- Job title – Application Security Specialist
- Department – IT Security
- Level – Vice President
- Reports to – Director, Application Security
- Location – New Jersey
- Compensation – $140,000–$180,000 base salary + variable compensation + 401(k) match + benefits
We’re hiring an Application Security Specialist to help development teams build secure, resilient software. This is a hands‑on AppSec role for someone who can interpret security findings, understand real‑world application risk, and turn that insight into practical guidance for engineers.
This is not a DevSecOps tooling integration role: engineering teams own security tool integration, automation, and pipeline operation. Your focus will be on understanding the output of those tools, separating meaningful risk from noise, and partnering with developers to improve the security of the code we write.
What you’ll do:
- Analyze and validate findings from SAST, DAST, SCA, API security testing, AI-assisted analysis, penetration testing, and code reviews.
- Assess vulnerabilities in context, considering exploitability, business impact, compensating controls, and realistic application risk.
- Work closely with development teams to explain issues clearly, prioritize remediation, and support secure implementation choices.
- Lead or facilitate threat modelling, secure design reviews, and architecture risk reviews for new features, services, APIs, and platforms.
- Promote secure coding standards, reusable security patterns, and practical guidance that reduce recurring vulnerability themes.
- Provide AppSec subject‑matter expertise to improve security testing, reporting, and SDLC processes without owning pipeline integration or tool administration.
What you’ll bring:
- Strong experience in application security, secure coding, secure‑by‑design practices, application security testing, and vulnerability management.
- Solid understanding of common application and API vulnerability classes, including the OWASP Top 10, and how to remediate them in modern software environments.
- Ability to read and reason about code well enough to validate findings, identify root causes, and discuss remediation options with developers.
- Experience with threat modelling, architecture risk reviews, secure design reviews, or similar AppSec activities.
- Practical knowledge of SAST, DAST, SCA, API security, secrets detection, and related testing approaches, with an emphasis on interpreting results rather than administering tools.
- Clear communication skills and the ability to translate security risk into practical guidance for engineering, product, and technology leadership audiences.
- Collaborative mindset, sound risk judgement, and a coaching style that helps development teams improve their security capability over time.
Qualifications:
- Degree in a technology discipline such as Computer Science, Information Management, Computer Engineering, Cybersecurity, or equivalent practical experience.
- Relevant security certifications such as CISSP, CSSLP, GWAPT, GWEB, or equivalent are preferred but not required.