Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Engineer

RegScale

Senior Application Security Engineer

Remote

RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution to a disciplined, enterprise-ready engineering organization, and we are building the team that will take us there. As a platform handling sensitive security and regulatory data for enterprise and government customers, security is not a compliance checkbox at RegScale. It is a core engineering discipline woven into how we build software.

The Role

This is a high autonomy role for a seasoned security engineer who thrives at the center of a complex engineering organization. You are the primary application security practitioner at RegScale. You identify where the risk is, build the strategy to address it, and drive initiatives from concept to measurable improvement without a team beneath you and without direct authority over the engineers you depend on to execute.

Your reach spans all of engineering including Core Engineering, Platform and AI, Compliance as Code, Quality Engineering, SRE, Infrastructure, and the external security team. You succeed by making engineers more security conscious and embedding security into how software is designed, built, and deployed rather than finding vulnerabilities after the fact.

RegScale serves enterprises and government agencies under frameworks like FedRAMP, NIST, and CMMC. This role reports into SRE and Infrastructure and requires deep technical security expertise combined with the organizational influence and end to end ownership mindset needed to make security a shared engineering value.

Key Responsibilities

  • Own the application security program end to end, identifying risks, setting priorities, building strategy, aligning stakeholders, driving implementation across engineering teams, and measuring outcomes.
  • Conduct threat modeling and security design reviews early in the development process, embedding security thinking into architecture and feature design before code is written.
  • Partner with developers across all engineering teams to shift security left, coaching on secure coding practices, reviewing code for vulnerabilities, and building security awareness as a shared engineering capability rather than a specialized handoff.
  • Integrate security tooling and automated security checks into CI/CD pipelines including static analysis, dependency scanning, and secrets detection, ensuring actionable security signals.
  • Own vulnerability management across the platform, triaging findings from internal testing, external assessments, and tooling, prioritizing remediation based on risk, and driving resolution to completion.
  • Lead and coordinate penetration testing and security assessments, working with internal and external resources to scope, execute, and translate findings into engineering action.
  • Define and maintain secure development standards and patterns that engineering teams can adopt, covering areas such as authentication, authorization, API security, and data-handling.
  • Bridge engineering and the external security team, translating security requirements into engineering priorities and engineering constraints into security strategy, ensuring both sides operate with shared context and mutual accountability.
  • Support compliance and regulatory requirements including FedRAMP, NIST, and enterprise customer security obligations, working with the Compliance as Code team to ensure security controls are implemented and evidenced effectively.
  • Assess and address security risks introduced by AI features and integrations, including prompt injection, data exposure through AI interfaces, and third-party model risks, working closely with the Platform and AI team to ensure AI capabilities are built and deployed securely.
  • Build visibility into the security posture of the platform through metrics, dashboards, and reporting that inform engineering leadership and support customer and auditor conversations.

Required Qualifications

  • 10 or more years of application security experience with a demonstrated track record of owning security programs and driving initiatives end to end across complex engineering organizations.
  • Deep expertise across the application security domain including threat modeling, secure design review, vulnerability assessment, penetration testing, and secure development practices.
  • Proven ability to operate as a solo practitioner or small team lead, setting priorities independently, managing competing demands, and delivering outcomes without close supervision.
  • Strong experience influencing engineering teams without direct authority, building credibility through technical depth, clear communication, and practical solutions that fit the realities of product delivery.
  • Experience integrating security into CI/CD pipelines and modern software delivery practices, with a shift left mindset that prioritizes prevention over detection.
  • Solid understanding of cloud security principles and how application security intersects with infrastructure security in a cloud native environment.
  • Strong written and verbal communication skills, able to articulate security risk, strategy, and tradeoffs clearly to engineering teams, leadership, and stakeholders including customers and auditors.

Preferred Qualifications

  • Experience in regulated industries with compliance frameworks such as FedRAMP, NIST 800-53, CMMC, or SOC 2. Direct FedRAMP authorization or continuous monitoring experience is a strong plus.
  • Background in enterprise SaaS companies where security scaled across multi-tenant architectures and high stakes regulatory environments.
  • Experience supporting penetration tests, bug bounty programs, or third-party security assessments and translating findings into prioritized engineering roadmaps.
  • Familiarity with GRC platforms or compliance automation tools, bringing domain context that makes security decisions more credible with customers.
  • Familiarity with AI security considerations including securing LLM integrations, prompt injection risks, AI governance, and emerging regulatory expectations around AI in compliance contexts.
  • Relevant certifications such as OSCP, CISSP, or CSSLP, valued as evidence of structured knowledge, not as a substitute for demonstrated engineering capability.

RegScale is only able to hire US Citizens

Vacancy posted 2 hours ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer in United States vacancy
  •  ...A leading web platform company is seeking a Senior Application Security Engineer to enhance their secure development practices. This remote role involves collaborating with engineering teams, identifying security vulnerabilities, and leading security initiatives. Candidates... 
    Senior
    Remote work

    Webflow

    New York, NY
    1 day ago
  • $130k - $218k

     ...A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants... 
    Senior
    Remote work

    ConsenSys

    New York, NY
    1 day ago
  •  ...A tech startup is looking for a Sr. Application Security Engineer to secure their Kubernetes multi-tenancy solutions. This role involves core product security, threat modeling, and vulnerability management while collaborating on feature development. Ideal candidates will... 
    Senior
    Remote work
    Flexible hours

    vCluster

    Salt Lake City, UT
    15 hours ago
  •  ...A dynamic tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role requires a strong background in application security and Kubernetes, along with proficiency in Go. You will lead security reviews, threat... 
    Senior
    Remote work
    Flexible hours

    vCluster

    Boston, MA
    3 days ago
  •  ...A venture-backed tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role focuses on ensuring secure multi-tenancy within Kubernetes, leading threat modeling initiatives, and managing vulnerability lifecycles... 
    Senior
    Remote work
    Flexible hours

    vCluster

    Saint Louis, MO
    14 hours ago
  •  ...Senior Application Security Engineer Location: Middletown, NJ (F2F Required, Onsite from Day Telecom Experience) Long Term Overview: We are looking for a Senior Application Security Engineer to join our growing team and play a hands-on role in strengthening security... 
    Senior

    Yantran LLC

    Middletown, NJ
    4 days ago
  • $215k - $230k

     ...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should... 
    Senior

    Crypto Pro Network

    New York, NY
    1 day ago
  •  ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software... 
    Senior
    Full time

    AGS INC

    San Francisco, CA
    2 days ago
  • $67.67 - $112.78 per hour

     ...Job Description Title : Senior Application Security Engineer Location : Remote Job Type : Contract (12 Months) Compensation : $67.67 - $112.78/hr Industry: Retail --- About the Role We are partnering with a leading enterprise... 
    Senior
    Contract work
    Remote work

    Dahl Consulting

    United States
    1 day ago
  •  ...end‑users (and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure... 
    Senior
    Remote work

    RevenueCat

    New York, NY
    1 day ago
  •  ...pioneering projects, and fast‐tracking careers. Together, we turn ideas into action — let's get started! We invite a Senior Application Security Engineer to join our team remotely . Responsibilities Demonstrated ability to collaborate with other teams to achieve complex... 
    Senior
    Remote work
    Relocation

    BrainRocket

    Staten Island, NY
    3 days ago
  •  ...available! The details are below. Beware of scams. S3 never asks for money during its onboarding process. Job Title: Senior Application Security Engineer (AI/ML) Contract Length: 6+ months Location: Iselin NJ 08830/ Charlotte, NC/ Dallas, TX/ Phoenix, AZ 3 days... 
    Senior
    Contract work
    Remote work
    Visa sponsorship
    Shift work
    3 days per week

    Leading Utilities Organization

    Charlotte, NC
    19 hours ago
  •  ...Senior Application Security Engineer Portugal The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global... 
    Senior
    Remote work
    Worldwide
    Flexible hours

    TripAdvisor

    United States
    2 hours ago
  • $80 - $85 per hour

     ...risks specifically related to application security. ? Develop, socialize, and implement...  ...vulnerabilities, to senior management. ? Perform/coordinate application...  ...Requirements Senior Application Security Engineer Mandatory Skills/Experience... 
    Senior
    Contract work
    Flexible hours

    Network Temp Inc

    New York, NY
    3 days ago
  • $75 - $110 per hour

     ...Contract consulting opportunity for an experienced Application Security Engineer Client requirements: Local to Minneapolis, MN area preferred...  ...: 1 year with extensions Seeking a highly motivated Senior Application Security Engineer to support and advance... 
    Senior
    Hourly pay
    Contract work
    Local area

    ITR Group

    Minneapolis, MN
    2 days ago
  •  ...and maintain $1.21 billion in surplus. Amerisure is hiring!! This role can sit remote . We're looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to safeguard... 
    Senior
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Mutual Insurance Company

    United States
    4 days ago
  • $128k - $181.25k

     ...capture moments that reflect who they uniquely are. This is an exciting time for Shutterfly and we are looking for a Senior Application Security Engineer to join our team! In this position you will be an integral part of a developing and expanding Application Security... 
    Senior
    Remote work

    Shutterfly

    New York, NY
    1 day ago
  •  ...Senior Application Security Engineer Moveworks is the Agentic AI Assistant platform that empowers the entire workforce. Our platform enables employees to converse with all of their business systems through natural language to quickly find answers and automate tasks... 
    Senior
    Work at office
    Remote work
    Flexible hours

    ServiceNow

    United States
    14 hours ago
  • $75 - $80 per hour

     ...Senior Application Security Engineer (DevSecOps | SAST/DAST/SCA | CI/CD Security) Immediate need for a talented Senior Application Security Engineer (DevSecOps | SAST/DAST/SCA | CI/CD Security). This is a 06+ months contract opportunity with long-term potential and... 
    Senior
    Contract work
    Local area
    Immediate start

    Pyramid Consulting

    Charlotte, NC
    2 days ago
  •  ...Title: Senior Application Security Engineer Location: Austin, TX / Dallas, TX (hybrid) Reports To: Sr. Manager, Cybersecurity About Hippo Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us.... 
    Senior
    Temporary work
    Flexible hours

    Hippo Insurance

    Austin, TX
    1 day ago
  • $27 per hour

     ...We are seeking a Sr. Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program. The ideal candidate will be responsible for ensuring the security of our applications throughout... 
    Senior
    Contract work
    Remote work
    Flexible hours

    Zetachain

    San Francisco, CA
    1 day ago
  •  ...holidays , to support a 24/7 environment. Respond to security incidents and operational escalations outside of...  ...containment, eradication, and post-incident reviews. Senior Application Security Engineer - Blue Team Who You Are A defensive security... 
    Senior
    Remote work
    Night shift

    3B Staffing LLC

    United States
    3 days ago
  • $180k - $210k

     ...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across... 
    Senior
    Work at office
    Remote work
    Flexible hours

    Qualia

    United States
    4 days ago
  • $220k - $350k

     ...Senior Application Security Engineer [Remote-US] remote To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors... 
    Senior
    Extra income
    Local area
    Remote work
    Work from home
    Home office

    Quanata

    New York, NY
    1 day ago
  • $160k - $240k

     ..., and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before...  ...and integrity of our customers' data. As our first Application Security Engineer , you will take on a dynamic and high impact role. You will... 
    Senior
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    3 days ago
  • $130k - $180k

     ...physicians, providing critical information about the right treatments for the right patients, at the right time. Senior Application Security Engineer Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to join our... 
    Senior

    Tempus

    Chicago, IL
    2 days ago
  • $158k - $238k

     ...performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies...  ...to power what’s possible on the web. We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development... 
    Senior
    Permanent employment
    Full time
    Temporary work
    Fixed term contract
    Local area
    Remote work
    Flexible hours

    Webflow

    New York, NY
    1 day ago
  • $120k - $150k

     ...Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware...  ...delivering high quality patient care. IDEXX is seeking a Senior Application Security Engineer to join our Product & Application Security team... 
    Senior
    Local area
    Remote work
    Worldwide
    Flexible hours

    IDEXX Laboratories

    United States
    3 days ago
  •  ...A global energy companyis looking to bring on a hands on a Senior Application Security Engineer to be part of a team building out their AppSec program from the ground up. This role is highly technical, and requires candidates with previous experience working in OTand/... 
    Senior
    Long term contract
    Remote work

    Motion Recruitment Partners LLC

    Los Angeles, CA
    3 days ago
  • $140k - $170k

     ...growing and changing Stellar ecosystem. SDF is looking for a Senior Security Engineer to help shape and scale the security program across the...  ...look forward to hearing from you! Privacy By submitting your application, you are agreeing to our use and processing of your data... 
    Senior
    Contract work
    Temporary work
    Work at office
    Local area
    Worldwide
    Flexible hours
    Night shift

    Energent Media

    New York, NY
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!