World Wide Technology

Senior Application Security Engineer

Remote, US$116,000-$145,000Posted 28 days ago

Job Description

Required Qualifications

  • Bachelor's degree in Computer Science, Software Engineering, Information Security, or a related field — or equivalent hands-on experience.
  • Minimum 8 years of experience in roles related to application security, information security, software engineering, SecDevOps.
  • A demonstrable track record of independently owning AppSec domains and delivering remediation without close supervision.
  • Hands-on experience operating application security scanning tooling (SAST, SCA, secrets, IaC) and integrating it into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or equivalent).
  • Experience securing cloud-native and container/Kubernetes-based applications (AWS, Azure, GCP; Docker, Kubernetes, OpenShift).
  • Ability to read and reason about code in one or more modern stacks (Java, JavaScript/TypeScript, Python, Go, or C#) well enough to perform and review secure code, trace data flows, and identify vulnerabilities in source code.
  • Scripting and automation in Python, Bash, or PowerShell.
  • Design-level understanding of authentication, authorization, and identity — session management, SSO and federation, and OAuth2/OIDC as architectural patterns.
  • Working knowledge of applied cryptography — TLS, certificates and PKI, secrets and key management, hashing versus encryption.
  • Strong command of HTTP and web API internals — request/response semantics, auth flows (OAuth2/OIDC, JWT, session management), and the authZ failures, injection, and business-logic flaws common to REST and GraphQL APIs.
  • Solid understanding of the secure software development lifecycle and where security testing, gates, and controls fit within it.
  • Strong working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and CWE.
  • Working knowledge of NIST SSDF (SP 800-218), NIST 800-53, NIST 800-171, ISO 27001, SOC 2, and CMMC as they apply to secure software development.
  • Hands-on threat modeling experience (

Apply for this role

Keep looking

Similar Remote Jobs That Pay Well