Staff Application Security Engineer

Sunrun

United States

On-site

USD 100,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading renewable energy company is seeking a Staff Application Security Engineer. This position involves protecting applications, managing identity security solutions, and integrating security practices into development workflows. Successful candidates will have over 5 years of experience in application security and identity management, along with proficiency in relevant programming languages and security tools. This primarily remote role will require occasional on-site teamwork and training.

Qualifications

  • 5+ years of combined experience in application security and identity access management.
  • Deep knowledge of application security principles and zero-trust architecture.
  • Hands-on experience with security tools and programming languages like Java, Python, or JavaScript.

Responsibilities

  • Assess potential attack vectors and design defense-in-depth strategies.
  • Integrate security into every stage of the software development lifecycle.
  • Design and manage identity security solutions across applications.

Skills

Application security principles
Secure coding practices
OWASP Top 10
Critical thinking
Collaboration skills

Tools

SAST
DAST
IAM platforms (e.g., Okta)
AWS IAM

Job description

Overview

Staff Application Security Engineer at Sunrun. This position is primarily remote, with occasional visits to a local office or our corporate headquarters for team-building, training, and collaborative project work. Equipment pick-up from a local branch will be required. We will provide advance notice whenever on-site attendance is required, making these times purposeful and rewarding.

Position Overview: The Application Security Engineer at Sunrun plays a pivotal role in protecting the applications that power our business. This position requires expertise across identity systems, and software development lifecycle. You will be responsible for driving the identification, assessment, and mitigation of security risks from the initial design phase through deployment and beyond. You will collaborate closely with developers and IT teams to integrate robust security practices, implement advanced protective measures for both applications and identities, and foster a comprehensive culture of security across the organization.

Responsibilities
  • Threat Modeling & Security Design: Assess potential attack vectors and design defense-in-depth strategies that address gaps across infrastructure, 1st and 3rd party applications, and identity management.
  • Secure Software Development Life Cycle (SSDLC): Partner with application development teams to integrate security into every stage of the development lifecycle. Champion secure coding standards, conduct security code reviews, and provide expert guidance to minimize vulnerabilities before production.
  • Identity & Access Management (IAM): Design, implement, and manage identity security solutions across 1st and 3rd party applications. Demonstrate hands-on experience in implementing strategies like Zero Trust architecture and modern authentication standards like WebAuthn.
  • Implement & Manage Security Controls: Design, implement, and fine-tune application security controls like SAST/DAST vulnerability scanning and standardizing secure coding practices. Establish and improve operational processes to ensure their continued effectiveness.
  • Guidance, Training & Compliance: Develop and maintain security policies and standards for both application and identity security. Provide ongoing training to developers to elevate secure coding practices.
  • Stakeholder Collaboration: Use strong critical thinking and communication skills to present complex technical concepts to business stakeholders, gain alignment, and independently drive security initiatives forward.
Qualifications
  • 5+ years of combined experience in application security and IAM
  • Deep knowledge of application security principles, secure coding practices, OWASP Top 10, and zero-trust architecture
  • Hands-on experience with SAST, DAST, WAF, and IAM platforms (e.g., Okta, AWS IAM)
  • Proficiency in programming languages such as Java, Python, or JavaScript
  • Familiarity with cloud environments (AWS, GCP) and their native security and identity controls
  • Threat modeling and defense-in-depth design experience
  • Understanding of MFA, SSO, WebAuthn
  • Excellent communication and collaboration skills
  • Strong critical thinking and problem-solving abilities
Preferred Qualifications
  • Experience with Okta and Salesforce security principles
  • Certifications (preferred): CISSP, CASE, or similar

Recruiter: Kristina Sedjo (kristina.sedjo@sunrun.com)

Apply Now

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Staff Application Security Engineer
Staff Application Security Engineer

Nclusion, Inc. • Palo Alto (CA)

On-site
USD 180,000 - 240,000
401k with match
Medical Insurance
Dental Insurance
+4
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital • Reno (NV)

On-site
USD 111,000 - 145,000
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Application Security Engineer
Application Security Engineer

Jobtailor • Atlanta (GA)

On-site
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Awardco • Lindon (UT)

On-site
USD 140,000 - 170,000
Application Security Engineer - Chandler, AZ
Application Security Engineer - Chandler, AZ

Motion Recruitment Partners LLC • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2