Senior Application Security Engineer

Clear Capital

Reno (NV)

Sur place

USD 111 000 - 144 000

Plein temps

Il y a 28 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature conçue pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Avantages offerts par ce poste

Medical insurance
Dental insurance
401(k)

Résumé du poste

Clear Capital is seeking a Sr. Application Security Engineer to validate and build security into their services and dependencies throughout the SDLC. You will identify weaknesses, plan mitigations, and work with teams to ensure secure design and implementation from the start.

The role emphasizes threat modeling, vulnerability management, and securing AWS/private cloud environments, with a focus on modern security challenges including AI systems and third‑party integrations.

Qualifications

  • Bachelor’s degree in a technically related field or equivalent work experience.
  • 4+ years of related experience in application security.
  • Expertise in SAST, DAST, and SCA tooling with practical implementation.

Responsabilités

  • Plan and carry out application security testing across the SDLC.
  • Assess vulnerabilities and recommend risk‑mitigating solutions.
  • Communicate findings and progress to stakeholders ensuring SLAs are met.
  • Lead AI security initiatives and audit third‑party models/APIs.

Connaissances

Threat modeling
Vulnerability testing
Penetration testing
API security
OWASP Top Ten

Formation

Bachelor's degree in Computer Science or related field

Outils

SAST
DAST
SCA tools
AWS security
Private cloud security

Description du poste

The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.

This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege.

What You Will Work On
  • Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices.
  • Assess discovered vulnerabilities and recommend risk‑mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes.
  • Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service‑level agreements (SLAs) and business metrics.
  • Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third‑party models and APIs to secure the software supply chain.
  • Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning.
  • Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks.
  • Fully define and follow a security review process to ensure an automated and repeatable process is managed.
  • Regularly monitor the security community for public‑facing security issues, as well as to learn new tactics that can be used in testing.
  • Train developers and junior application security engineers on weaknesses to avoid.
  • Perform other duties as assigned.
Who We Are Looking For
  • 4+ years of related experience required.
  • Bachelor’s Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience.
  • Expertise in application security testing, including hands‑on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools.
  • Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.
  • Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.
  • Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.
What You Can Expect
  • Compensation: The base salary for this position ranges from $111,000 to $144,400 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit‑sharing bonus program, communication stipends, and referral bonuses.
  • Inclusive benefits package offering:
  • Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&DD insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources.
  • Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team.
  • Career and skill development resources to help advance your career and personal growth.
  • A mission‑driven environment where your work makes a measurable impact on the real estate industry.
What We Value
  • Wherever it Leads, Whatever it Takes - No matter how remote, complex, or unexpected. Our commitment never wavers.
  • Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit.
  • Lift others up - We lead with empathy and strive to improve the lives of those around us.
  • Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact.
  • Raise the bar - We don’t settle for industry standards, we redefine them.
About Us

Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. Our goal is to provide customers with a complete understanding of nearly every U.S. property through our AI‑driven analytics, data solutions, valuation services and automated appraisal review platforms. Our commitment to excellence - wherever it leads, whatever it takes - is embodied by our team members across our brands and has remained steadfast in this pursuit since our first order in 2001.

Clear Capital is an equal‑opportunity employer.

To all recruitment agencies: Clear Capital does not accept agency resumes. Please do not forward resumes to our jobs alias, Clear Capital employees, or any other company location. Clear Capital is not responsible for any fees related to unsolicited resumes.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Reno (NV)

Sur place
USD 111 000 - 144 400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
GRC Security Analyst (copy)
GRC Security Analyst (copy)

Clear Capital • Reno (NV)

Sur place
USD 114 000 - 139 000
Profit-sharing bonus program
Communication stipends
Referral bonuses
+3
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Capital Group • New York (NY)

Hybride
CAD 240 000 - 384 000
Flexible work
Health benefits
Matching gifts
+2
Senior Application Security Engineer — Secure SDLC & AI
Senior Application Security Engineer — Secure SDLC & AI

Clear Capital | CubiCasa • Reno (NV)

Sur place
USD 111 000 - 144 400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior AI AppSec Engineer
Senior AI AppSec Engineer

504 CGCG-US CG Companies Global-US • États-Unis

Hybride
USD 154 000 - 246 000
Competitive base salary
Bonus opportunities
Health benefits
+2
Senior Application Security Engineer
Senior Application Security Engineer

Arrowstreet Capital, Limited Partnership • Boston (MA)

Sur place
USD 110 000 - 315 000
Staff Software Engineer
Staff Software Engineer

Secure Identity, LLC. • New York (NY), Northern (KY)

Hybride
USD 325 000 - 500 000
Health insurance
Flexible time off
Wellness stipend
+3
Information Security Engineer IV
Information Security Engineer IV

Capital-Group-1 • Charlotte (NC)

Sur place
USD 137 000 - 219 000
Annual performance bonus
Profit sharing bonus
Retirement plan with 15% employer 13
Staff Software Engineer
Staff Software Engineer

CLEAR - Corporate • New York (NY)

Sur place
USD 325 000 - 500 000
Catered lunches
Fully stocked kitchens
Wellness stipend
+2
Security Engineer 4 (SailPoint)
Security Engineer 4 (SailPoint)

Capital One • McLean (VA)

Sur place
USD 197 000 - 225 000