Senior Application Security Engineer

Wilson Elser - Business & Legal Professionals

New York (NY)

On-site

USD 150,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401k match
Generous PTO
Corporate discount plans

Job summary

Wilson Elser is seeking a Senior Application Security Engineer to mature the SSDLC program and bridge Security with Application Development. You will collaborate with engineering leadership to embed secure practices into the software development lifecycle for Azure-hosted services and CI/CD pipelines.

The role combines hands-on security with development experience, focusing on securing SSDLC, DevSecOps tooling, threat modeling, and secure architecture reviews while partnering with

Qualifications

  • 5+ years of experience in Application Security, DevSecOps, or related fields.
  • Hands-on in securing CI/CD pipelines and modern development workflows.
  • Experience collaborating with development teams in Agile environments.
  • Strong understanding of OWASP Top 10 and secure SDLC practices.

Responsibilities

  • Lead and mature the SSDLC program across applications and platforms.
  • Embed secure-by-design principles into development workflows.
  • Perform threat modeling and secure architecture assessments.
  • Review code to identify and remediate vulnerabilities.
  • Establish secure coding standards and reusable templates.
  • Develop dashboards and metrics for security posture and SLAs.
  • Integrate security tooling into Azure DevOps pipelines.

Skills

SSDLC
DevSecOps
CI/CD Pipelines
Threat Modeling
Secure SDLC
Vulnerability Management
OWASP Top 10
Communication Skills
Collaboration

Tools

SonarQube
PowerShell
Python
.NET
React
PHP
Azure DevOps
Databricks
Power Platform / Power Apps

Job description

AtWilson Elser , we are redefining what it means to work at a national law firm. With more than 1,400 attorneys across 46 offices nationwide, we are recognized among the top 100 law firms by The American Lawyer and ranked #30 in the National Law Journal’s survey of the nation’s largest law firms.

Our continued success is built on a culture of collaboration, innovation, client service, and mutual respect. We are committed to fostering an environment where employees are empowered to grow their careers, contribute meaningfully, and thrive professionally.

The Position

We are seeking a highly skilled Senior Application Security Engineer to help establish and mature our secure software development and DevSecOps program. This role will serve as the bridge between Information Security and Application Development, partnering closely with engineering leadership to embed security into the software development lifecycle without slowing innovation or delivery.

This individual will work across internally developed applications, cloud-native platforms, CI/CD pipelines, integrations, low-code/no-code platforms, and Azure-hosted services. The ideal candidate combines hands‑on application security expertise with practical development experience and strong collaboration skills.

This position will report to the Information Security team with a strong dotted‑line partnership into Application Development and Engineering leadership.

Key Responsibilities

Application Security & Secure Development Lifecycle (SDL)

  • Lead and mature the organization’s secure software development lifecycle (SSDLC) program
  • Partner with developers and engineering leadership to embed secure‑by‑design principles into development workflows
  • Perform application security reviews, threat modeling, and secure architecture assessments
  • Review source code and assist development teams in identifying and remediating vulnerabilities
  • Establish secure development standards, policies, and reusable secure coding templates
  • Build and maintain “paved road” secure development patterns for common technologies and frameworks

DevSecOps & CI/CD Security

  • Integrate and optimize security tooling within Azure DevOps pipelines
  • Manage and improve SAST, DAST, SCA, API scanning, and IaC scanning processes
  • Enhance automated security testing within CI/CD workflows
  • Develop processes for vulnerability ingestion, triage, prioritization, remediation tracking, and reporting
  • Build dashboards and metrics around application security posture and remediation SLAs
  • Create or customize scripts and integrations to normalize findings across multiple security tools

Security Tooling & Vulnerability Management

  • Administer and optimize tools such as:
  • SonarQube
  • PowerShell scanning tools
  • Additional open source or commercial AppSec tooling as needed
  • Evaluate gaps in existing security tooling coverage and recommend improvements
  • Tune scanners, suppress false positives appropriately, and create custom detection rules where necessary
  • Partner with development teams to manage security exceptions and remediation timelines
  • Collaborate with cloud and infrastructure teams to secure Azure-hosted applications and services
  • Support security reviews involving:
  • Containers
  • Databricks
  • MongoDB
  • Data Lake environments
  • Power Platform / Power Apps
  • Assist with securing low-code/no-code platforms and related governance processes

Security Culture & Developer Enablement

  • Establish and support a Security Champions program within engineering teams
  • Deliver developer-focused training, workshops, lunch‑and‑learns, and secure coding guidance
  • Serve as a trusted advisor and mentor to developers on secure coding and DevSecOps practices
  • Promote a collaborative, enablement-focused security culture

Qualifications

  • 5+ years of experience in Application Security, Product Security, DevSecOps, or Software Engineering
  • Hands‑on experience securing CI/CD pipelines and modern development workflows
  • Experience working directly with development teams in agile environments
  • Strong understanding of:
  • OWASP Top 10
  • Secure SDLC practices
  • Threat modeling
  • Vulnerability management
  • Experience with at least several of the following technologies:
  • SonarQube
  • PowerShell
  • Python
  • .NET
  • React
  • PHP
  • Experience integrating security tooling into CI/CD pipelines
  • Ability to analyze scanner results and distinguish meaningful risk from low‑value findings
  • Strong scripting and automation skills
  • Excellent communication and collaboration skills

Wilson Elser offers a competitive salary and benefits package designed to support our attorneys both professionally and personally.

A variety of factors are considered in making compensation decisions, including but not limited to experience, education, licensure and/or certifications, geographic location, market demands, other business and organizational needs, and other factors permitted by law. Final salary wages offered may be outside of this range based on other reasons and individual circumstances. This position is considered full‑time and therefore qualifies for benefits including 401(k) retirement savings plan, medical, dental, vision, disability, and life insurance. Details of participation in these benefit plans will be provided if an employee receives an offer of employment.

Salary Range:

$150,000 - $180,000 USD

Why Should You Apply?
  • Benefits: Outstanding benefits package, including 401k match and generous PTO plan
  • Career Growth: Ample opportunities for professional development and advancement
  • Employee Perks: Access to corporate discount plans and other benefits
Wilson Elser welcomes submissions of candidates for our open positions exclusively from recruitment agencies with an active, signed fee agreement who have been granted access to a position through our dedicated Recruitment Agency Portal. We are unable to consider submissions from recruitment agencies without a current (dated as of 7/1/2024) agreement in place. We appreciate your understanding. For collaboration inquiries or to establish an agreement, please contact us at talentacquisition@wilsonelser.com .
Wilson Elser is committed to a collegial work environment in which all individuals are treated with respect and dignity. It is the Firm's policy that employment will be based on merit, qualifications, and competence. Further, employment decisions will be made without regard to an applicant's race, color, age, sex, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation or preference, gender identity, physical or mental disability, status as a victim of domestic violence, sex offenses, or stalking, past or present service in the uniformed services or application or obligation to serve in the uniformed services, or any other characteristic protected by law.
Wilson Elser endeavors to make the Wilson Elser website accessible to any and all users. You may review our Accessibility Policy here .
California Residents may review our CCPA notice for applicants and employees here .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Infrastructure Operations Engineer
Senior Infrastructure Operations Engineer

Wilson Elser • Portland (OR)

On-site
USD 120,000 - 165,000
401k match
Generous PTO
Corporate discount plans
Senior Infrastructure Operations Engineer
Senior Infrastructure Operations Engineer

Wilson Elser • Dallas (TX)

On-site
USD 120,000 - 165,000
Full Stack Software Engineering Manager
Full Stack Software Engineering Manager

Wilson Elser • New York (NY)

On-site
USD 150,000 - 190,000
401(k) retirement savings plan
Medical, dental, and vision insurance
Senior Infrastructure Operations Engineer
Senior Infrastructure Operations Engineer

Justia, Inc. • New York (NY)

On-site
USD 120,000 - 165,000
401k match
Generous PTO
Corporate discount plans
Senior Infrastructure Operations Engineer
Senior Infrastructure Operations Engineer

Wilson Elser - Business & Legal Professionals • United States

Hybrid
USD 120,000 - 165,000
401(k) plan
Paid time off
Corporate discounts
Business Line Program Administrator
Business Line Program Administrator

Wilson Elser (Professional Staff Careers) • New York (NY)

On-site
USD 65,000 - 85,000
401(k) retirement savings plan
Medical, dental, and vision insurance
Generous PTO plan
+1
Data Analyst
Data Analyst

Wilson Elser (Professional Staff Careers) • Chicago (IL)

Hybrid
USD 80,000 - 90,000
401k match
Generous PTO plan
Corporate discount plans
Cyber Incident Response Associate Attorney
Cyber Incident Response Associate Attorney

Wilson Elser Moskowitz Edelman & Dicker LLP • Miami (FL)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Competitive compensation
Cyber Incident Response Associate Attorney
Cyber Incident Response Associate Attorney

Wilson Elser - Attorneys • New York (NY)

Hybrid
USD 160,000 - 190,000
Hybrid flexibility
Competitive compensation
Generous PTO
+6
Cyber Incident Response Associate Attorney
Cyber Incident Response Associate Attorney

Wilson Elser - Attorneys • Washington

Hybrid
USD 160,000 - 190,000
Hybrid work arrangement
Competitive compensation
Excellent benefits
+2