All roles

Application Security Engineer / Senior AppSec Engineer

Remote · USA Full-time New today

Job Information Date Opened 03/27/2026 Job Type Full time Remote Job Industry Technology This is a remote position. We are seeking a skilled Application Security Engineer to drive secure development practices and manage end-to-end application security testing, vulnerability management, and DevSecOps integration. The role requires hands-on experience in SAST/DAST tools, vulnerability scanning, CI/CD security integration, and manual security testing across web and API-based applications.

Key Responsibilities

  • Perform application security assessments for web and API applications
  • Integrate security into Secure SDLC (SSDLC) and DevSecOps pipelines
  • Conduct threat modeling and security design reviews
  • Execute vulnerability scans using tools like Tenable
  • Analyze results from SAST, DAST, and manual testing
  • Document findings including severity, exploitability, reproduction steps, and remediation guidance
  • Integrate and maintain SAST/DAST tools within CI/CD pipelines
  • Perform vulnerability validation, PoC development, and false-positive analysis
  • Apply risk-based prioritization and track remediation to closure
  • Provide L2/L3 support, incident investigation, and root cause analysis (RCA)
  • Maintain AppSec documentation, audit evidence, and compliance reports
  • Track and report vulnerability metrics, scan coverage, and remediation status

Required Skills

  • Strong experience in Application Security (Web & API Security Testing)
  • Expertise in OWASP Top 10 vulnerabilities and remediation techniques
  • Hands-on experience with SAST tools (Checkmarx, Veracode, SonarQube)
  • Hands-on experience with DAST tools (Burp Suite, OWASP ZAP)
  • Experience with vulnerability scanning tools (Tenable preferred)
  • Knowledge of Secure SDLC and DevSecOps practices
  • Strong understanding of HTTP, REST APIs, authentication (OAuth, JWT)
  • Proficiency in Python / Bash / PowerShell scripting
  • Experience with CI/CD tools and pipeline security integration
  • Familiarity with JIRA / ServiceNow or similar tracking tools

Preferred Qualifications

  • Experience in manual penetration testing and exploit development
  • Exposure to red team techniques and offensive security testing
  • Experience in cloud environments (AWS / Azure / GCP)
  • Knowledge of container and microservices security (Docker, Kubernetes)
  • Experience supporting SOC 2, ISO 27001, or similar audits

Certifications (Preferred)

  • OSCP / OSWE / GWAPT / eWPT
  • CEH (Certified Ethical Hacker)
  • CISSP / CSSLP
  • AWS Security Specialty / Azure Security Engineer
  • Certified Kubernetes Security Specialist (CKS)

Soft Skills

  • Strong analytical and problem-solving skills
  • Excellent communication and collaboration with engineering teams
  • Ability to work in SLA-driven environments
  • Detail-oriented with strong documentation skills

Apply tot his job Apply To this Job

Related roles

ICT + Security Designer D2

Remote · USA Full-time

Hybrid Network Security Engineer Firewall & Policy Management

Remote · USA Full-time

IoT / ICS / OT Penetration Tester

Remote · USA Full-time

Summer Internship - Security Engineering

Remote · USA Full-time

AI Security Consultant

Remote · USA Full-time

Information System Security Officer, Proposal

Remote · USA Full-time

Security Penetration Tester

Remote · USA Full-time

Pentration Tester

Remote · USA Full-time

Application Penetration testers /Dynamic Application Security Testing (DAST)

Remote · USA Full-time

Penetration Tester - Angular & PHP Web Application

Remote · USA Full-time

Looking for Future Agency Owners - Texas Hiring Event (June 25)

Remote · USA Full-time

Experienced Remote Data Entry Specialist – Flexible Work Arrangements at arenaflex

Remote · USA Full-time

Experienced Identity and Access Management (IAM) Developer – Integration and Governance Specialist at arenaflex

Remote · USA Full-time

Labor Relations Consultant (HR Office of Employee & Labor Relations)

Remote · USA Full-time

Experienced Full Stack Content & Customer Experience Specialist – Web & Cloud Application Development

Remote · USA Full-time

Inside Sales Representative - Dropbox (German Bilingual)

Remote · USA Full-time

Steuerfachkraft (m/w/d) in Weingarten mindestens 52.000€ - 100% Remote möglich

Remote · USA Full-time

Sneaker Authentication Specialist - Premium Footwear Verification & Quality Assurance Professional ($32/Hour)

Remote · USA Full-time

Copywriter, Sr.

Remote · USA Full-time

Experienced Full Stack Data Entry Specialist – Remote, Part-Time Position with Competitive Hourly Rate

Remote · USA Full-time