Job Closed
This listing is no longer active.
Helping people save and grow their money.
Application Security Engineer
Location
United States
Posted
158 days ago
Salary
$170K - $210K / year
Seniority
Lead
Job Description
Application Security Engineer
ONE
• Architect and implement secure AWS configurations (IAM roles/policies, encryption keys, VPC segmentation) • Embed security into CI/CD pipelines and repos using policy-as-code tools (pre-commit hooks, SAST/SCA, IDE tool integrations) • Secure container and orchestration environments (EKS, Kubernetes, Docker) per best practices • Conduct threat modeling sessions and risk‑driven design reviews early in development • Perform secure code reviews and static/dynamic analysis; oversee remediation with dev teams • Automate repetitive security tasks—vulnerability triage, code scanning, tool orchestration • Build and extend in-house AppSec automation frameworks or pentest tooling • Partner with security architecture and detection teams (SIEM tuning, logging, telemetry alignment) • Develop and enforce AppSec standards and patterns across product teams; iterate through feedback loops • Support regulatory or compliance assessments (PCI, CCPA, GLBA) as needed
Job Requirements
- 8–12 years’ experience in application security engineering, DevSecOps, or security platform engineering
- Deep familiarity with CVSS, MITRE ATT&CK frameworks, OWASP Top 10 and CWE taxonomy
- Proven experience with AWS core services: IAM, KMS, VPC, EC2, RDS, EKS
- Hands-on expertise in securing IaC and CI/CD pipelines; strong knowledge of policy-as-code tooling
- Container security experience: Docker, Kubernetes, EKS-related threat surfaces
- Solid threat modeling and secure code review skills; SAST/SCA tool proficiency
- Experience scripting automation (e.g. Python, Bash, PowerShell) to streamline AppSec tasks
- Capability to lead in-house AppSec frameworks or tooling development
- Strong communicator, able to translate technical findings to non-technical stakeholders
- Track record of defining and institutionalizing security architecture patterns
Benefits
- Competitive base salary, stock options, and health benefits from Day 1
- 401(k) plan with company match
- Remote-friendly (US), flexible time off (FTO), and opportunities for growth
- A high-growth, mission-driven, inclusive culture where your work has real impact
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
• Lead, mentor, and manage a team of application engineers, Salesforce developers, and front-end developers. • Partner with Product Owners, Scrum Masters, and QA teams to plan and deliver product releases using Agile methodology. • Oversee sprint velocity, resource allocation to ensure on-time, on-budget delivery. • Direct development efforts across Salesforce (Sales, Service, and Commerce Cloud), including APEX, LWC, and API integrations. • Architect, design, and maintain headless and composable experiences leveraging Next.js, React, and Salesforce Commerce Cloud D2C. • Ensure seamless integration between Sitecore, Salesforce, and back-end .NET and Azure-based APIs. • Oversee CI/CD pipelines, infrastructure automation, and deployment processes through Azure DevOps. • Act as a key leader in Agile ceremonies (sprint planning, retrospectives, backlog grooming, etc.). • Manage project scope, risks, and dependencies; escalate issues proactively with solution-oriented recommendations. • Collaborate with business stakeholders, architects, and infrastructure teams to define and deliver enterprise-grade digital experiences.
Manager, Enterprise Application Engineering
OppFiBased in Chicago, Illinois, Opportunity Financial (OppFi) is a financial services company dedicated to providing socially responsible products that increase financial opportunities
• Lead, mentor, and build a world-class team of Enterprise Application Engineers. • Be responsible for hiring, onboarding, performance management, and the career development of your direct reports. • Act as the "player-coach" and most senior technical expert for your team, capable of unblocking your engineers, leading complex architecture reviews, and troubleshooting the most challenging issues. • Foster a culture of accountability, collaboration, and continuous improvement. • Develop and maintain the strategic roadmap for our enterprise application and integration architecture, ensuring it scales with the company's growth. • Act as the primary technical consultant and liaison for business leaders (e.g., Finance, HR, Marketing, Operations), understanding their needs and translating them into scalable, secure technology solutions. • Manage vendor relationships, software licenses, and budgets for your application stack, continuously evaluating new tools to maximize ROI and business value. • Manage the entire Google Workspace ecosystem (Gmail, Drive, Calendar, Groups), defining, configuring, and enforcing policies, rules, and OU structures. • Lead the architecture and administration of our Atlassian stack (Jira, Confluence) guiding your team in building complex workflows and customizing projects for other engineering and business teams. • Design, build, and manage a SaaS Management Platform (SMP) to bring all OppFi SaaS applications under centralized management. • Proactively analyze license utilization across our entire SaaS portfolio to identify opportunities for cost savings, license reclamation, and contract consolidation. • Partner with Information Security and Enterprise Risk Management to conduct technical reviews for all new SaaS applications. • Serve as the top-level architect for our Identity and Access Management (IAM) program. • Design, build, and manage our centralized Identity Provider (IdP) as the single source of truth for all user identities. • Develop, deploy, and enforce Role-Based Access Control (RBAC) policies to ensure the principle of least privilege. • Champion an "automation-first" mindset. • Build and manage automated Joiner, Mover, and Leaver (JML) workflows, ensuring employees are provisioned correctly on their start date and all access is instantly revoked upon termination. • Architect, build, and maintain robust integrations between our core business systems. • Be responsible for the reliability and integrity of data as it moves between integrated systems, including error handling and monitoring.
• 集成和调用主流大语言模型(如 GPT、Claude、Gemini、Ollama 等),实现基于语义理解的高精度结构化信息抽取。 • 设计并实现批量 HTML 或文档语义解析 Pipeline,并将其与底层数据抽取规则引擎深度结合。 • 持续优化大模型提示词工程(Prompt Engineering)模板,通过迭代不断提升输出结果的准确性。 • 负责结构化结果(JSON/CSV/数据库)的管理与存储,为后续数据分析与 API 接口输出提供坚实支撑。 • 构建并行解析架构和完善的错误重试机制,在高通量运行环境下保障系统的高可用性与稳定性。 • 编写并维护可复用的技术脚本与开发文档,支持在多种业务场景下的快速部署与模块复用。 • 独立闭环完成从数据样本设计、模型微调/调优到最终结果输出的全生命周期开发流程。
Senior Application Development Engineer
Cloud Software GroupEnabling customers to evolve, compete & succeed in data, automation, insight, and collaboration.
• Create, develop, and maintain robust, high-quality software solutions using .NET (Framework/Core), C#, TypeScript, JavaScript and MS SQL Server. • Independently address and resolve technical issues of moderate complexity, leveraging strong analytical abilities and accumulated experience. • Proactively identify and implement enhancements to our systems, processes, and products to boost performance and efficiency. • Take responsibility for projects, features and essential processes on the Scribe Online Platform that are assigned to you. • Engage effectively with cross-functional teams and internal stakeholders to ensure alignment on technical standards and operational procedures. • Integrating AI tools, such as CoPilot or equivalent solutions, to assist with day-to-day coding tasks. • Contribute to and influence operational decisions regarding technical practices within and outside the immediate job function. • Directly contribute to achieving operational targets that significantly impact the departmental results.




