App Sec Engineer - Threat Modeling & Secure SDLC
Softswiss
Security | Application Security Engineer SOFTSWISS is growing, and we are seeking a skilled Application Security Engineer to join our team. If you are driven by excellence and share our values, we would love to hear from you. Purpose of the role: Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers. As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products. Key responsibilities: Partner with product teams during the design phase to facilitate threat modeling and risk assessment sessions. Perform in-depth manual code reviews on critical applications to identify logical vulnerabilities as part of white-box security assessments. Tune and adjust rulesets for automated security scanning tools to reduce false positives and improve detection rates. Develop scripts and automation tools to streamline workflows and free up time for more complex analysis. Assist developers in understanding security risks and threats discovered during risk assessments, threat modeling, and dynamic testing. Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws. Collaborate with Dev/QA teams throughout the development lifecycle to enhance the application’s security posture by providing dedicated security consulting, continuous knowledge sharing, and actionable guidance. Develop and maintain the internal security knowledge base, including comprehensive secure coding guidelines and technical manuals for standard security features. Required Experience: 1.5+ years of experience in application security, software development, or related technical roles. Knowledge of web application security mechanisms and controls (e.g., SOP, CORS, CSP). Comprehensive understanding of common web vulnerabilities (e.g., OWASP Top 10) and their practical mitigation strategies. Knowledge of secure system and application architecture alongside secure‑by‑design principles. Practical, hands‑on expertise in identifying vulnerabilities through manual security assessments and secure code reviews. Ability to clearly articulate and explain the business impact of identified threats and vulnerabilities to developers and product teams. A strong security‑first mindset with a continuous drive to learn and achieve excellence in the cybersecurity field. University degree in Computer Science, Information Security, or a related field (or an equivalent combination of education and practical experience). Intermediate or higher proficiency in English (B2 level or above) for effective technical communication. Nice to have: Passion about programming. Technical knowledge of network and operating systems security. Practice of participation in bug bounty programs and/or CTFs. Knowledge of SAST/DAST tools, including customization. Main Advantages Private health insurance Sports benefits Free English lessons (online) Local language courses Paid time off Maternity leave support Referral program rewards Upskilling, internal workshops, and participation in professional conferences and corporate events #J-18808-Ljbffr
- ...ManpowerGroup Global, Inc. is seeking multiple experienced professionals for the AI Engineering for Threat Modeling role in New York City. As a member of the Security Engineering Department, you will design AI-driven threat modeling capabilities and automate validation...Suggested
- ...Vertex, Inc. is looking for an AI Security Engineer to secure AI systems and identify risks unique to AI features. This role involves performing threat modeling, developing security tooling, and working with product engineering teams to ensure safe deployment of AI applications...Suggested
- ...A leading technology and consulting firm is seeking a Senior Engineer - Threat Modeling to enhance security processes and practices. This role requires expertise in GCP, various threat modeling methodologies, and the ability to work collaboratively in a cross-functional...Suggested
- ...an experienced Application Security Engineer to join their security team.... ...design and resilient against threats, requiring collaboration with... ...development lifecycle (SDLC), conducting code reviews, and... ...tools management, and threat modeling is essential. #J-18808-Ljbffr...Suggested
- ...AgileEngine, LLC. is seeking a Senior Application Security Engineer responsible for architecting secure coding practices within the SDLC. You will leverage your expertise in Python and Java to deploy security tools and guide code remediation. This position includes working...SuggestedRemote work
$215k - $230k
...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should...- ...Trail of Bits Inc. is seeking a Security Engineer to join their Software Assurance practice in New York, NY. This role involves conducting comprehensive security assessments of client software, focusing on low-level code analysis and developing security tools to enhance...
- ...is seeking experienced professionals to enhance AI systems for security content evaluation and feedback. This remote position allows candidates... ...hours on projects that play a crucial role in shaping AI models. Preferred qualifications include 2+ years in cybersecurity and...Remote jobFlexible hours
$115k - $135k
...AssetMark is seeking a Lead Security Engineer to ensure high security across their organization and product lines. This role requires strong... ...integrate security at all levels. The position offers a hybrid work model and requires candidates to be located near Atlanta, GA,...$80 - $90 per hour
...seeking a highly skilled engineer who can design and... ...also embedding security into every layer of the SDLC. You will work across... ...CDC pipelines, data modeling). Ensure high performance... ...coding standards, threat models, and security... ...and Azure services (App Services, Functions,...Hourly payPermanent employmentContract work3 days per week- ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer... ...ZAPExperience writing or validating WAF r ulesSecure SDLC, threat modelling, or security champion progra mmesConsulting or...Full time
- ...Application Security Engineer | Location: New York, NY or Charlotte, NC | Contract... ...secure-by-design principles throughout the SDLC. Identify, assess, and remediate... ...across development teams. Perform threat modeling and risk analysis for new and existing...Contract work
- ...implementation of Application Security controls across CI/CD... ...ownership across engineering teams. 2. Vulnerability & Threat Management Lead... ...categories. Perform threat modeling and security design... ...Vulnerability Management, or Secure SDLC. ~ Strong expertise...
- GuidePoint Security, LLC is seeking a security engineer with expertise in Static Application Security Testing (SAST) and CI/CD pipelines. The ideal candidate will have a Bachelor's degree and 5-7 years of relevant experience. Responsibilities include implementing security...Remote jobFlexible hours
- ...Lead Application Security Engineer We are a specialized technology staffing agency supporting... ...! Responsibilities: Perform threat modeling on applications to determine... ...control systems, CI/CD pipeline management, SDLC maturity, SaaS security tools (SCA, SAST...Work at office
$10 per hour
...about what’s ahead. About the Role: Our engineering organization is growing, and with... ...that requires dedicated application security ownership. This role exists to build... ...SAST and DAST tooling to secure SDLC practices, threat modeling, dependency security, and penetration...Full timeTemporary workFor contractorsWork at officeRemote workVisa sponsorshipFlexible hours- Application Security Engineer (Senior) ID71672 Full time | AgileEngine | United States Posted... ...automated security layers within the SDLC, engineering AI-enabled secure code scanning... ...generation; Advanced application threat modeling experience. PERKS AND BENEFITS...Full timeWork at officeRemote workVisa sponsorshipWork visaFlexible hours
$40 per hour
...for experienced cybersecurity professionals to evaluate AI-generated content and solve security-related problems. This role supports the development of AI models for improved threat analysis and defenses. Candidates should have over 2 years of hands-on cybersecurity experience...Remote jobHourly payFull timePart time- A leading global financial services firm is seeking a Lead Security Engineer to enhance software security. In this role, you will design and implement security solutions while ensuring compliance with cloud service requirements. Candidates should have over 5 years of certification...
- ...Luxoft is seeking an experienced Application Security professional to join a cross-functional team in the Oil & Gas domain... ...a strong focus on AI/ML security, protecting against threats, and ensuring secure SDLC integration. Candidates should have over 5 years of experience...
$194k - $239k
...Security Software Engineer Hover helps people design, improve, and protect the... ...accurate, and interactive 3D models of any property — all from a... ...design principles, and lead threat modeling. System Hardening... ...software development lifecycle (SDLC). ~ Meticulous attention...Full timeFor contractorsWork at officeLocal areaFlexible hours- ...Staff+ Software Security Engineer San Francisco, CA | New York City, NY... ...cryptographic foundations that protect model weights and training data,... ...systematic risks through threat modeling and risk assessment,... ...build infrastructure, and SDLC integrations Built or secured...Visa sponsorship
- ...focused organization in the United States is seeking a DevSecOps Engineer to manage secure CI/CD pipelines and integrate security practices early in... ...DevOps, Docker, and Kubernetes. Responsibilities include threat detection logic management, Azure pipeline maintenance, and...
- ...I’m hiring for an Application Security Engineering Manager to lead and scale a high-impact AppSec function in a deeply technical financial... ...engineering environments, understands secure SDLC, threat modelling, code review, application architecture risk, cloud/application...Work at officeRemote work3 days per week
- ...itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our... ...Strong expertise in application security: OWASP Top 10, threat modeling, code reviews, architecture design Proficiency with AI...Full timeFreelanceWork from home
- ..., and Vercel use Braintrust to compare models, test prompts, and catch regressions -... ...We're looking for an Application Security Engineer who lives in the code. Braintrust is a... ...-on IC role. You'll review code, build threat models, ship paved-road libraries, and...Flexible hours
- ...ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline... ...platforms such as Wiz; - Basic understanding of application threat modeling. PERKS AND BENEFITS - Professional growth :...Work at officeRemote workVisa sponsorshipWork visaFlexible hours
$135k - $200k
...in the face of advanced persistent threats. The mission of the Application Security Team is to enable developers to be... ...As an Application Security Engineer, you will be hands-on and have wide... ...architects and engineers. You will threat model, assess risks, and help implement...Work experience placementWork at officeRemote workWork from homeRelocation package$221k - $260k
...You'll DoSecurity Platform Engineering Design and implement scalable... ...evidence collection Security Automation & Tooling Create... ...Application & Data Security Lead threat modeling and security architecture... ...frameworks and secure SDLC principles ~ Excellent communication...Full timeContract workWork at officeImmediate startRemote workFlexible hours3 days per week- ...GuidePoint Security is looking for an Application Security Engineer to work remotely from the U.S. The role involves running security tools, integrating security practices into CI/CD pipelines, and collaborating with development teams. Ideal candidates will have at least...Remote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to App Sec Engineer - Threat Modeling & Secure SDLC. Be the first to apply!
- technical application engineer New York, NY
- senior app developer New York, NY
- application operations engineer New York, NY
- senior application support engineer New York, NY
- application support developer New York, NY
- application engineer New York, NY
- field applications engineer New York, NY
- hydraulic application engineer New York, NY
- application support engineer New York, NY
- database application developer New York, NY



