Job Closed
This listing is no longer active.
Elevating Autism & IDD Care through Technology
Senior Application Security Engineer
Location
United States
Posted
96 days ago
Salary
$150K - $170K / year
Seniority
Senior
Job Description
Senior Application Security Engineer
CentralReach
• Act as the security representative for all SSDLC activities, partnering with development teams to embed security early and continuously. • Conduct architecture reviews, threat modeling, and security design consultations for new applications, services, and features. • Review pull requests (PRs) for security concerns and support secure code review processes, particularly in .NET-based applications. • Integrate and maintain automated security checks within CI/CD pipelines. • Apply best practices aligned with OWASP, CIS, and other industry benchmarks, ensuring robust protection for traditional and AI-driven systems. • Enhance application and infrastructure security in containerized environments, including Kubernetes and AWS EKS. • Collaborate with developers and architects to identify, assess, and remediate vulnerabilities efficiently.
Job Requirements
- Strong understanding of application security principles, secure coding, and threat modeling.
- Experience integrating security into CI/CD workflows (Jenkins preferred).
- Familiarity with Kubernetes/EKS and cloud-native architectures.
- Working knowledge of C#, ASP.NET, and React is strongly preferred; an understanding of Python will also serve you well in this role.
- Extensive experience working alongside and partnering with software engineers to build systems that are secure by design.
- Excellent communication and collaboration skills with a proactive, partnership-oriented mindset.
Benefits
- Competitive compensation
- Comprehensive health benefits
- Generous PTO
- 401(k) matching
- Paid parental leave
- Hybrid work schedules
- Career development support
- Wellness programs
- Opportunities to give back through CR Cares™
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
• Support on-site and remote deployment of our solutions across sensors, edge devices, and software platforms, including configuration, calibration, testing, and validation. • Act as the technical point of contact during pilots, PoCs, and live implementations, owning technical execution end-to-end. • Partner with the Project team to plan and run deployments: align scope, milestones, site readiness, risks, and action items, and provide clear status updates. • Work closely with customers to understand technical requirements and site constraints, and translate them into deployment and integration steps. • Troubleshoot hardware, software, and network issues in the field, lead root cause analysis, and drive resolution with Engineering and Product. • Collaborate with Engineering, Product, and Project teams to share field learnings, collect requirements, and highlight gaps for improvement. • Create and maintain technical documentation, installation guides, and field reports to support repeatable deployments. • Train customer teams and internal stakeholders when required. • Provide input to pre-sales and post-sales when needed (demos, technical scoping, and RFP/RFI technical support).
• Keep our business and revenue safe by building security into the way we develop software • Design secure application architectures • Improve secure coding practices • Detect vulnerabilities early in the development lifecycle • Continuously improve application security as part of everyday engineering work • Build and maintain secure coding standards • Conduct threat modeling during architecture and design stages • Implement and improve application security testing, including: SAST, DAST, Dependency and secrets scanning, CI/CD security checks • Perform regular application security assessments and maturity evaluations (OWASP ASVS, OWASP SAMM) • Manage the full vulnerability lifecycle: triage, prioritization, remediation support, and validation • Support external penetration testing and Bug Bounty programs • Identify and mitigate security risks in cloud environments and CI/CD pipelines.
• Accelerate pipeline growth by cultivating high-trust relationships with architects, engineers, contractors, OEMs, dealers, and channel partners. • Surface and route qualified deals by recognizing early buying signals. • Shape specs and purchasing decisions by aligning solutions to project needs. • Be the go-to technical/business resource for Key Influencers. • Drive account strategy and execution by building Key Influencer account plans. • Expand market presence and credibility through segment and industry insight. • Inform strategic choices with market analysis and alternative technology assessments. • Uplift commercial capability by mentoring sales personnel and sharing best practices.
Application Security Engineer
Lucidya | لوسيدياThe leading Customer Experience Management platform geared towards Arab.
• Develop and implement automated security testing and vulnerability detection workflows integrated into the Software Development Lifecycle (SDLC). • Conduct security reviews of web applications, mobile applications, APIs, and cloud environments (public and private). • Perform penetration testing on web, mobile, API, and desktop applications, as well as supporting infrastructure. • Evaluate application defenses, identify architectural and design-level security gaps, and recommend mitigation strategies. • Think like an attacker to proactively identify vulnerabilities and complex security risks before they reach production. • Collaborate closely with engineering teams to support secure coding practices and security-aware development. • Conduct code reviews with a security focus, especially for critical services and deployments. • Research emerging threats and contribute to the development or adoption of new security tools and techniques. • Review application code and architecture from a security perspective. • Support and guide teams on secure development lifecycle (SDLC) practices. • Work closely with developers during feature development and releases to ensure security controls are in place. • Participate in threat modeling, vulnerability triage, and remediation tracking. • Contribute to defining and evolving Lucidya’s application security strategy. • Gain a deep understanding of Lucidya’s system architecture, codebase, and security landscape in the first 90 days.




