Senior Application Security Specialist

A-Line Staffing Solutions

Charlotte (NC)

Hybrid

USD 56,000 - 94,000

Full time

25 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

A-Line Staffing Solutions in New York, NY or Charlotte, NC is seeking an experienced Application Security Engineer to build and scale an enterprise AppSec program. This hands-on role works with security tooling, CI/CD pipelines, and secure SDLC practices.

You will lead vulnerability triage workflows, threat modeling, and integration with development teams, influencing engineering leaders without direct authority. Strong scripting and REST API experience are essential.

Qualifications

  • 7+ years in Application Security or related field.
  • Experience across multiple business units or product lines.
  • Hands-on with AppSec platforms (Semgrep, Checkmarx, Veracode, Ox Security, GHAS).
  • Ability to read code, triage findings, and automate security tasks.
  • Strong scripting (Python) and REST API integrations.
  • CI/CD experience with GitHub Actions or Jenkins.
  • Strong knowledge of OWASP Top 10 and threat modeling methods.

Responsibilities

  • Perform application discovery and inventory across multiple units.
  • Map ownership, tech stacks, and risk classifications.
  • Operate AppSec tooling (SAST, SCA, secrets, container, IaC scanning).
  • Integrate AppSec into CI/CD pipelines.
  • Design AI-assisted vulnerability triage workflows to minimize false positives.
  • Define secure SDLC requirements and threat-modeling practices.
  • Collaborate with engineering leaders to enable security without slowing delivery.
  • Develop shared AppSec standards and playbooks across teams.
  • Evaluate emerging AI security technologies for risk and value.
  • Develop metrics linking AppSec activities to business risk reduction.
  • Promote secure coding practices across engineering teams.

Skills

Application Security
Cross-organization collaboration
AppSec tooling
SAST
SCA
Secrets scanning
Container scanning
IaC scanning
CI/CD integration
Threat modeling
Python scripting
REST APIs
GitHub Actions / Jenkins
OWASP Top 10
STRIDE/PASTA
Influence without authority
Security metrics

Job description

Location: New York, NY or Charlotte, NC – Hybrid

Schedule: 3 days onsite per week

Pay Rate: $65–$68/hour on W-2

No C2C or third-party candidates

Position Overview

We are seeking an experienced Application Security Engineer to help build, operationalize, and scale an enterprise application security program across multiple business units and development organizations.

This position will have end-to-end involvement in application security, from application discovery and risk classification through implementation of AppSec tooling, CI/CD security integration, secure SDLC practices, threat modeling, and AI-assisted security workflows.

This is both a hands-on technical and relationship-driven role. The successful candidate must be capable of working directly with security tooling and development pipelines while also influencing engineering teams and driving security adoption across independent business units.

Key Responsibilities
  • Perform application discovery and inventory across multiple business units.
  • Map application ownership, technology stacks, and risk classifications.
  • Implement, configure, and operate modern AppSec tooling, including:
  • SAST
  • Software Composition Analysis (SCA)
  • Secrets scanning
  • Container scanning
  • Infrastructure-as-Code (IaC) scanning
  • Integrate application security tooling and controls into CI/CD pipelines.
  • Design and implement AI-assisted vulnerability triage workflows to reduce false positives and prevent excessive finding volume from overwhelming development teams.
  • Define and operationalize secure SDLC requirements, security gates, and threat-modeling practices.
  • Partner with development and engineering leaders to integrate security without unnecessarily slowing software delivery.
  • Develop shared AppSec standards and playbooks that can be adopted across multiple engineering organizations.
  • Evaluate emerging AI security and LLM-based security technologies, including AI-assisted code review, agentic security testing, automated remediation guidance, and security requirement generation.
  • Recommend which emerging security technologies should be operationalized based on risk, effectiveness, and business value.
  • Develop executive-level metrics and reporting connecting AppSec activities with measurable business risk reduction.
  • Promote application security best practices across engineering and technology organizations.
Required Qualifications
  • 7+ years of experience in Application Security, Product Security, Security Engineering, or a closely related discipline.
  • At least 3 years of experience working across multiple independent business units, brands, or product lines.
  • Hands-on experience implementing and operating modern AppSec platforms such as:
  • Semgrep
  • Checkmarx
  • Veracode
  • Ox Security
  • GitHub Advanced Security
  • Ability to read application code, review vulnerabilities, and independently triage security findings.
  • Strong scripting and automation experience using Python or equivalent technologies.
  • Experience building integrations using REST APIs.
  • Hands-on CI/CD experience with platforms such as:
  • GitHub Actions
  • Jenkins
  • Strong understanding of OWASP Top 10 and modern application attack patterns.
  • Practical threat-modeling experience using STRIDE, PASTA, or equivalent methodologies.
  • Understanding of software supply-chain security risks.
  • Demonstrated ability to influence engineering teams without direct authority.
  • Experience driving adoption of security standards and working directly with development leadership.
  • Strong communication, relationship-building, and stakeholder-management skills.
Preferred Qualifications
  • Experience integrating LLM-based or AI-assisted technologies into security workflows, including vulnerability triage, finding summarization, remediation guidance, or similar use cases.
  • Experience evaluating AI code-review assistants, agentic security testing tools, or other emerging AI security technologies.
  • Familiarity with compliance and security frameworks such as HITRUST, HIPAA, NIST AI RMF, or SOC 2.
  • Experience within regulated or healthcare-adjacent environments.Strong cloud security knowledge in AWS, Azure, or GCP.
  • Public contributions to the AppSec community through open-source projects, conference presentations, published research, security rules, or detection content.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

BBG Ventures, LLC • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Medical, Dental, and 401k (no match)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

BBG Ventures, LLC • New York (NY)

Hybrid
USD 120,000 - 180,000
Medical, Dental, and 401k (no match)
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

The Mom Project • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Medical
Dental
401k
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)
Application Security Engineer (Hybrid - New York, NY or Charlotte, NC)

The Mom Project • New York (NY)

Hybrid
USD 140,000 - 190,000
Medical
Dental
401k (no match)
Application Security Engineer ( Only USC Or GC)
Application Security Engineer ( Only USC Or GC)

LinQ Global Group • Philadelphia

Hybrid
USD 110,000 - 160,000
Senior Security Engineer
Senior Security Engineer

STEPS Talent • New York (NY)

Hybrid
USD 140,000 - 200,000
Senior Application Security Specialist
Senior Application Security Specialist

CLS Group • Woodbridge Township (NJ)

On-site
USD 140,000 - 180,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000