Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

App Sec Engineer - Threat Modeling & Secure SDLC

Softswiss

Security | Application Security Engineer SOFTSWISS is growing, and we are seeking a skilled Application Security Engineer to join our team. If you are driven by excellence and share our values, we would love to hear from you. Purpose of the role: Our goal is to make sure that we deploy secure software to production without unnecessary bottlenecks, that applications are properly hardened, and security vulnerabilities, once discovered, are fixed by the developers. As an Application Security Engineer, you will play a crucial role in ensuring the security of our applications throughout the entire software development lifecycle (SDLC). You will partner closely with the product teams to identify, analyze, and mitigate security vulnerabilities, contributing to the creation of trustworthy and robust products. Key responsibilities: Partner with product teams during the design phase to facilitate threat modeling and risk assessment sessions. Perform in-depth manual code reviews on critical applications to identify logical vulnerabilities as part of white-box security assessments. Tune and adjust rulesets for automated security scanning tools to reduce false positives and improve detection rates. Develop scripts and automation tools to streamline workflows and free up time for more complex analysis. Assist developers in understanding security risks and threats discovered during risk assessments, threat modeling, and dynamic testing. Triage vulnerabilities from the bug bounty program, collaborating with external researchers and internal engineering teams to resolve discovered flaws. Collaborate with Dev/QA teams throughout the development lifecycle to enhance the application’s security posture by providing dedicated security consulting, continuous knowledge sharing, and actionable guidance. Develop and maintain the internal security knowledge base, including comprehensive secure coding guidelines and technical manuals for standard security features. Required Experience: 1.5+ years of experience in application security, software development, or related technical roles. Knowledge of web application security mechanisms and controls (e.g., SOP, CORS, CSP). Comprehensive understanding of common web vulnerabilities (e.g., OWASP Top 10) and their practical mitigation strategies. Knowledge of secure system and application architecture alongside secure‑by‑design principles. Practical, hands‑on expertise in identifying vulnerabilities through manual security assessments and secure code reviews. Ability to clearly articulate and explain the business impact of identified threats and vulnerabilities to developers and product teams. A strong security‑first mindset with a continuous drive to learn and achieve excellence in the cybersecurity field. University degree in Computer Science, Information Security, or a related field (or an equivalent combination of education and practical experience). Intermediate or higher proficiency in English (B2 level or above) for effective technical communication. Nice to have: Passion about programming. Technical knowledge of network and operating systems security. Practice of participation in bug bounty programs and/or CTFs. Knowledge of SAST/DAST tools, including customization. Main Advantages Private health insurance Sports benefits Free English lessons (online) Local language courses Paid time off Maternity leave support Referral program rewards Upskilling, internal workshops, and participation in professional conferences and corporate events #J-18808-Ljbffr

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the App Sec Engineer - Threat Modeling & Secure SDLC in New York, NY vacancy
  •  ...ManpowerGroup Global, Inc. is seeking multiple experienced professionals for the AI Engineering for Threat Modeling role in New York City. As a member of the Security Engineering Department, you will design AI-driven threat modeling capabilities and automate validation... 
    Suggested

    ManpowerGroup Global, Inc.

    New York, NY
    3 days ago
  •  ...Vertex, Inc. is looking for an AI Security Engineer to secure AI systems and identify risks unique to AI features. This role involves performing threat modeling, developing security tooling, and working with product engineering teams to ensure safe deployment of AI applications... 
    Suggested

    Vertex Limited

    New York, NY
    9 hours ago
  •  ...A leading technology and consulting firm is seeking a Senior Engineer - Threat Modeling to enhance security processes and practices. This role requires expertise in GCP, various threat modeling methodologies, and the ability to work collaboratively in a cross-functional... 
    Suggested

    Synergy Interactive

    New York, NY
    2 days ago
  •  ...an experienced Application Security Engineer to join their security team....  ...design and resilient against threats, requiring collaboration with...  ...development lifecycle (SDLC), conducting code reviews, and...  ...tools management, and threat modeling is essential. #J-18808-Ljbffr... 
    Suggested

    Itlearn360

    New York, NY
    4 days ago
  •  ...AgileEngine, LLC. is seeking a Senior Application Security Engineer responsible for architecting secure coding practices within the SDLC. You will leverage your expertise in Python and Java to deploy security tools and guide code remediation. This position includes working... 
    Suggested
    Remote work

    AgileEngine

    New York, NY
    9 hours ago
  • $215k - $230k

     ...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should... 

    Crypto Pro Network

    New York, NY
    1 day ago
  •  ...Trail of Bits Inc. is seeking a Security Engineer to join their Software Assurance practice in New York, NY. This role involves conducting comprehensive security assessments of client software, focusing on low-level code analysis and developing security tools to enhance... 

    Trail of Bits

    New York, NY
    3 days ago
  •  ...is seeking experienced professionals to enhance AI systems for security content evaluation and feedback. This remote position allows candidates...  ...hours on projects that play a crucial role in shaping AI models. Preferred qualifications include 2+ years in cybersecurity and... 
    Remote job
    Flexible hours

    DataAnnotation

    New York, NY
    2 days ago
  • $115k - $135k

     ...AssetMark is seeking a Lead Security Engineer to ensure high security across their organization and product lines. This role requires strong...  ...integrate security at all levels. The position offers a hybrid work model and requires candidates to be located near Atlanta, GA,... 

    AssetMark

    New York, NY
    20 hours ago
  • $80 - $90 per hour

     ...seeking a highly skilled engineer who can design and...  ...also embedding security into every layer of the SDLC. You will work across...  ...CDC pipelines, data modeling). Ensure high performance...  ...coding standards, threat models, and security...  ...and Azure services (App Services, Functions,... 
    Hourly pay
    Permanent employment
    Contract work
    3 days per week

    Genesis10

    New York, NY
    3 days ago
  •  ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer...  ...ZAPExperience writing or validating WAF r ulesSecure SDLC, threat modelling, or security champion progra mmesConsulting or... 
    Full time

    AGS

    New York, NY
    4 days ago
  •  ...Application Security Engineer | Location: New York, NY or Charlotte, NC | Contract...  ...secure-by-design principles throughout the SDLC. Identify, assess, and remediate...  ...across development teams. Perform threat modeling and risk analysis for new and existing... 
    Contract work

    Delphi-US

    New York, NY
    20 hours ago
  •  ...implementation of Application Security controls across CI/CD...  ...ownership across engineering teams. 2. Vulnerability & Threat Management Lead...  ...categories. Perform threat modeling and security design...  ...Vulnerability Management, or Secure SDLC. ~ Strong expertise... 

    2T Consulting

    Jersey City, NJ
    20 hours ago
  • GuidePoint Security, LLC is seeking a security engineer with expertise in Static Application Security Testing (SAST) and CI/CD pipelines. The ideal candidate will have a Bachelor's degree and 5-7 years of relevant experience. Responsibilities include implementing security... 
    Remote job
    Flexible hours

    GuidePoint Security, LLC

    New York, NY
    3 days ago
  •  ...Lead Application Security Engineer We are a specialized technology staffing agency supporting...  ...! Responsibilities: Perform threat modeling on applications to determine...  ...control systems, CI/CD pipeline management, SDLC maturity, SaaS security tools (SCA, SAST... 
    Work at office

    Eleven Recruiting

    New York, NY
    1 day ago
  • $10 per hour

     ...about what’s ahead. About the Role: Our engineering organization is growing, and with...  ...that requires dedicated application security ownership. This role exists to build...  ...SAST and DAST tooling to secure SDLC practices, threat modeling, dependency security, and penetration... 
    Full time
    Temporary work
    For contractors
    Work at office
    Remote work
    Visa sponsorship
    Flexible hours

    Bitwise Asset Management

    New York, NY
    4 days ago
  • Application Security Engineer (Senior) ID71672 Full time | AgileEngine | United States Posted...  ...automated security layers within the SDLC, engineering AI-enabled secure code scanning...  ...generation; Advanced application threat modeling experience. PERKS AND BENEFITS... 
    Full time
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours

    AgileEngine, LLC.

    New York, NY
    1 day ago
  • $40 per hour

     ...for experienced cybersecurity professionals to evaluate AI-generated content and solve security-related problems. This role supports the development of AI models for improved threat analysis and defenses. Candidates should have over 2 years of hands-on cybersecurity experience... 
    Remote job
    Hourly pay
    Full time
    Part time

    DataAnnotation

    New York, NY
    2 days ago
  • A leading global financial services firm is seeking a Lead Security Engineer to enhance software security. In this role, you will design and implement security solutions while ensuring compliance with cloud service requirements. Candidates should have over 5 years of certification... 

    JPMorgan Chase & Co.

    Brooklyn, NY
    1 day ago
  •  ...Luxoft is seeking an experienced Application Security professional to join a cross-functional team in the Oil & Gas domain...  ...a strong focus on AI/ML security, protecting against threats, and ensuring secure SDLC integration. Candidates should have over 5 years of experience... 

    Luxoft

    New York, NY
    1 day ago
  • $194k - $239k

     ...Security Software Engineer Hover helps people design, improve, and protect the...  ...accurate, and interactive 3D models of any property — all from a...  ...design principles, and lead threat modeling. System Hardening...  ...software development lifecycle (SDLC). ~ Meticulous attention... 
    Full time
    For contractors
    Work at office
    Local area
    Flexible hours

    Almaz Capital

    New York, NY
    4 days ago
  •  ...Staff+ Software Security Engineer San Francisco, CA | New York City, NY...  ...cryptographic foundations that protect model weights and training data,...  ...systematic risks through threat modeling and risk assessment,...  ...build infrastructure, and SDLC integrations Built or secured... 
    Visa sponsorship

    Anthropic

    New York, NY
    1 day ago
  •  ...focused organization in the United States is seeking a DevSecOps Engineer to manage secure CI/CD pipelines and integrate security practices early in...  ...DevOps, Docker, and Kubernetes. Responsibilities include threat detection logic management, Azure pipeline maintenance, and... 

    Quzara LLC

    New York, NY
    2 days ago
  •  ...I’m hiring for an Application Security Engineering Manager to lead and scale a high-impact AppSec function in a deeply technical financial...  ...engineering environments, understands secure SDLC, threat modelling, code review, application architecture risk, cloud/application... 
    Work at office
    Remote work
    3 days per week

    Iceberg

    New York, NY
    3 days ago
  •  ...itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our...  ...Strong expertise in application security: OWASP Top 10, threat modeling, code reviews, architecture design Proficiency with AI... 
    Full time
    Freelance
    Work from home

    Valence

    New York, NY
    1 day ago
  •  ..., and Vercel use Braintrust to compare models, test prompts, and catch regressions -...  ...We're looking for an Application Security Engineer who lives in the code. Braintrust is a...  ...-on IC role. You'll review code, build threat models, ship paved-road libraries, and... 
    Flexible hours

    Brain Trust Inc

    New York, NY
    8 hours ago
  •  ...ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline...  ...platforms such as Wiz; - Basic understanding of application threat modeling. PERKS AND BENEFITS - Professional growth :... 
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours

    AgileEngine

    New York, NY
    3 days ago
  • $135k - $200k

     ...in the face of advanced persistent threats. The mission of the Application Security Team is to enable developers to be...  ...As an Application Security Engineer, you will be hands-on and have wide...  ...architects and engineers. You will threat model, assess risks, and help implement... 
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    New York, NY
    1 day ago
  • $221k - $260k

     ...You'll DoSecurity Platform Engineering Design and implement scalable...  ...evidence collection Security Automation & Tooling Create...  ...Application & Data Security Lead threat modeling and security architecture...  ...frameworks and secure SDLC principles ~ Excellent communication... 
    Full time
    Contract work
    Work at office
    Immediate start
    Remote work
    Flexible hours
    3 days per week

    Maven Clinic

    New York, NY
    1 day ago
  •  ...GuidePoint Security is looking for an Application Security Engineer to work remotely from the U.S. The role involves running security tools, integrating security practices into CI/CD pipelines, and collaborating with development teams. Ideal candidates will have at least... 
    Remote work
    Flexible hours

    GuidePoint Security

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to App Sec Engineer - Threat Modeling & Secure SDLC. Be the first to apply!