Application Security Engineer in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Engineer based in the United States.
This is an opportunity to take ownership of application security across a modern, cloud-native technology environment.
You will lead vulnerability management from discovery and prioritization through remediation, reporting, and continuous improvement.
The role combines hands-on security engineering with strategic influence across software development and infrastructure teams.
You will strengthen operating system images, open-source dependencies, and the broader software supply chain against emerging threats.
You will also embed security validation directly into CI/CD workflows through automation, testing, and modern security tooling.
Working cross-functionally, you will establish secure-coding practices and help engineering teams adopt security as part of everyday development.
This role is ideal for a pragmatic security professional who enjoys solving complex problems and balancing strong protection with usability and delivery speed.
- Own vulnerability management: Lead the end-to-end vulnerability management lifecycle across the technology stack, including vulnerability discovery, risk prioritization, remediation, reporting, measurement, and continuous improvement.
- Secure the software supply chain: Harden base operating system images and strengthen the security of open-source software, dependencies, package managers, and other components of the software supply chain.
- Embed security into development: Integrate SAST, DAST, dependency scanning, automated validation, and other security controls into CI/CD pipelines to identify and address vulnerabilities earlier in the development lifecycle.
- Evaluate security technologies: Research, assess, adopt, and develop security tools and approaches, including solutions such as Google Assured OSS and comparable technologies.
- Establish secure-development practices: Define practical secure-coding standards and provide engineering teams with guidance, training, mentorship, and resources to improve security adoption.
- Lead cross-functional initiatives: Partner with engineering and other technical teams to drive security programs, resolve critical vulnerabilities, and establish sustainable security processes.
- Strengthen proactive security: Identify emerging application, infrastructure, and supply-chain risks and introduce technologies and processes that improve the overall security posture.
- Balance security with engineering needs: Develop pragmatic solutions that protect systems effectively while maintaining performance, usability, developer productivity, and delivery velocity.
- Education and experience: Bachelor’s degree in Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience, combined with 8+ years of experience in application security and vulnerability management.
- Security expertise: Deep understanding of software vulnerabilities, including CVEs, the OWASP Top 10, application security principles, and software supply-chain risks.
- Security tooling: Hands-on experience with SAST, DAST, dependency scanning, and vulnerability management platforms such as Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP, or comparable technologies.
- Cloud-native security: Strong experience securing cloud environments such as AWS and GCP, including containers, Kubernetes, microservices, and related infrastructure.
- Automation and CI/CD: Ability to integrate security controls and automated validation into modern software delivery pipelines.
- Technical leadership: Demonstrated ability to lead cross-functional security initiatives and influence engineering teams toward stronger security practices.
- Problem-solving mindset: Proactive and pragmatic approach to identifying risks, evaluating solutions, and resolving complex technical security challenges.
- Communication and collaboration: Strong interpersonal skills with the ability to explain security concepts clearly, build trust with engineering partners, and drive adoption without creating unnecessary friction.
- Adaptability: Comfortable working in a fast-moving environment, managing ambiguity, and balancing security requirements with performance, usability, and business priorities.
- Competitive compensation: Standard base salary range of $185,000–$260,000 USD annually, with compensation determined by factors including location, role level, knowledge, skills, and experience.
- Additional compensation: Certain roles may be eligible for variable compensation and equity.
- Healthcare coverage: Medical, vision, and dental benefits.
- Retirement savings: Opportunity to contribute to a 401(k) plan.
- Paid time off: Generous time-off policy to support rest and personal wellbeing.
- Remote work: Fully remote position for candidates based in the United States.
- Home office support: Home office improvement stipend to help create an effective remote workspace.
- Learning and development: Annual education stipend supporting continued professional growth.
- Wellness support: Annual wellness stipend focused on employee wellbeing.
- Workplace culture: Regular company events and a collaborative environment designed to connect distributed teams.
- Employee perks: Healthy lunches provided daily where applicable.