Application Security Engineer
H.W. Kaufman Group
Role Description
The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements, proactively mitigating threats, and collaborating closely with developers to enhance the overall security posture of our applications.
- Partner with development teams to embed security best practices across the SDLC, including design, development, and deployment, and provide secure coding guidance.
- Conduct threat modeling and security architecture reviews to identify design-level risks and implement appropriate security controls.
- Identify, assess, and mitigate application vulnerabilities through a combination of automated (SAST/DAST) and manual code reviews, as well as penetration testing, and drive risk-based remediation.
- Implement and manage application security tools, including SAST, DAST, Software Composition Analysis (SCA), and other security scanning solutions.
- Ensure application security practices align with regulatory standards such as NYDFS, NIST, and OWASP guidelines.
- Partner with DevOps, IT, and security teams to integrate security into CI/CD pipelines and engineering workflows.
- Design and oversee the implementation of authentication, authorization, and access control mechanisms for APIs and platforms.
- Develop and enforce secure usage standards and governance for AI tools and AI-generated code, addressing risks such as prompt injection, data leakage, insecure code generation, and model misuse, while aligning with regulatory and industry standards.
Qualifications
- 5+ years of experience in application security, secure software development, and vulnerability management.
- Strong knowledge of secure coding practices, OWASP Top 10, OWASP Top 10 for LLMs, MITRE ATLAS, and common security vulnerabilities.
- Experience with containerization technologies such as Docker and Kubernetes, the principles of container operation, and their secure interaction.
- Experience with security testing tools (e.g., Burp Suite, Fortify, Veracode, or similar).
- Experience with Black Duck/Polaris with Apex code (Salesforce) is a plus.
- Familiarity with DevSecOps principles and integrating security into CI/CD pipelines.
- Direct experience with security tools such as vulnerability scanners, intrusion detection systems, and log analysis tools.
- Understanding of regulatory frameworks and compliance requirements (e.g., NYDFS, GDPR, SOC 2).
- Ability in scripting and automation using languages such as Python, PowerShell, or Bash and leverage AI driven tools to streamline and enhance security process and workflows.
- Relevant certifications such as Certified DevSecOps Engineer, CISSP, OWASP certifications, GIAC GWAPT.
Company Description
H.W. Kaufman Group is a powerful global network of companies dedicated to shaping the future of insurance. With thousands of dedicated professionals across an extensive network of over 60 offices around the world, we lead by offering innovative solutions that are at the forefront of the industry. We are privately owned and thus free from the influence of Wall Street. This allows us the ability to adapt to constantly fluctuating market conditions. From brokerage, underwriting, and real estate to claims, loss control and risk management services, our depth of services is unrivaled.
Equal Opportunity Employer
The H.W. Kaufman Group of companies is an equal opportunity employer. All employment decisions are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, gender, gender identity, age, national origin, disability, veteran status, marital status, pregnancy, sexual orientation, genetic information or any other status or condition protected by the laws or regulations in the locations where we operate.
In addition, Kaufman will make reasonable accommodations to known physical or mental limitations of an otherwise qualified person with a disability, unless the accommodation would impose an undue hardship on the operation of our business.
$85k - $105k
...Application Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and...SuggestedFull timeH1bLocal areaImmediate startRemote workVisa sponsorship$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SuggestedTemporary workRemote work$125k - $165k
...economic inclusion. Find out how TripleLift raises up the programmatic ecosystem at triplelift.com. Overview The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's...SuggestedFull timeFlexible hours$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...SuggestedFull timeWork at officeRemote workWeekend work$111k - $144.4k
Role Description The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected...SuggestedFull timeTemporary workWork experience placement$100k - $150k
Role Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio....Full timeLocal areaImmediate start$130k - $190k
...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50... ...this role now: The company is maturing its application security function from a position of strength...Full timeHome office- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...Full timeRemote work
$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...Full timeFlexible hours$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...Full timeLocal areaImmediate start$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management....Full timeWork experience placement$125.6k - $172.7k
Role Description As an Application Security Engineer at Solventum, you will: ~Join a team of cybersecurity professionals motivated to secure Solventum's healthcare information systems and the personal health information of our clients and their patients. ~Operate and...Full timeFlexible hours$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...Full timeFlexible hours$120k - $258.5k
Role Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn’t have to choose between moving... ...of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack...Full time$157k - $216k
Role Description AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity...Full timeRemote work$175k - $215k
Role Description We're looking for an Application Security Engineer to help build secure-by-default products and services across Quanata's AI-native insurance technology platform. In this role, you'll partner closely with Product, Engineering, and Security teams to identify...Extra incomeFull timeHome officeShift work$130k - $160k
...information at scale across 75+ health systems and millions of patient encounters. Security is not a layer we add at the end; it is built into how we work. As a Senior Application Security Engineer, you will own the application security practice at Fabric, partnering...Full time- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...Full timeFlexible hours
$120k - $145k
Role Description Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery...Full timeRemote work- Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable...Full timeFlexible hours
- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...Full timeRemote work
$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...Full timeTemporary work- Role Description As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our...Full timeTemporary workImmediate startRemote workFlexible hours
$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...Full timeWork experience placementRemote workSleeping nights$180k - $200k
...Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most... ...core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop...Full timeFlexible hours$100k - $140k
Role Description Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security...Full timeFlexible hours- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...Full timeRemote workFlexible hours
- Role Description As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform. You'll own the security judgment layer that sits between raw tooling output and what our customers actually...Full timeRemote work
- Role Description DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission...Full timeLocal areaRemote work
$114k - $240k
Role Description As a senior individual contributor on the Application Security team, the Staff Application Security Engineer will help to define and drive Reltio’s application and product security architecture across a distributed, cloud-native SaaS platform. This role...Full timeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- network applications engineer Remote
- hydraulic application engineer Remote
- application engineering manager Remote
- project application engineer Remote
- application security engineer Remote
- senior application security engineer Remote
- application operations engineer Remote
- application system engineer Remote
- technical application engineer Remote
- senior application support engineer Remote
















