Sr. Application Security Engineer in United States Embassy at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States.
The Sr. Application Security Engineer will serve as the technical authority responsible for embedding security throughout the software development lifecycle.
This role bridges engineering and information security, helping development teams build secure, resilient, and compliant applications.
You will own application security initiatives across internet-facing financial software, APIs, and cloud-based environments.
The position focuses on proactive risk reduction through vulnerability management, secure design practices, threat modeling, and developer enablement.
You will work closely with engineering leadership and cross-functional teams to establish scalable security practices.
This is an opportunity to shape a mature security program, influence product decisions, and strengthen trust with enterprise customers and regulators.
The Sr. Application Security Engineer will own the application security strategy and collaborate closely with engineering teams to integrate security best practices into product development processes. The role requires hands-on technical expertise, strong communication skills, and the ability to drive security improvements across the organization.
- Own and manage the application vulnerability remediation program, prioritizing findings, defining remediation timelines, guiding developers, and ensuring critical issues are addressed effectively.
- Partner with engineering teams to validate fixes, identify root causes, and implement long-term security improvements rather than short-term patches.
- Define and maintain secure software development lifecycle (SDLC) processes, including security reviews, release checkpoints, and security requirements within development workflows.
- Configure, optimize, and manage security tooling such as SAST, DAST, and SCA solutions to provide actionable insights for developers.
- Conduct threat modeling for new features and architectural changes, assessing authentication, authorization, data flows, and cryptographic risks.
- Establish and maintain API security standards covering authentication, authorization, abuse prevention, and secure integration practices.
- Perform and coordinate secure code reviews, application penetration testing activities, and remediation validation.
- Build developer security enablement programs, including Security Champions initiatives, training sessions, secure coding guidelines, and reusable security resources.
- Support customer and regulatory security engagements by providing technical expertise and evidence of security practices.
- Continuously improve application security processes, identify automation opportunities, and contribute to a proactive security culture.
The ideal candidate brings strong application security expertise combined with software engineering knowledge and the ability to influence development teams. You should have experience securing modern applications, improving security processes, and communicating complex technical concepts clearly.
- 5–8 years of experience in application security, product security, or security-focused software engineering roles.
- Hands-on experience with application penetration testing, including business logic testing and API security assessments.
- Strong knowledge of SAST, DAST, and SCA tools, including configuration, tuning, and operational implementation.
- Experience conducting secure code reviews across multiple web application programming languages.
- Expertise in threat modeling methodologies such as STRIDE, PASTA, or equivalent approaches.
- Strong understanding of OWASP Top 10, API security risks, authentication mechanisms, and secure development practices.
- Ability to collaborate effectively with software engineers and influence teams toward secure engineering practices.
- Experience with cloud-native application security, container security, or modern software architectures is preferred.
- Familiarity with regulated industries such as financial services, fintech, SaaS, or environments requiring compliance frameworks is advantageous.
- Knowledge of financial-sector security risks, including fraud prevention, account takeover threats, and API abuse scenarios.
- Experience with PCI-DSS security requirements is a plus.
- Relevant certifications such as OSCP, GWEB, or CSSLP are desirable.
- Strong analytical, communication, problem-solving, and stakeholder management skills.
- Competitive salary range of $130,000 – $190,000 per year, depending on experience, skills, and location.
- Opportunity to own and shape an application security function with significant technical visibility.
- Work on complex security challenges involving internet-facing financial software, APIs, and regulated environments.
- Direct collaboration with security, IT, and engineering leadership teams.
- Remote-first flexibility with tools and practices designed to support distributed work.
- Healthcare plan options, including universal, supplemental, and private healthcare offerings depending on location.
- Retirement and pension plan contributions, plus stock plan participation opportunities.
- Life event and disability coverage for financial protection.
- Generous paid time off, company holidays, and volunteer time off.
- Home office setup allowance.
- Learning and development opportunities, including e-learning access, tuition reimbursement, and hackathons.
- Additional benefits such as pet insurance, identity theft protection, and legal assistance.