Senior Application Security Engineer

World Wide Technology

Maryland Heights (MO)

On-site

USD 116,000 - 145,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401k with company matching
Paid time off
Parental leave
Wellness program
Employee discount program

Job summary

World Wide Technology seeks a Senior Application Security Engineer to secure our application ecosystem across cloud and on-premise environments. You will own vulnerability lifecycle, perform threat modeling, secure code reviews, and drive secure coding practices with engineering and DevOps.

In this hands-on role, you’ll operate SCA/SAST/DAST tooling, integrate security into CI/CD, mentor teams, and coordinate penetration testing and risk assessments to reduce risk across WWTs software portfolio.

Qualifications

  • Bachelor’s degree or equivalent hands-on experience.
  • Minimum 8 years in application security roles.
  • Experience securing cloud-native apps and containers.
  • Experience with CI/CD integration of security tooling.
  • Ability to read code in Java/JS/Python/Go/C#.

Responsibilities

  • Own the application vulnerability lifecycle and remediation.
  • Operate SCA, SAST, DAST tooling across the SDLC.
  • Incorporate security into CI/CD pipelines.
  • Conduct threat modeling and secure code reviews.
  • Lead penetration testing and risk assessment.

Skills

Application security
Threat modeling
SAST & SCA
CI/CD security
Cloud security
Programming basics

Education

Bachelor's degree in CS/SE/InfoSec

Tools

SAST tooling
SCA tooling
DAST tooling
CI/CD tooling (GitHub Actions, Jenkins, etc.)
Cloud platforms (AWS/Azure/GCP)

Job description

World Wide Technology (WWT) strives to make a new world happen. WWT's work benefits clients and partners as much as it does its people and community across the globe.

Founded in 1990, WWT brings together strategy, deep technical expertise and world-class partnerships to help public and private sector organizations design, build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions. Through its Advanced Technology Center (ATC)—a collaborative ecosystem featuring state-of-the-art hardware and software—WWT enables clients and partners to conceptualize, test and validate innovative technology and then deploy solutions at scale using its global integration and distribution capabilities.

With more than 14,000 team members and over 60 locations globally, WWT's culture—grounded in core values and leadership philosophies—has been recognized by Fortune® and Great Place to Work for its commitment to innovation, trust and creating a great place to work for all. WWT provides products and services to large enterprise, global service provider and public sector clients in up to 130 countries across six continents. Softchoice, a World Wide Technology company, supports commercial and SMB markets in the U.S. and Canada.

Want to work with highly motivated individuals on high-performance teams? Join WWT today!

What is the Internal WWT IT Team, and why join? The Internal WWT IT team is the backbone of our company’s technological infrastructure, ensuring seamless operations and continuous innovation. Our team is dedicated to managing and supporting the company’s technology infrastructure, ensuring the smooth operation of hardware, software, networks, and data systems, while providing top-notch technical support to employees.

By joining the Internal WWT IT team, you will play a crucial role in maintaining the efficiency and security of our IT environment, enabling the company to achieve its strategic goals. The Internal IT team offers the opportunity to work in a dynamic and collaborative environment, where your contributions will have a direct impact on the company's success. If you are passionate about technology and eager to take on new challenges, we encourage you to apply and join our team.

About The Role
World Wide Technology’s Information Security organization is hiring a Senior Application Security Engineer to help secure the organization’s application ecosystem and reduce risk across WWT-developed and WWT-operated software. As a Senior Application Security Engineer, you’ll be a hands-on technical contributor helping mature an evolving application security function. Your focus is executing the highest-impact technical security work and enabling developers to ship secure code at speed through threat modeling, secure code review, security tooling and automation, and vulnerability remediation. Operating across containerized, hybrid-cloud environments, you’ll partner closely with engineering, DevOps, and compliance and risk management teams to embed security into the SDLC. You’ll help grow the skills of those around you and act as a trusted application security resource for development and other teams across the organization. This is a role for an engineer who wants to help shape the practices that keep our applications secure.

Key Responsibilities
Application Vulnerability & Risk Management
Own the technical core of the application vulnerability lifecycle, driving discovery and detection, validating exploitability, prioritizing by risk, offering technical remediation guidance, and verifying fixes fully close the issue.

  • Cut through scanner noise by dismissing false positives with rationale and documenting clear, actionable remediation developers can act on.
  • Maintain playbooks that make triage, escalation, and remediation repeatable as we scale.

  • Application Security Tooling
    Operate and maintain application security tooling (SCA, SAST, DAST, secrets, etc.) across the SDLC.
  • Drive adoption of security tooling, partnering with developers to integrate into their workflows and maximize meaningful coverage.

  • Secure SDLC & Developer Enablement
    Partner with DevOps to build security into delivery by integrating SCA, SAST, and DAST into the CI/CD pipeline.
  • Perform secure code reviews, threat models (STRIDE/PASTA), and design and architecture reviews for net-new and high-risk applications.
  • Surface validated findings where developers already work - IDE, pull request, ticketing - to minimize noise and context switching.
  • Contribute to documentation that gives developers a clear path to shipping secure code.

  • Penetration Testing
    Scope, execute, and coordinate penetration tests across the organization’s environment overseeing remediation and validation retests.
  • Perform hands-on manual testing to uncover business-logic flaws, chained exploits, and vulnerabilities that automated scanners miss.

  • Secure AI / LLM Application Security
    Apply secure development practices to AI/LLM-enabled and agentic applications; assess risks like prompt injection, tool poisoning, confused-deputy, and credential exposure.
  • Make responsible, hands-on use of AI to work faster and more effectively, reflecting our culture as an AI-first company operating at the leading edge of the field.

  • Collaboration & Mentorship
    Act as a credible application security escalation point for engineering and a force multiplier - an enabler, not a gatekeeper.
  • Produce technical evidence and control mappings that satisfy compliance and audit needs across CMMC, SOC 2, ISO 27001, and NIST 800-171/800-53.

  • ,

    Required Qualifications
    Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related field — or equivalent hands-on experience.
  • Minimum 8 years of experience in roles related to application security, information security, software engineering, SecDevOps.
  • A demonstrable track record of independently owning AppSec domains and delivering remediation without close supervision.
  • Hands-on experience operating application security scanning tooling (SAST, SCA, secrets, IaC) and integrating it into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or equivalent).
  • Experience securing cloud-native and container/Kubernetes-based applications (AWS, Azure, GCP; Docker, Kubernetes, OpenShift).
  • Ability to read and reason about code in one or more modern stacks (Java, JavaScript/TypeScript, Python, Go, or C#) well enough to perform and review secure code, trace data flows, and identify vulnerabilities in source code.
  • Scripting and automation in Python, Bash, or PowerShell.
  • Design-level understanding of authentication, authorization, and identity — session management, SSO and federation, and OAuth2/OIDC as architectural patterns.
  • Working knowledge of applied cryptography — TLS, certificates and PKI, secrets and key management, hashing versus encryption.
  • Strong command of HTTP and web API internals — request/response semantics, auth flows (OAuth2/OIDC, JWT, session management), and the authZ failures, injection, and business-logic flaws common to REST and GraphQL APIs.
  • Solid understanding of the secure software development lifecycle and where security testing, gates, and controls fit within it.
  • Strong working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and CWE.
  • Working knowledge of NIST SSDF (SP 800-218), NIST 800-53, NIST 800-171, ISO 27001, SOC 2, and CMMC as they apply to secure software development.
  • Hands-on threat modeling experience (STRIDE, PASTA, or equivalent).
  • Excellent interpersonal, written, and verbal communication — able to explain and document security risk and remediation credibly to both engineers and non-technical stakeholders.
  • Self-starter, team player, and enthusiasm for learning.
  • Applicants must be authorized to work in the United States without sponsorship. We are unable to provide sponsorship now or in the future for this position.

  • Preferred Qualifications
    Hands-on experience with one or more leading application security platforms (e.g., Wiz, Snyk, Apiiro, OX Security, Cycode, Checkmarx, Veracode, or GitHub Advanced Security).
  • Hands-on experience securing AI/LLM-enabled and agentic applications; familiarity with OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic AI, MITRE ATLAS, NIST AI RMF, and Model Context Protocol (MCP) security implications.
  • Hands-on penetration testing or offensive security experience across web, API, infrastructure, or AI systems (including prompt injection, jailbreaks, and agent abuse).
  • Industry certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP, OSWE, or AWS/Azure/GCP security certifications.

  • Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $116,000 to $145,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the base pay.

    The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:

    • Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
    • Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
    • Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
    • Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program

    Note: This is not an all-encompassing list and should not be used as a complete description of the plan’s benefits. For more information, see our US Benefits Website

    We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for all!

    If you require accessibility accommodation(s) or adjustment during any stage of the hiring process, please let your WWT Recruiter know. The recruiter will work with you to understand your needs and help ensure an accessible experience throughout the interview process. World Wide Technology is an Equal Opportunity Employer.

    If you have any questions or concerns about this posting, please email taposting@wwt.com.

    Get your free, confidential resume review.
    or drag and drop your file here.
    Similar jobs

    Similar jobs worth comparing

    Senior Application Security Engineer
    Senior Application Security Engineer

    World Wide Technology, Inc. • Northern (KY)

    Hybrid
    USD 116,000 - 145,000
    Health and Wellbeing
    401k with Company Matching
    Paid Time Off
    +2
    Senior AI Security Engineer
    Senior AI Security Engineer

    World Wide Technology • Maryland Heights (MO)

    On-site
    USD 116,000 - 145,000
    Health and Wellbeing
    401k Plan with Company Matching
    Paid Time Off
    +1
    Senior Offensive Security Engineer
    Senior Offensive Security Engineer

    World Wide Technology • Maryland Heights (MO)

    On-site
    USD 116,000 - 145,000
    Health benefits
    401k with company matching
    Paid time off
    +2
    Senior Offensive Security Engineer
    Senior Offensive Security Engineer

    RadNet, Inc. • Northern (KY)

    Hybrid
    USD 116,000 - 145,000
    Health and Wellbeing: Health, Dental,
    401k with Company Matching
    Paid Time Off and Holidays
    +1
    Security Solutions Analyst - Customer Success
    Security Solutions Analyst - Customer Success

    World Wide Technology • Maryland Heights (MO)

    On-site
    USD 72,000 - 90,000
    Health benefits
    401k with company matching
    Paid time off
    Team Lead, Security Operations Center (SOC) - 3rd Shift
    Team Lead, Security Operations Center (SOC) - 3rd Shift

    World Wide Technology • Maryland Heights (MO)

    On-site
    USD 122,000 - 152,000
    Manager, Development — AI Execution Platforms
    Manager, Development — AI Execution Platforms

    World Wide Technology • Maryland Heights (MO)

    On-site
    USD 150,000 - 170,000
    Health insurance
    401k with company matching
    Paid time off
    +3
    Senior Site Reliability Engineer
    Senior Site Reliability Engineer

    World Wide Technology • United States

    On-site
    USD 108,000 - 136,000
    Health and Wellbeing benefits
    Competitive Pay + 401k with matching
    Profit Sharing
    +3
    Senior EUC Engineer
    Senior EUC Engineer

    World Wide Technology • St. Louis (MO)

    On-site
    USD 108,000 - 136,000
    Health and Wellbeing
    Financial Benefits
    Paid Time Off
    +1
    Full Stack Developer
    Full Stack Developer

    RadNet, Inc. • St. Louis (MO), Northern (KY)

    Hybrid
    USD 82,000 - 103,000
    Health and Wellbeing benefits
    401K with company matching
    Tuition reimbursement
    +2