Senior Application Security Engineer

Motion Recruitment Partners — United States · Posted ~5 hours ago

Senior Contract Hybrid No Visa

Skills

application security secure software engineering cloud-native security vulnerability management security automation secure software delivery

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Work as a senior technical contributor advancing application security across a large-scale technology environment. You will address complex security challenges, strengthen secure software engineering practices, improve vulnerability management and automation, and translate security requirements into practical engineering solutions.

Highlights

Senior security engineering opportunity with broad enterprise scope, focused on strengthening application security, improving developer experience, and enabling secure software delivery at scale.

Description

About the Company Motion recruitment has partnered with a global Enterprise client and seeking a senior Application security engineer for a contract to hire role. About the Role We are seeking a Senior Application Security Engineer to help advance enterprise application security capabilities across a large-scale technology environment. This role is a senior technical contributor responsible for strengthening application security, improving developer experience, and enabling secure software delivery at scale. The ideal candidate brings deep expertise in application security, secure software engineering, cloud-native security, vulnerability management, and security automation, with the ability to solve complex security challenges and translate security requirements into practical engineering solutions. This position is a hybrid role with 3 days in the office. This is a W2 position only. Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time. Responsibilities Design, implement, and optimize enterprise application security capabilities, including SAST, SCA, Secrets, DAST, API, Container, and Infrastructure-as-Code (IaC) security.Develop and maintain security baselines, detection logic, and risk models to improve finding quality, reduce false positives, and prioritize exploitable vulnerabilities.Perform advanced application security assessments, including secure code reviews, architecture reviews, threat modeling, and exploit validation.Research emerging vulnerabilities, attack techniques, and defensive technologies to continuously improve application security capabilities.Design and implement security automation that scales application security throughout the software development lifecycle.Integrate security tooling into centralized vulnerability management platforms and developer workflows.Develop secure-by-default patterns, reusable security controls, and engineering guidance for development teams.Lead technical investigations into complex application security findings and recommend practical remediation strategies.Design, implement, and optimize Web Application Firewall (WAF) and CDN security capabilities, including DDoS protection, bot mitigation, and traffic management.Evaluate and improve security tooling to increase automation, detection accuracy, and operational efficiency.Assess cloud-native applications, APIs, containers, and modern architectures to identify security gaps and recommend improvements.Develop technical documentation, reference implementations, operational runbooks, and engineering standards.Define and monitor security metrics and KPIs to measure program effectiveness and drive continuous improvement.Mentor engineers through technical coaching, design reviews, and knowledge sharing.Collaborate with Platform Engineering, DevOps, Development, Security Operations, and Enterprise Architecture teams to deliver secure software at scale.Participate in Agile development activities, including sprint planning, backlog refinement, estimation, stand-ups, and retrospectives.Participate in a 24/7 on-call rotation, including weekends and holidays. Qualifications Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related technical field.6–8 years of relevant experience in Application Security, Software Engineering, Security Engineering, or Cloud Security.Hands-on experience with secure software development and secure SDLC practices.Advanced expertise in application security, vulnerability management, and secure software engineering.Strong experience conducting secure code reviews, architecture assessments, exploit validation, and threat modeling.Advanced knowledge of OWASP Top 10, OWASP ASVS, CWE Top 25, CAPEC, and modern application attack techniques.Hands-on experience with SAST, SCA, Secrets, DAST, API, Container, IaC, and Software Supply Chain security tools.Strong experience integrating security controls into CI/CD pipelines.Strong understanding of cloud-native security in AWS, Azure, or GCP; AWS experience is preferred.Experience securing Kubernetes, Docker, serverless applications, APIs, and microservice architectures.Advanced knowledge of API security, including OAuth, JWT, authentication, authorization, SSRF protections, and access controls.Strong understanding of cryptography, secrets management, and secure key management.Experience with Infrastructure-as-Code security using Terraform, CloudFormation, or equivalent technologies.Experience deploying and tuning WAF technologies, such as Imperva, Cloudflare, Akamai, AWS WAF, Azure Front Door, or similar platforms.Strong understanding of CDN security, bot mitigation, DDoS protection, caching, and edge security.Experience with runtime security, workload protection, and modern cloud security controls.Strong scripting and automation skills using Python and/or Go. Required Skills Hands-on experience with secure software development and secure SDLC practices.Advanced expertise in application security, vulnerability management, and secure software engineering.Strong experience conducting secure code reviews, architecture assessments, exploit validation, and threat modeling.Advanced knowledge of OWASP Top 10, OWASP ASVS, CWE Top 25, CAPEC, and modern application attack techniques.Hands-on experience with SAST, SCA, Secrets, DAST, API, Container, IaC, and Software Supply Chain security tools.Strong experience integrating security controls into CI/CD pipelines.Strong understanding of cloud-native security in AWS, Azure, or GCP; AWS experience is preferred.Experience securing Kubernetes, Docker, serverless applications, APIs, and microservice architectures.Advanced knowledge of API security, including OAuth, JWT, authentication, authorization, SSRF protections, and access controls.Strong understanding of cryptography, secrets management, and secure key management.Experience with Infrastructure-as-Code security using Terraform, CloudFormation, or equivalent technologies.Experience deploying and tuning WAF technologies, such as Imperva, Cloudflare, Akamai, AWS WAF, Azure Front Door, or similar platforms.Strong understanding of CDN security, bot mitigation, DDoS protection, caching, and edge security.Experience with runtime security, workload protection, and modern cloud security controls.Strong scripting and automation skills using Python and/or Go. Preferred Skills Experience with vulnerability research, exploit development, reverse engineering, or binary analysis.Experience working in large-scale enterprise or global technology environments.Experience building security automation and reusable security frameworks.Strong understanding of modern application architectures and cloud security patterns. Pay range and compensation package