Senior Application Security Engineer

Clear Capital

Reno (NV)

On-site

USD 111,000 - 144,400

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance

Job summary

Clear Capital is seeking a Sr. Application Security Engineer to validate that applications and services are built with strong security. You will test across SDLC, model threats, and guide teams to reduce exploitable risks while maintaining business continuity.

You will also lead AI security initiatives and monitor the software supply chain. You will collaborate with architects and development teams to embed secure design, automate security reviews, and mentor junior engineers.

Qualifications

  • Bachelor's degree or equivalent work experience.
  • 4+ years of relevant application security experience.
  • Proficiency with SAST/DAST/SCA tools and threat modeling.

Responsibilities

  • Plan and carry out application security testing in all SDLC phases to identify vulnerabilities.
  • Assess discovered vulnerabilities and recommend risk-mitigating solutions using automation.
  • Communicate findings, risks, and progress to stakeholders with SLAs and metrics.
  • Lead AI security initiatives, including threat modeling for autonomous systems and auditing third-party models.
  • Collaborate with architects and development teams to drive secure design practices.
  • Define and follow a security review process for automated, repeatable assessments.
  • Monitor security community for issues and learn new testing tactics.
  • Train developers and junior engineers on weaknesses to avoid.
  • Perform other duties as assigned.

Skills

Security testing
Threat modeling
Stakeholder communication
Leadership

Education

Bachelor's Degree in CS/IT/SE

Tools

SAST tools
DAST tools
SCA tools
AWS security

Job description

The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.

This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege.

What You Will Work On
  • Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices.
  • Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes.
  • Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics.
  • Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain.
  • Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning.
  • Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks.
  • Fully define and follow a security review process to ensure an automated and repeatable process is managed.
  • Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing.
  • Train developers and junior application security engineers on weaknesses to avoid.
  • Perform other duties as assigned.
Who We Are Looking For
  • 4+ years of related experience required.
  • Bachelor's Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience.
  • Expertise in application security testing, including hands-on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools.
  • Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.
  • Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.
  • Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.
What You Can Expect
  • Compensation: The base salary for this position ranges from $111,000 to $144,400 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Inclusive benefits package offering:
  • Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&D insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources.
  • Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team.
  • Career and skill development resources to help advance your career and personal growth.
  • A mission-driven environment where your work makes a measurable impact on the real estate industry.

Clear Capital is an equal-opportunity employer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Capital Group • New York (NY)

Hybrid
CAD 240,000 - 384,000
Flexible work
Health benefits
Matching gifts
+2
Senior Application Security Engineer
Senior Application Security Engineer

Cybersecurity Jobs • Boston (MA)

On-site
USD 110,000 - 315,000
Annual discretionary bonuses
Benefits package
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Sr. Manager, Application Security
Sr. Manager, Application Security

Prosper Marketplace • United States

On-site
USD 226,000 - 270,000
401(k) with 5% company match
Flexible time off
Paid parental leave
+1
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Senior Application Security Engineer
Senior Application Security Engineer

Arrowstreet Capital, Limited Partnership • Boston (MA)

On-site
USD 110,000 - 315,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

Inmar Inc. • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+2
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Capital Group • Charlotte (NC)

On-site
USD 137,000 - 219,000
Time-away benefits
Flexible work options
Professional development resources
Application Security Engineer
Application Security Engineer

CivicPlus • United States

On-site
USD 90,000 - 100,000
Comprehensive health insurance
Dental insurance
Vision insurance
+2