Staff Engineer, Application Security

BetterCloud

Buffalo (NY)

On-site

USD 110,000 - 170,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ACV is seeking an Application Security Engineer to lead the development and maturation of our AppSec program within a fast-paced, cloud-native SaaS environment. You’ll work across engineering, product, and DevOps to ensure secure design, implementation, and deployment of our applications and services.

You will partner with engineering, product, and DevOps to embed security into the software development lifecycle, drive secure-by-default design, and mentor teams on threat modeling, code reviews,

Qualifications

  • Experience building or leading an Application Security Program at a tech-driven org.
  • Deep knowledge of web/mobile vulnerabilities (OWASP Top 10) and microservices security.
  • Cloud-native architectures (preferably AWS) and secure-by-default engineering.
  • Hands-on securing CI/CD environments and working with DevOps.
  • Industry certifications a plus (e.g., OSWE, GWAPT, CSSLP, CISSP).

Responsibilities

  • Design, implement, and scale ACV's Application Security Program aligning with Secure SDLC practices.
  • Integrate security tools into CI/CD pipelines (SAST, DAST, SCA, secrets management).
  • Conduct and oversee code reviews, security assessments, and pen testing of apps and services.
  • Lead threat modeling workshops, security training, and awareness initiatives for developers and architects.
  • Develop policies, standards, and automation to support a secure-by-default culture.
  • Drive remediation with developers and collaborate with compliance and risk teams for audits.

Skills

AppSec program leadership
Secure SDLC/Shift Left
CI/CD security
SAST/DAST/SCA and secrets
Threat modeling
Code reviews & security assessments
AWS/cloud-native
Security testing tools
OWASP Top 10 knowledge
DevSecOps collaboration

Tools

Burp Suite
GitHub Advanced Security
Snyk
Checkmarx

Job description

Who we are looking for:

ACV is looking for an Application Security Engineer to join our security team and lead the development and maturation of our Application Security (AppSec) program. This is a high-impact role for someone with a proven track record of embedding security into modern software development lifecycles in SaaS environments. You’ll work across engineering, product, and DevOps to ensure secure design, implementation, and deployment of our applications and services. This role is ideal for a developer turned security leader who has built or significantly matured an AppSec program from the ground up and is looking to drive impact at scale within a fast-paced, cloud-native, DevSecOps environment.

What you will do:

Actively and consistently support all efforts to simplify and enhance the customer experience. Design, implement, and scale ACV's Application Security Program, aligning with Secure SDLC best practices and taking a Shift Left by default approach. Serve as the subject matter expert for secure application architecture, code analysis, and application threat modeling. Partner with engineering and security teams to integrate security tools and controls into CI/CD pipelines (e.g., SAST, DAST, SCA, secrets management). Conduct and oversee escalated code reviews, security assessments, and pen testing of internal and external applications. Lead threat modeling workshops, security training, and awareness initiatives for developers and architects. Develop policies, standards, and automation to support a secure-by-default engineering culture. Drive remediation efforts by working hands‑on with developers to fix critical vulnerabilities. Collaborate with compliance and risk teams to meet security audit and regulatory requirements (SOC2, ISO27001, etc.). Stay current on emerging threats, vulnerabilities, and secure development trends. Perform additional duties as assigned.

What you will need:

Ability to read, write, speak and understand English. Attention to detail and strong organizational skills Critical thinking and problem‑solving abilities Effective written and verbal English communication skills Demonstrated experience building or leading a successful Application Security Program at a technology‑driven organization Deep technical knowledge of common web and mobile vulnerabilities (e.g., OWASP Top10), microservices security, and cloud‑native architectures (preferably AWS) Strong proficiency with security testing tools (e.g., Burp Suite, GitHub Advanced Security, Snyk, Checkmarx, etc.) Familiarity with modern development stacks and languages (e.g., Node.js, Python, Go, React). Hands‑on experience securing CI/CD environments and working with DevOps teams Experience conducting code and security reviews of architecture designs, APIs, and infrastructure‑as‑code Strong communication skills with the ability to influence engineers and leadership alike as well as understand that different audiences require different messages Industry certifications a plus (e.g., OSWE, GWAPT, CSSLP, CISSP)

#LI-AM3

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Engineer: Scale Secure SDLC
Staff Application Security Engineer: Scale Secure SDLC

BetterCloud • Buffalo (NY)

On-site
USD 110,000 - 170,000
Staff Engineer, Application Security — Lead Secure DevOps
Staff Engineer, Application Security — Lead Secure DevOps

Socket.dev • Buffalo (NY)

On-site
USD 120,000 - 190,000
Medical plans
Disability & Life Insurance
PTO & holidays
+2
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Staff Engineer, Application Security
Staff Engineer, Application Security

ACV Auctions • Buffalo (NY), Northern (KY)

Hybrid
USD 110,000 - 170,000
Health plans
Disability & Life Insurance
Dental & Vision
+3
Staff Engineer, Application Security
Staff Engineer, Application Security

Socket.dev • Buffalo (NY)

On-site
USD 120,000 - 190,000
Medical plans
Disability & Life Insurance
PTO & holidays
+2
AppSec Architect & DevSecOps Leader
AppSec Architect & DevSecOps Leader

ACV Auctions • Buffalo (NY), Northern (KY)

Hybrid
USD 110,000 - 170,000
Health plans
Disability & Life Insurance
Dental & Vision
+3
Director Application Security
Director Application Security

Vibehackers • Austin (TX), Northern (KY)

Hybrid
USD 180,000 - 250,000
Medical Insurance
Dental Insurance
Life Insurance
+3
Principal Application Security Engineer
Principal Application Security Engineer

CDW • United States

On-site
USD 180,000 - 240,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000