Respect the people. Respect the data. Virtru equips you to protect your data anywhere and everywhere it's shared.
Application Security Engineer
Location
District Of Columbia + 1 moreAll locations: District Of Columbia | Washington
Posted
1 day ago
Salary
$180K - $200K / year
Seniority
Senior
Job Description
Application Security Engineer
Virtru
• Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC. • Independently identify security improvements and implement them. • Implement, manage, and automate vulnerability management processes. • Prioritize and remediate vulnerabilities discovered through internal scans, penetration tests, and bug bounties. • Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development. • Collaborate in providing actionable recommendations to find workable solutions. • Establish a threat hunting capability and automate where appropriate. • Enhance logging capabilities related to security events. • Integrate and manage dynamic and static code analysis tools. • Ensure operation of security tools within the development pipeline.
Job Requirements
- 4+ years experience in secure development or application security.
- Deep knowledge of security concepts such as authentication, web architecture, etc.
- Experience with Nodejs, Go, etc.
- Experience running bug-bounty, penetration testing, vulnerability scanning programs.
- Experience setting up and maintaining SAST, DAST, IAST and SCA tooling
- Experience using assessment tools such as Burp, ZAP, Qualys, Nessus, etc.
- Experience building and maintaining WAF solutions.
- Familiarity with industry security practices, standards, and regulations such as FedRAMP, SOC2, HIPAA, etc. a plus.
- Familiarity with GCP/AWS and Kubernetes infrastructure security a plus.
- Self-motivated and goal driven, able to find what needs to be done and do it.
Benefits
- A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
- A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.
- Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social!
- Access to an Employee Assistance Program
- Access to Headspace, a mental health app tailored to your specific needs.
- A flat 3% contribution to your retirement account
- A high degree of flexibility — Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.
- In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging. Our DB&I Council is dedicated to fostering an inclusive workplace and making the psychological safety of each and every one of our teammates a top priority.
- Competitive compensation
- Generous parental, medical, and bereavement policies
- 401K contribution and stock options
- Full medical, dental, and vision benefits
- New Hire Swag and IT Welcome boxes
- Structured semi-annual 360° performance reviews
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
Field Application Engineer – Southeast Region
QnityThe quantum electrochemical one-stop solution for drug discovery.
• Responsible for working with OEM engineers, Manufacturer's Representatives, Distribution Partners and Territory Sales Managers to implement Laird solutions • Regularly attend customer meetings and provide technical design support • Utilize Laird and Qnity products and materials to help solve customer challenges • Present design solutions to customer, utilizing modeling and simulation during presentation • Drive customer interactions, prototype, and initial production build to meet stakeholder timelines • Originate and release final production documentation • Manage and direct a project through a product development design team
Role Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production. Key Responsibilities - Conduct threat modeling and security architecture reviews for new and existing applications and services. - Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components. - Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines. - Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking. - Build paved-road libraries and frameworks that make secure patterns the default for engineering teams. - Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses. - Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms. - Design and enforce secure authentication, authorization, session management, and cryptographic patterns. - Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments. - Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff. - Respond to security incidents involving application vulnerabilities or active exploitation. - Track and apply emerging threats and CVEs that may affect the application portfolio. - Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures. - Stay current with application security research and emerging defensive tooling. Qualifications - Bachelor’s degree in Computer Science, Cybersecurity, or a related field. - Five or more years of application security or security engineering experience. - Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns. - Hands-on experience performing code review across at least two major languages. - Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling. - Strong understanding of authentication, authorization, and cryptographic primitives. - Experience with cloud security and modern infrastructure controls. - Strong communication skills with technical and non-technical audiences. - Proficiency in at least one programming language for tooling and automation. - Experience working closely with engineering teams in an Agile environment. Preferred Qualifications - Industry certifications such as OSCP, OSCE, GWAPT, or CISSP. - Experience with offensive security tooling and red-team operations. - Bug bounty experience, public CVEs, or open-source security contributions. - Familiarity with AI/LLM application security considerations. - Exposure to regulated industries with strict compliance requirements. How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to [email protected] or contact us at (908) 676-4399. Learn more about Bright Vision Technologies at www.bvteck.com .
• Garantizar la alta disponibilidad, estabilidad y desempeño de aplicaciones y sistemas críticos. • Analizar incidentes y problemas identificando causas raíz y proponiendo soluciones definitivas o paliativas. • Supervisar infraestructura, microservicios, bases de datos y experiencia de usuario final mediante Dynatrace. • Configurar alertas inteligentes basadas en comportamiento y capacidades de Inteligencia Artificial para la detección temprana de incidentes. • Crear y mantener dashboards de monitoreo para visualizar flujos de datos, volumen de transacciones y estados de peticiones. • Monitorear patrones inusuales en registros de aplicaciones y servidores mediante Kibana y Elastic Search. • Vigilar la salud de aplicaciones móviles utilizando Firebase Crashlytics, identificando regresiones y errores en producción. • Actuar como soporte de tercer nivel, colaborando con equipos de Infraestructura, Redes, Operaciones y Desarrollo. • Proporcionar evidencia técnica mediante logs, métricas y trazas para acelerar la resolución de incidentes y despliegue de correcciones. • Colaborar con equipos Frontend, Backend, CRM y Product Teams para asegurar la estabilidad de los ecosistemas tecnológicos.
• Assist channel partners, consulting engineers, and contractors in proper selection and pricing of HVAC equipment • Provide commercial, competitive, and technical application support via phone or e-mail • Work with a small team of technical employees to resolve the field selling organization’s requests • Provide application training and support on a broad range of packaged and split commercial products • Participate in testing of applicable product selection and pricing software • Coordinate with engineering to develop Special Requests for unique requirements • Collaborate with marketing to develop selection and pricing software requirements



