Apollo.io logo
Apollo.io

Helping sales teams find their ideal buyers and convert them into customers.

Senior Application Security Engineer

Application EngineerApplication EngineerFull TimeRemoteSeniorTeam 51-200Since 2015H1B No SponsorCompany SiteLinkedIn

Location

Canada

Posted

3 days ago

Salary

$190K - $273K / year

Seniority

Senior

Job Description

Senior Application Security Engineer

Apollo.io

• Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment. • Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch. • Provide practical security architecture guidance to Engineering, Product, and IT teams. • Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems. • Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs. • Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities. • Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom. • Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities. • Apply clear, risk-based severity decisions using exploitability, data sensitivity, customer impact, and blast radius. • Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise. • Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly. • Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment. • Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths. • Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely. • Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content. • Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly. • Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity. • Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making.

Job Requirements

  • 5+ years of software engineering or application security experience, with meaningful hands-on AppSec depth in modern SaaS environments.
  • Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, and Python or similar scripting ability is a plus.
  • Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments.
  • Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling.
  • Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations that hold up against bypass attempts and variant analysis.
  • Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification.
  • Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale.
  • Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations.
  • Strong written and verbal communication, stakeholder management, and influencing skills across technical and non-technical partners.

Benefits

  • equity
  • company bonus or sales commissions/bonuses
  • 401(k) plan
  • at least 10 paid holidays per year
  • flex PTO
  • parental leave
  • employee assistance program and wellbeing benefits
  • global travel coverage
  • life/AD&D/STD/LTD insurance
  • FSA/HSA and medical, dental, and vision benefits

Related Categories

Related Job Pages

More Application Engineer Jobs

Intel logo

MDM Software Application Development Engineer

Intel

Intel, founded in 1968, is a technology firm located in Silicon Valley’s Santa Clara, California. Intel's staff works in 46 countries across Asia, North and S

MDM Software Application Development Engineer Virtual US Full time Job Description: Join Intel IT as an MDM Software Application Development Engineer. The software application development engineer defines software application solutions across client, cloud, or enterprise thru industry best practices to fulfill stakeholder and business needs and organizational goals. In this role responsibilities include, although not limited to: - Recommend design choices focused on manageability, scalability, usability, resiliency, availability, security, and/or safety for the software structure, protocols, and algorithms. - Identifies business requirements, functional and system specifications that meet business user requirements, maps them to systems capabilities and recommends technical solutions. - Configures system settings and options, plans and executes unit, integration, and acceptance testing, and creates systems specifications. - Collaborates with management, product owners, and project managers to evaluate feasibility of requirements and determine priorities for development. - Performs pathfinding, surveys technologies, participates in standards committees, and presents at external and internal events. - Interacts with multiple technologists in the company to influence architectures and optimize/customize software offerings. - Examines current business procedures, system practices and IT modification design and recommends new improved ones. - Designs and develop MDM customizations and systems by analyzing business requirements, configure and automate workflows, studying system capabilities and writing specifications. - Performs troubleshooting, solves complex bug issues in production systems or applications, and collaborates with subject matter experts on issues. - Anticipates complex issues and discusses within and outside of project team to maintain open communication. - Serves as a technical lead on a subsystem or small feature(s), manages projects of small to medium size and complexity, performs tasks, and applies expertise in subject area to meet deadlines. In addition to the qualifications listed below, the ideal candidate will also have: - Excellent verbal and written communication skills. - A strong team player with initiative, self-motivation, and flexibility in dealing with ambiguous situations. - Must be flexible to work with remote teams and handling multiple tasks in a dynamic IT environment. - Ability to work in high-pressure, milestone-driven environments, and ability to extend hours during critical cutover cycles. - Proven ability to define complex business solutions and system architecture. Qualifications: You must possess the below minimum qualifications to be initially considered for this position. Preferred qualifications are in addition to the minimum requirements and are considered a plus factor in identifying top candidates. Minimum Qualifications: The candidate must have a bachelor's degree in Cybersecurity, Information Security, electrical/computer engineering or computer science and 6+ years of experience OR a master's degree in Cybersecurity, Information Security, electrical/computer engineering or computer science and 4+ years of experience OR a PhD in in Cybersecurity, Information Security, electrical/computer engineering or computer science and 2+ years of experience. In addition, the candidate must have: - 6+ years of hands-on experience related to designing, configuring, and developing SAP MDG and S4 HANA solutions. - Practical level experience with ABAP, SAP Fiori, S/4 HANA, ALE and IDOC processing, and SQL Queries. - Working hands-on experience in SAP's Material, Bill of Material (BOM), Routing, Work Center, and Production Version master data. - Experience in at least one large scale SAP MDM and S4 HANA migration/conversion/transformation program. Preferred Qualifications: - Prior involvement in managing or executing data cleansing, data mapping, and data governance areas preferably in SAP environments, along with integration across complex ERP landscape - Experience in developing, normalizing, and maintaining master data standards and definitions - Experience in developing and supporting cross-system integration (SAP + non-SAP) - Data migration experience from legacy to new SAP ERP systems. - Semiconductor industry experience. Job Type: Experienced Hire Shift: Shift 1 (United States of America) Primary Location: Virtual US Additional Locations: Business group: IT is the trusted technology partner for Intel's business, relentlessly focused on the experience of our people, our end users, and our customers. We design and support Intel's IT infrastructure, driving e-Commerce and web services with a focus on robust security and identity protection. Posting Statement: All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance. Position of Trust N/A Benefits We offer a total compensation package that ranks among the best in the industry. It consists of competitive pay, stock bonuses, and benefit programs which include health, retirement, and vacation. Find out more about the benefits of working at Intel. Annual Salary Range for jobs which could be performed in the US: $160,980.00-227,270.00 USD The range displayed on this job posting reflects the minimum and maximum target compensation for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific compensation range for your preferred location during the hiring process. Work Model for this Role This role is available as a fully home-based and generally would require you to attend Intel sites only occasionally based on business need. However, you must live and work from the country specified in the job posting, in which Intel has a legal presence. Due to legal regulations, remote work from any other country is unfortunately not permitted. * Job posting details (such as work model, location or time type) are subject to change. ADDITIONAL INFORMATION: Intel is committed to Responsible Business Alliance (RBA) compliance and ethical hiring practices. We do not charge any fees during our hiring process. Candidates should never be required to pay recruitment fees, medical examination fees, or any other charges as a condition of employment. If you are asked to pay any fees during our hiring process, please report this immediately to your recruiter.

United States
$161.0K - $227.3K / year
Virtru logo

Application Security Engineer

Virtru

Respect the people. Respect the data. Virtru equips you to protect your data anywhere and everywhere it's shared.

Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

• Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC. • Independently identify security improvements and implement them. • Implement, manage, and automate vulnerability management processes. • Prioritize and remediate vulnerabilities discovered through internal scans, penetration tests, and bug bounties. • Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development. • Collaborate in providing actionable recommendations to find workable solutions. • Establish a threat hunting capability and automate where appropriate. • Enhance logging capabilities related to security events. • Integrate and manage dynamic and static code analysis tools. • Ensure operation of security tools within the development pipeline.

District Of Columbia + 1 moreAll locations: District Of Columbia | Washington
$180K - $200K / year
Qnity logo

Field Application Engineer – Southeast Region

Qnity

The quantum electrochemical one-stop solution for drug discovery.

Full TimeRemoteTeam 1-10Since 2023H1B No Sponsor

• Responsible for working with OEM engineers, Manufacturer's Representatives, Distribution Partners and Territory Sales Managers to implement Laird solutions • Regularly attend customer meetings and provide technical design support • Utilize Laird and Qnity products and materials to help solve customer challenges • Present design solutions to customer, utilizing modeling and simulation during presentation • Drive customer interactions, prototype, and initial production build to meet stakeholder timelines • Originate and release final production documentation • Manage and direct a project through a product development design team

North Carolina + 2 moreAll locations: North Carolina | Missouri | Virginia

Role Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production. Key Responsibilities - Conduct threat modeling and security architecture reviews for new and existing applications and services. - Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components. - Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines. - Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking. - Build paved-road libraries and frameworks that make secure patterns the default for engineering teams. - Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses. - Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms. - Design and enforce secure authentication, authorization, session management, and cryptographic patterns. - Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments. - Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff. - Respond to security incidents involving application vulnerabilities or active exploitation. - Track and apply emerging threats and CVEs that may affect the application portfolio. - Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures. - Stay current with application security research and emerging defensive tooling. Qualifications - Bachelor’s degree in Computer Science, Cybersecurity, or a related field. - Five or more years of application security or security engineering experience. - Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns. - Hands-on experience performing code review across at least two major languages. - Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling. - Strong understanding of authentication, authorization, and cryptographic primitives. - Experience with cloud security and modern infrastructure controls. - Strong communication skills with technical and non-technical audiences. - Proficiency in at least one programming language for tooling and automation. - Experience working closely with engineering teams in an Agile environment. Preferred Qualifications - Industry certifications such as OSCP, OSCE, GWAPT, or CISSP. - Experience with offensive security tooling and red-team operations. - Bug bounty experience, public CVEs, or open-source security contributions. - Familiarity with AI/LLM application security considerations. - Exposure to regulated industries with strict compliance requirements. How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to [email protected] or contact us at (908) 676-4399. Learn more about Bright Vision Technologies at www.bvteck.com .

United States
100K - 150K / year