Location: New York, NY or Charlotte, NC – Hybrid
Schedule: 3 days onsite per week
Pay Rate: $65–$68/hour on W-2
No C2C or third-party candidates
Position Overview
We are seeking an experienced Application Security Engineer to help build, operationalize, and scale an enterprise application security program across multiple business units and development organizations.
This position will have end-to-end involvement in application security, from application discovery and risk classification through implementation of AppSec tooling, CI/CD security integration, secure SDLC practices, threat modeling, and AI-assisted security workflows.
This is both a hands-on technical and relationship-driven role. The successful candidate must be capable of working directly with security tooling and development pipelines while also influencing engineering teams and driving security adoption across independent business units.
Key Responsibilities
- Perform application discovery and inventory across multiple business units.
- Map application ownership, technology stacks, and risk classifications.
- Implement, configure, and operate modern AppSec tooling, including:
- SAST
- Software Composition Analysis (SCA)
- Secrets scanning
- Container scanning
- Infrastructure-as-Code (IaC) scanning
- Integrate application security tooling and controls into CI/CD pipelines.
- Design and implement AI-assisted vulnerability triage workflows to reduce false positives and prevent excessive finding volume from overwhelming development teams.
- Define and operationalize secure SDLC requirements, security gates, and threat-modeling practices.
- Partner with development and engineering leaders to integrate security without unnecessarily slowing software delivery.
- Develop shared AppSec standards and playbooks that can be adopted across multiple engineering organizations.
- Evaluate emerging AI security and LLM-based security technologies, including AI-assisted code review, agentic security testing, automated remediation guidance, and security requirement generation.
- Recommend which emerging security technologies should be operationalized based on risk, effectiveness, and business value.
- Develop executive-level metrics and reporting connecting AppSec activities with measurable business risk reduction.
- Promote application security best practices across engineering and technology organizations.
Required Qualifications
- 7+ years of experience in Application Security, Product Security, Security Engineering, or a closely related discipline.
- At least 3 years of experience working across multiple independent business units, brands, or product lines.
- Hands-on experience implementing and operating modern AppSec platforms such as:
- Semgrep
- Checkmarx
- Veracode
- Ox Security
- GitHub Advanced Security
- Ability to read application code, review vulnerabilities, and independently triage security findings.
- Strong scripting and automation experience using Python or equivalent technologies.
- Experience building integrations using REST APIs.
- Hands-on CI/CD experience with platforms such as:
- GitHub Actions
- Jenkins
- Strong understanding of OWASP Top 10 and modern application attack patterns.
- Practical threat-modeling experience using STRIDE, PASTA, or equivalent methodologies.
- Understanding of software supply-chain security risks.
- Demonstrated ability to influence engineering teams without direct authority.
- Experience driving adoption of security standards and working directly with development leadership.
- Strong communication, relationship-building, and stakeholder-management skills.
Preferred Qualifications
- Experience integrating LLM-based or AI-assisted technologies into security workflows, including vulnerability triage, finding summarization, remediation guidance, or similar use cases.
- Experience evaluating AI code-review assistants, agentic security testing tools, or other emerging AI security technologies.
- Familiarity with compliance and security frameworks such as HITRUST, HIPAA, NIST AI RMF, or SOC 2.
- Experience within regulated or healthcare-adjacent environments.Strong cloud security knowledge in AWS, Azure, or GCP.
- Public contributions to the AppSec community through open-source projects, conference presentations, published research, security rules, or detection content.