Job Closed
This listing is no longer active.
EnerSys is a global leader in stored energy solutions for industrial applications. We have over thirty manufacturing and assembly plants worldwide servicing over 10,000 customers in more than 100 countries. Worldwide headquarters are located in Reading, PA, USA with regional headquarters in Europe and Asia. We complement our extensive line of Motive Power and Energy Systems with a full range of integrated services and systems. With sales and service locations throughout the world, and over 100 years of battery experience, EnerSys is the power/full solution for stored DC power products.
Application Security Engineer (REMOTE)
Location
United States + 3 moreAll locations: United States | Azerbaijan | Canada | Ukraine
Posted
98 days ago
Salary
$117K - $146K / year
Seniority
Mid Level
No structured requirement data.
Job Description
Application Security Engineer (REMOTE)
EnerSys Delaware Inc.
EnerSys is a global leader in stored energy solutions for industrial applications. We have over thirty manufacturing and assembly plants worldwide servicing over 10,000 customers in more than 100 countries. Worldwide headquarters are located in Reading, PA, USA with regional headquarters in Europe and Asia. We complement our extensive line of Motive Power and Energy Systems with a full range of integrated services and systems. With sales and service locations throughout the world, and over 100 years of battery experience, EnerSys is the power/full solution for stored DC power products. Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers, DevOps teams, and security professionals to embed security into the full software development lifecycle. Collaborate within an expanding Cybersecurity team, and work closely with internal EnerSys teams to ensure new and continued compliance with cybersecurity frameworks and required programs and initiatives. Base Salary Range: $117,200.00 - $146,600.00 per year Compensation may vary based on applicant's work experience, education level, skill set, and/or location. Essential Duties and Responsibilities • Serve as a primary liaison between the Cybersecurity and development teams, ensuring security is integrated into design, development, deployment, and operations. • Conduct application security assessments, code reviews, API testing, threat modeling, and penetration testing to identify vulnerabilities. • Define, maintain, and enforce secure coding standards, patterns, and best practices. • Integrate and manage security tooling within CI/CD pipelines, including SAST, DAST, SCA, IaC scanning, and container security solutions. • Support secure architecture reviews for cloud‑native applications, microservices, and containerized workloads. • Support threat modeling, risk assessments, and security architecture reviews for applications. • Ensure that all security practices meet regulatory and compliance requirements. • Develop and deliver cybersecurity training programs for development teams to promote awareness and adherence to best practices. • Ensure application security practices align with regulatory and compliance frameworks (e.g., NIST CSF, ISO 27001, IEC 62443). • Keep up to date on emerging threats, incorporating threat intelligence into security practices and providing proactive defenses. • Monitor and respond to application security threats, incidents and vulnerabilities. • Stay up to date on regulatory developments and industry trends. • Manage and maintain third-party vendor and consultant relationships . • Perform other duties as assigned. SUPERVISORY RESPONSIBILITIES: N/A Qualifications To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Must have an active passport and be willing to travel internationally. Education and/or Experience • A degree in a technical field (Computer Science, Information Systems, or Cybersecurity) is preferred but not required. • 5+ years of experience in Information Security, with at least 3 years focused on application security, secure development, or DevSecOps. • Strong understanding of OWASP Top 10, OWASP ASVS, SANS Top 25, and secure SDLC methodologies. • Hands-on experience with application security testing tools (e.g., Burp Suite, Fortify, Checkmarx, Veracode, Fortify, ZAP.). • Experience with threat modeling, penetration testing, and secure software development practices. • Practical experience with cloud platforms (AWS or Azure) and cloud-native security controls. • Familiarity with Kubernetes security, container hardening, and runtime protection. • Experience conducting threat modeling, penetration testing, and secure architecture reviews. • Strong communication skills with the ability to influence and collaborate across technical and non-technical teams. • Relevant certifications (e.g., CISSP, CSSLP, OSCP, GWAPT, CEH, GIAC Cloud Security) other relevant certifications is preferred. Reasoning Ability • Problem management / resolution skills; project management skills; generally accepted security principles. • Ability to analyze data, resources, and schedules to make decisions that affect a project on a regular basis. TRAVEL REQUIRED: Up to 15% General Job Requirements - This position will work in an office setting, expect minimal physical demands. EnerSys provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. Know Your Rights Know Your Rights (Spanish) We use artificial intelligence to screen, assess and select applicants for open positions, including for the purposes of reviewing and ranking application materials and scoring answers to application questions. Accordingly, decisions about your application and eligibility for employment with EnerSys may be made based exclusively on the automated processing of the personal information that you submit in your application materials.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
As a Network Security Engineer here at Honeywell, you will oversee the daily operations of our perimeter security technologies across global data centers and cloud environments, including firewall and proxy services. You will serve as a key technical resource—proactively identifying potential risks, proposing solutions, and ensuring seamless service delivery across interconnected infrastructure. You will collaborate closely with internal customers by responding to service requests and supporting secure operations across the enterprise. You will report directly to our Cybersecurity Manager and you’ll work remotely. Honeywell helps organizations solve the world's most complex challenges in automation, the future of aviation and energy transition. As a trusted partner, we provide actionable solutions and innovation through our Aerospace Technologies, Building Automation, Energy and Sustainability Solutions, and Industrial Automation business segments – powered by our Honeywell Forge software – that help make the world smarter, safer and more sustainable.
Director of Cyber Security
Ivy Rehab NetworkWe’re looking for physical, occupational, speech, and ABA therapists who want to help others live life to the fullest.
• Directly design and work with the team to deploy security tools across our network, including IAM, endpoint protection, and encryption protocols. • Act and execute during security events. • Oversee the end-to-end security operations, including threat detection, vulnerability management, and leading the response to any potential security breaches. • Lead technical due diligence for all acquired clinics, identifying security risks and standardizing their systems to meet the Ivy Rehab security ecosystem. • Partner directly with teams to integrate security into their workflows without creating bottlenecks. • Manage a portfolio of security initiatives (e.g., IAM rollouts, EMR security hardening, network encryption), ensuring they are delivered on time and within budget. • Manage relationships with strategic security vendors (SOC, MSSP, Cyber Insurance) to ensure all infrastructure and tools are delivering maximum protection. • Lead and mentor a small, agile team of IT professionals by example.
• Protect people, enhance lives, and preserve the planet • Serve consumer and business customers across multiple industries • Maintain a legacy of excellence
Senior Application Security Engineer
Beyond FinanceBeyond Finance is a technology and financial services company that is on a mission to help its clients “move beyond debt.” As an employer, the company is known for its fast-pac
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As our Senior Application Security Engineer, you will be the primary owner and driver of our application security program. You’ll work hands‑on with engineering teams to embed secure development practices, improve tooling and automation, and guide security considerations for new features, architectures, and services. This is a high‑impact role where you’ll shape the future of AppSec at a company that values security as a core part of product quality. What You’ll Do - Application Security Ownership - Lead and evolve the company’s application security strategy, roadmap, and day‑to‑day operations. - Serve as the primary AppSec partner for numerous dev teams working on Ruby on Rails web apps, React Native mobile apps, and various other projects including Python and Go. - Provide security guidance during design, development, and code review for new features and projects. - Drive adoption of secure coding practices and threat‑modeling across engineering teams. - Tooling & Automation - Manage and optimize existing AppSec tooling, including: - GitHub Advanced Security (SAST, SCA, Secret Scanning) - Invicti (DAST) - Hadrian (ASM) - AppDome (mobile application security) - Cloudflare WAF - Improve automation and integration of security tools into CI/CD pipelines. - Identify and implement additional tools or processes to strengthen the security posture. - Secure SDLC & Developer Enablement - Build and maintain secure development standards, playbooks, and training materials. - Partner with engineering teams during sprint planning and feature design to proactively address risks. - Conduct security reviews, code assessments, and vulnerability triage with development teams. - Cloud & DevOps Collaboration - Work with DevOps to ensure secure AWS infrastructure deployments and configurations. - Contribute to hardening efforts across ECS, IAM, networking, and supporting cloud services. - Assist in designing and maintaining secure CI/CD workflows. - Incident & Vulnerability Management - Lead or support investigation and remediation of application‑level vulnerabilities. - Monitor, prioritize, and track findings from SAST/DAST/ASM tools. - Collaborate with engineering to ensure timely and effective remediation. Qualifications - 3–7+ years of experience in Application Security, Product Security, or related engineering roles. - Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC. - Experience working with cloud‑native applications, ideally in AWS. - Understanding of SSL certificates & cryptographic key management. - Hands‑on experience with SAST, DAST, WAFs, and/or mobile application security tools. - Ability to partner effectively with developers and influence secure design decisions. - Familiarity with GitHub‑based workflows and CI/CD pipelines. Requirements - Development experience with Ruby on Rails or similar dynamic languages. - Knowledge of AWS ECS/EKS, container security, secrets management and infrastructure‑as‑code (CloudFormation, Terraform). - Experience building or maturing an AppSec program from early stages. - SOAR Automation & Scripting experience. - Experience working in a PCI compliant environment working with annual reporting needs. Benefits - High ownership role where you define the AppSec roadmap. - Modern engineering environment with strong leadership support for security. - Opportunity to influence architecture, tooling, and culture across the entire development organization. - Competitive compensation, benefits, and growth opportunities. - Considerable employer contributions for health, dental, and vision programs. - Generous PTO, paid holidays, and paid parental leave. - 401(k) matching program. - Merit advancement opportunities. - Career development & training. - Team spirit and culture that cultivates an environment of community, connection, and belonging.



