Staff Application Security Engineer

Triwill Group

United States

On-site

USD 120,000 - 145,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Fully remote work arrangement

Job summary

Jobgether is seeking a Staff Application Security Engineer in the United States to design, build, and scale modern application security capabilities across a large enterprise environment. You will combine deep application security expertise with strong software engineering to deliver practical, developer-facing security solutions in CI/CD, containers, IaC, and software supply chains.

You will mentor engineers, influence secure development practices, and shape AI-assisted development guardrails

Qualifications

  • 8+ years of experience in Application Security or related technical discipline.
  • Deep expertise in secure software development and software supply chain security.
  • Hands-on experience building security automation and developer tooling.
  • Strong Python scripting and software engineering skills.
  • Experience with integrating AS technologies into developer workflows.
  • Familiarity with AI-assisted development and secure AI practices.

Responsibilities

  • Design, build, and continuously improve application security capabilities across a large-scale enterprise.
  • Develop reusable security automations, APIs, and workflows to scale security.
  • Establish secure-by-default patterns and paved roads for secure development.
  • Build security solutions across source code, containers, cloud-native apps, and CI/CD.
  • Collaborate with Cloud Security and Platform Engineering to embed security throughout the lifecycle.
  • Mentor engineers and influence secure development practices across teams.

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Application Security Engineer based in United States.

This is a senior technical opportunity focused on building and scaling modern application security capabilities across a complex enterprise environment.
You will combine deep Application Security expertise with strong software engineering skills to create practical, developer-facing security solutions.
The role will turn security strategy into scalable implementations, including automation, secure development patterns, remediation workflows, and AI security guardrails.
You will work closely with Cloud Security, Platform Engineering, Software Engineering, architects, and development teams to embed security throughout the software lifecycle.
The position offers significant technical ownership across application code, cloud-native environments, CI/CD, containers, infrastructure as code, and software supply chains.
You will also help shape how AI-assisted development and agentic workflows can be adopted safely and securely.
As a staff-level technical leader, you will influence engineering practices, mentor others, and make secure development easier to adopt at scale.

Accountabilities
  • Design, build, and continuously improve application security capabilities that enable secure software development across a large-scale enterprise environment.
  • Develop reusable security automations, integrations, APIs, workflows, platforms, and developer tools that reduce manual effort and improve security scalability.
  • Establish secure-by-default golden paths, paved roads, reusable patterns, and engineering practices that make secure development easier for engineering teams to adopt.
  • Build scalable security solutions across source code, open-source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains.
  • Partner with Cloud Security and Platform Engineering teams on security capabilities spanning applications, containers, cloud platforms, CI/CD, infrastructure as code, and software supply chain workflows.
  • Improve vulnerability prioritization, triage, remediation, validation, reporting, and overall time to remediation.
  • Develop security patterns, guardrails, and reusable implementations that enable safe adoption of AI-assisted development tools, coding assistants, and agentic workflows.
  • Apply automation and AI-enabled techniques to improve vulnerability analysis, remediation planning, developer guidance, and security workflow efficiency.
  • Build integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing platforms, reporting solutions, and other engineering tools.
  • Create telemetry, dashboards, and reporting pipelines that provide actionable visibility into application risk, security coverage, and remediation progress.
  • Serve as a senior technical authority in Application Security, secure software development, software supply chain security, and secure AI development.
  • Collaborate with architects, platform engineers, cloud security specialists, and development teams to translate security requirements into practical technical solutions.
  • Mentor engineers, strengthen engineering practices and automation capabilities, and contribute to the continuous improvement of the broader security organization.
Requirements
  • 8+ years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a closely related technical discipline.
  • Deep expertise in secure software development, application security, vulnerability management, and software supply chain security.
  • Hands-on experience building security automation, integrations, APIs, platforms, developer tooling, or comparable engineering solutions.
  • Strong software engineering and scripting capabilities using Python or similar programming languages.
  • Experience integrating application security technologies such as SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows.
  • Strong understanding of secure development practices and the ability to solve complex, ambiguous technical challenges.
  • Ability to influence adoption through hands-on implementation, clear documentation, technical guidance, and cross-functional collaboration.
  • Familiarity with AI-assisted software development, agentic workflows, and their associated security considerations.
  • Experience with application security platforms such as Snyk, Wiz Code, GitHub Advanced Security, Checkmarx, Veracode, or comparable technologies is preferred.
  • Experience building secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services is a strong plus.
  • Experience across both Application Security and Cloud Security, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies, is desirable.
  • Knowledge of software supply chain security, SBOM capabilities, dependency risk management, and artifact security processes is preferred.
  • Experience applying AI to vulnerability management, remediation workflows, security operations, or developer productivity is a plus.
  • Strong communication and technical leadership skills, with the ability to mentor engineers and collaborate effectively across highly technical teams.
Benefits
  • Competitive annual salary of $120,000–$145,000, with bonus eligibility.
  • Fully remote work arrangement.
  • Medical, dental, and vision insurance.
  • 401(k) retirement plan.
  • Paid leave.
  • Tuition reimbursement.
  • Additional employee discounts, perks, and company-sponsored benefits.
  • Opportunity to work on enterprise-scale application security, cloud security, software supply chain, and secure AI initiatives.
  • Ongoing opportunity to influence engineering standards, automation, and security practices across a large technology environment.
  • Applications accepted on an ongoing basis.

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Application Security Engineer (Remote - US)
Application Security Engineer (Remote - US)

Jobgether • United States

Remote
USD 103,000 - 128,000
Competitive salary
Flexible remote work options
Health, dental, and vision insurance
+2
Staff Application Security Engineer
Staff Application Security Engineer

Nclusion • Palo Alto (CA)

Hybrid
USD 200,000 - 260,000
401k match
Medical Insurance
Dental Insurance
+4
Senior Manager, Security Engineering
Senior Manager, Security Engineering

Jobgether • United States

On-site
USD 137,000 - 222,000
401(k) match
Medical benefits
Equity opportunities
+2
Application Security Engineer-68257
Application Security Engineer-68257

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Staff Application Security Engineer
Staff Application Security Engineer

Nclusion, Inc. • Palo Alto (CA)

On-site
USD 180,000 - 240,000
401k with match
Medical Insurance
Dental Insurance
+4
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Triwill Group • United States

On-site
USD 140,000 - 200,000
Remote-first
Competitive salary
Unlimited PTO
+2
Architect, Information Security - DevSecOps/Application Security
Architect, Information Security - DevSecOps/Application Security

Jobgether • United States

On-site
USD 72,000 - 157,000
Competitive compensation
US-based role
Enterprise security exposure
Director, Security Engineering
Director, Security Engineering

Jobgether • United States

Remote
USD 162,000 - 209,000
Remote-first work environment
Competitive compensation
Healthcare and wellness benefits
+2