Senior Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (Cybersecurity): Own and lead the application security program for a SaaS CMMS platform with an accent on threat modeling, secure design reviews, and vulnerability remediation workflows. Focus on implementing and managing SAST, SCA, SBOM, DAST tooling in CI/CD pipelines, enforcing OWASP/NIST standards, and leveraging AI-assisted techniques for scalable security testing.
Fully remote position
$165,000 - $185,000 annual salary
Company
provides a comprehensive SaaS CMMS platform to optimize asset performance and maintenance operations.
What you will do
- Define application security strategy, roadmap, and standards aligned with OWASP Top 10 and NIST 800-218.
- Perform hands-on threat modeling, secure design reviews, and vulnerability triage/remediation.
- Implement security testing (SAST, SCA, SBOM, DAST) and integrate tooling into CI/CD pipelines using GitHub or Wiz.
- Drive secure coding enablement, OWASP training, and scale the Security Champions program.
- Track program metrics, facilitate Responsible Disclosure, and deliver prioritized remediation roadmaps.
- Leverage AI tools like Claude and Cursor for vulnerability discovery and automation.
Requirements
- 5–8+ years in application security, product security, or security-focused software engineering.
- Deep expertise in web/API security, OWASP Top 10, secure SDLC, cloud-native SaaS, and microservices.
- Strong knowledge of AWS, GitHub CI/CD, Jira, SAST/SCA/DAST tools, and threat modeling (STRIDE/DREAD).
- Experience with real-world exploits (auth bypass, injection, SSRF, XSS, IDOR) and AI-assisted dev tools.
- Proven ability to influence engineering teams and drive outcomes through trust and practical solutions.
Nice to have
- Familiarity with Wiz or similar security platforms.
Culture & Benefits
- Fully remote with flexible PTO and 13 paid company holidays.
- Health, dental, vision insurance; employer-paid life and short-term disability.
- 401(k) and HSA matching, flexible spending accounts, wellness stipend.
- Paid parental leave, pet insurance, learning and development reimbursement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →