Senior Application Security Engineer

Talenthopllc — United States · Posted ~3 hours ago

Senior Full-time Remote

Skills

application security cloud security vulnerability management security engineering secure architecture Cloud Application Security DevSecOps

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A technology organization is looking for a senior security engineer to lead application and cloud security initiatives. The role combines hands-on engineering, vulnerability prevention, and collaboration with development teams to improve security posture.

Highlights

Fully remote role with opportunities to influence security strategy, collaborate with engineering teams, and drive secure software practices.

Description

This is a Fully Remote Job 1. About Our Client: This organization operates within the technology sector, addressing challenges related to application and cloud infrastructure security. It focuses on preventing and mitigating vulnerabilities that impact products and cloud environments. The team is mission-driven, growing rapidly, and committed to fostering a diverse and inclusive workplace that supports professional growth and personal well-being. 2. About the Opportunity: The Senior Application Security Engineer role is a technically deep individual contributor position with responsibilities that blend hands-on security engineering and leadership. The position leads the technical strategy and execution for identifying, remediating, and preventing security vulnerabilities in applications and cloud infrastructure. This role collaborates closely with engineering teams to integrate security into architecture decisions, raising the overall security posture of the organization. 3. Responsibilities: Conduct manual penetration testing, exploit development, and authenticated web/API assessments.Lead threat modeling and secure design reviews for high-risk projects.Own and develop the application security tooling stack including SAST, DAST, SCA, secret scanning, and IaC scanning.Review and improve cloud security configurations including AWS, IAM, and Kubernetes workloads.Develop automation and tools to reduce team workload and improve efficiency.Collaborate with Infrastructure and Platform teams on detection engineering and incident response.Establish and maintain technical standards and mentorship within the AppSec team.Participate in architectural reviews, vendor evaluations, and compliance activities. 4. Requirements: Minimum 8 years of experience in application security, offensive security, or security engineering.Proficiency in manual exploitation of real web and API vulnerabilities.Experience building and operating security tooling including custom detection rules and CI/CD integrations.Practical knowledge of AWS services, container orchestration (Docker, Kubernetes/EKS), and infrastructure-as-code tools.Ability to read and contribute code in languages such as Python, Go, Ruby, or TypeScript.Effective communication skills suitable for technical and leadership audiences.Strong collaborative approach to enable other teams. 5. Pay Range and Compensation Package: Base annual salary of $180,000 to $210,000 plus a competitive equity and benefits package, with salary determined by experience, location, and skills. 6. Benefits & Perks: Comprehensive health plans401(k) programCommuter benefitsParental leaveFlexible time off policyProfessional development support Equal Opportunity Statement: Our client is an equal opportunity employer. They celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, or national origin. Note: TalentHop is a recruitment partner of this role. Please note that all employment decisions, including candidate assessment, interviews, hiring, compensation, and employment terms, are made exclusively by the hiring employer.