Insurance
Life Insurance
+3
Senior Application Security Engineer
Senior Application Security Engineer

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

Hybrid
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment