Senior Application Security Engineer

Clear Capital | CubiCasa | restb.ai

United States

A distancia

USD 111.000 - 144.000

Jornada completa

14 días+
Generador de candidaturas

Una candidatura completa en un minuto — currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Profit-sharing bonus program
Communication stipends
Referral bonuses

Descripción de la vacante

Clear Capital is seeking a Sr. Application Security Engineer to validate high security throughout applications and services, including databases and middle-tier systems. You will address legacy and emerging issues and implement repeatable secure development practices to reduce exploitable design flaws.

This role emphasizes threat modeling, vulnerability remediation, and collaboration with architects and developers to secure design from the start, including AI security initiatives.

Formación

  • 4+ years of related experience required.
  • Bachelor’s Degree, ideally in Computer Science, IT, Software Engineering, or equivalent.
  • Strong technical and analytical background with software development and scripting experience (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP).
  • Expertise in application security testing (SAST/DAST/SCA).
  • Proficiency in threat modeling, vulnerability/penetration testing, API security, OWASP Top Ten, and AWS/private cloud security.

Responsabilidades

  • Plan and carry out application security testing across the SDLC to identify vulnerabilities and secure coding weaknesses.
  • Assess vulnerabilities and propose risk-mitigating solutions using automation to improve testing and remediation.
  • Communicate findings, risks, and progress to stakeholders with SLAs and business metrics.
  • Lead AI security initiatives, including threat modeling for AI stacks and auditing third-party models/APIs.

Conocimientos

Scripting languages
Software development
Attack thinking

Educación

Bachelor’s degree

Herramientas

SAST
DAST
SCA

Descripción del empleo

The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.

This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege.

What You Will Work On
  • Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices.
  • Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes.
  • Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics.
  • Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain.
  • Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning.
  • Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks.
  • Fully define and follow a security review process to ensure an automated and repeatable process is managed.
  • Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing.
  • Train developers and junior application security engineers on weaknesses to avoid.
  • Perform other duties as assigned.
Who We Are Looking For
  • 4+ years of related experience required.
  • Bachelor’s Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience.
  • Highly technical and analytical, with a background in software development, and scripting (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP).
  • Expertise in application security testing, including hands‑on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools.
  • Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.
  • Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.
  • Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.
What You Can Expect
  • Compensation: The base salary for this position ranges from $111,000 to $144,400 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit‑sharing bonus program, communication stipends, and referral bonuses.
  • Inclusive benefits package offering:
  • Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&D insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources.
  • Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team.
  • Career and skill development resources to help advance your career and personal growth.
  • A mission‑driven environment where your work makes a measurable impact on the real estate industry.
What We Value
  • Wherever it Leads, Whatever it Takes - No matter how remote, complex, or unexpected. Our commitment never wavers.
  • Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit.
  • Lift others up - We lead with empathy and strive to improve the lives of those around us.
  • Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact.
  • Raise the bar - We don’t settle for industry standards, we redefine them.
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa | restb.ai • Reno (NV)

Presencial
USD 111.000 - 144.400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital • Reno (NV)

Presencial
USD 111.000 - 144.000
Medical insurance
Dental insurance
401(k)
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

Presencial
USD 140.000 - 190.000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Security Engineer, Application
Security Engineer, Application

gnw • Richmond (VA)

Híbrido
USD 78.000 - 117.000
Competitive compensation
Comprehensive healthcare coverage
401(k) with employer match
+2
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

Presencial
USD 150.000 - 210.000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Virginia

Presencial
USD 140.000 - 190.000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer
Application Security Engineer

Spry Methods, Inc. • Washington

Presencial
USD 120.000 - 160.000
Medical coverage
Dental coverage
Vision coverage
+4
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Texas City (TX)

Presencial
USD 120.000 - 180.000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Miami (FL)

Presencial
USD 120.000 - 180.000
Professional growth
Competitive compensation
Fortune 500 projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Jacksonville (FL)

Presencial
USD 110.000 - 170.000
Professional growth
Competitive compensation
Exciting projects
+1