Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Application Security Engineer

Vertafore

The insurance industry runs on Vertafore. We equip agencies, MGAs, and carriers with the core digital systems, specialized AI, and data-driven foundation to eliminate distribution drag across the insurance lifecycle, spanning sales, servicing, and back-office operations.

Underpinned by unmatched speed and performance power, we are the trusted backbone that's taking the insurance industry from friction to flow with Distribution Velocity - speed, performance, and trust - to drive growth at scale.

With over 95% of the top agencies and insurers and 50% of industry compliance transactions running through Vertafore, we lead at the intersection of innovation and trust, giving insurance professionals the confidence to transform and win in the AI era.

Our reach is global, with headquarters in Denver, Colorado, and offices across the U.S., Canada, and India.

The Senior Application Security Engineer is responsible for advancing application, product, cloud, API, identity, and AI security across Vertafore's software engineering organization. This role partners directly with product, engineering, architecture, DevOps, cloud, and security teams to identify risk early, define secure design patterns, and embed scalable security controls into the software development lifecycle.

This role will serve as a hands-on technical security partner for application teams, helping them understand and document application architecture from a security perspective, identify trust boundaries and attack paths, and implement practical mitigations. The Senior Application Security Engineer will support secure design reviews, threat modeling, secure coding practices, vulnerability management, CI/CD security controls, API security, identity and access management patterns, and emerging AI/agentic product security capabilities.

A key focus of this position is securing AI-enabled applications and AI agents integrated into Vertafore products. This includes understanding AI agent architecture, authentication and authorization patterns, memory handling, prompt tracing, tool/plugin access, guardrails, model and runtime behavior, AI runtime scanning, and secure use of code-assist tools within engineering workflows.

The ideal candidate is a strong application security practitioner who can translate complex technical risk into actionable engineering guidance, influence teams without direct authority, and help product teams ship securely without unnecessary friction..


Core Requirements and Responsibilities:


Essential job functions included but are not limited to the following:
• Partner with product and engineering teams to perform application security reviews, secure architecture reviews, and threat modeling for new and existing applications, services, APIs, integrations, and cloud-native workloads.
• Work with teams to understand application architecture, data flows, trust boundaries, authentication and authorization models, third-party integrations, deployment patterns, and security-relevant design decisions.
• Document application architecture from a security perspective, including key assets, identity flows, privilege boundaries, attack surfaces, sensitive data flows, control gaps, and recommended mitigations.
• Identify and prioritize application security risks across web applications, APIs, microservices, SaaS platforms, cloud services, CI/CD pipelines, infrastructure-as-code, and AI-enabled product capabilities.
• Provide hands-on guidance to engineering teams on secure coding, secure design, vulnerability remediation, secrets management, dependency risk, API security, input validation, authentication, authorization, session management, logging, and error handling.
• Support and improve secure SDLC practices, including security requirements, design review checkpoints, threat modeling, secure code review, automated scanning, developer education, exception management, and remediation tracking.
• Integrate and tune security tooling across CI/CD pipelines, including SAST, SCA, IaC scanning, container scanning, DAST, API security testing, secrets detection, and AI runtime security scanning where applicable.
• Help define and operationalize security controls for AI agents and AI-enabled product features, including guardrails, authentication, authorization, prompt tracing, model/tool interaction logging, memory controls, data leakage prevention, abuse-case testing, and runtime monitoring.
• Evaluate the secure use of AI code-assist tools and developer productivity tools, including risks related to data exposure, insecure code generation, hallucinated dependencies, licensing, secrets leakage, provenance, and secure review workflows.
• Collaborate with DevOps and platform teams to embed security controls into CI/CD workflows while minimizing developer friction and false positives.
• Review identity and access management patterns across applications and platforms, including IAM, PAM, JIT access, service accounts, least privilege, privileged workflows, role design, federation, SSO, API access, token handling, and lifecycle governance.
• Partner with cloud and infrastructure teams to review application-level cloud security controls across AWS, Azure, and related platforms.
• Support vulnerability management by validating findings, assessing exploitability and business impact, partnering on remediation plans, and escalating material risks when needed.
• Develop reusable security patterns, reference architectures, standards, guardrails, and implementation guidance for engineering teams.
• Mentor engineers and security team members on application security, cloud security, API security, AI security, threat modeling, and secure SDLC practices.
• Communicate risk clearly to technical and non-technical stakeholders, including engineering leaders, product leaders, compliance partners, and security leadership.
• Contribute to security policy, standards, compliance, and audit readiness efforts related to application security, product security, identity, cloud, AI, and SDLC controls.
• Participate in security incident response, security operations escalation, or on-call processes as required by the business.


Knowledge, Skills and Abilities:
• Strong knowledge of application security principles, secure design, secure coding, web application security, API security, cloud-native application security, and secure SDLC practices.
• Strong understanding of common application and API vulnerabilities, including OWASP Top 10, OWASP API Security Top 10, authentication bypass, authorization flaws, injection, insecure deserialization, SSRF, business logic flaws, secrets exposure, and supply chain risks.
• Experience performing security architecture reviews, threat modeling, design reviews, and risk assessments for modern software systems.
• Ability to understand complex application architectures and document them from a security perspective, including data flows, trust boundaries, identity flows, external integrations, and critical control points.
• Working knowledge of AI-enabled application and AI agent security concepts, including agent components, tool use, memory, prompt handling, prompt tracing, guardrails, authentication, authorization, runtime monitoring, abuse-case testing, and data protection.
• Familiarity with AI security frameworks, patterns, or risk areas such as prompt injection, indirect prompt injection, tool misuse, excessive agency, data leakage, insecure plugin/tool access, model output handling, and agentic workflow abuse.
• Experience evaluating or securing AI code-assist tools, including secure configuration, acceptable-use guardrails, source code exposure risks, generated-code review practices, and developer workflow controls.
• Experience integrating security testing and security gates into CI/CD pipelines, including SAST, SCA, IaC scanning, container scanning, secrets scanning, DAST, API testing, and AI runtime scanning.
• Strong understanding of identity and access management concepts, including IAM, PAM, JIT access, least privilege, RBAC/ABAC, federation, SSO, MFA, privileged workflows, service identities, API tokens, and access lifecycle management.
• Experience with cloud security concepts and services across AWS and/or Azure, particularly as they relate to application workloads, identity, networking, logging, encryption, and deployment pipelines.
• Familiarity with WAF, API gateway, rate limiting, bot protection, DLP, logging/monitoring, SIEM integrations, and application-layer detective and preventive controls.
• Ability to assess vulnerabilities based on exploitability, compensating controls, business impact, and remediation complexity rather than scanner severity alone.
• Ability to influence engineering teams and product stakeholders through practical, risk-based guidance.
• Strong written and verbal communication skills, including the ability to explain security risk, tradeoffs, and recommended actions to both technical and non-technical audiences.
• Ability to create repeatable standards, patterns, playbooks, and architecture guidance that scale across multiple teams and products.
• Strong collaboration skills with engineering, architecture, DevOps, cloud, compliance, IT, identity, and security operations teams.
• Ability to work independently, manage competing priorities, and operate effectively in a remote or hybrid environment.
Skills & Requirements
Qualifications:
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or related field OR equivalent experience.
• 7+ years of experience in application security, product security, security engineering, software engineering with security focus, cloud security, or security architecture.
• Hands-on experience with application security reviews, threat modeling, secure SDLC practices, vulnerability management, and engineering partnership.
• Experience securing cloud-hosted applications, APIs, microservices, CI/CD pipelines, and modern software delivery environments.
• Experience with at least several of the following security tools or control areas: SAST, DAST, SCA, secrets scanning, container scanning, IaC scanning, API security testing, WAF, CNAPP/CSPM, CI/CD security controls, SIEM/logging, or runtime application security monitoring.
• Experience with identity and access management patterns, including IAM, PAM, JIT access, privileged access workflows, service account governance, SSO, MFA, RBAC/ABAC, and least privilege.
• Experience or demonstrated working knowledge of AI application security, AI agents, LLM-enabled product features, AI runtime controls, AI-assisted development workflows, or secure AI adoption is strongly preferred.
• Experience working directly with software engineering teams to document architecture, identify security risks, and drive remediation through practical engineering guidance.
• Security certifications are a plus, such as CSSLP, CISSP, GWAPT, GWEB, AWS Security Specialty, CCSP, or other relevant credentials.
• Familiarity with regulatory, compliance, or control frameworks such as SOC 2, ISO 27001, NIST CSF, NIST SSDF, OWASP ASVS, OWASP SAMM, or similar frameworks is preferred.


Additional Requirements and Details:
• Travel required up to 10% of the time.
• Ability to work remote with a stable internet connection on an as needed basis
• Located and working from an office location (when required)
• Occasional lifting and/or moving up to 10 pounds.
• Frequent repetitive hand and arm movements required to operate a computer.
• Specific vision abilities required by this job include close vision (working on a computer, etc.).
• Frequent sitting and/or standing.

#LI-Hybrid

THE VERTAFORE STORY

Over the past 50 years, Vertafore has advanced the entire insurance distribution channel with the best software solutions in the industry. Today, we're proud to say hundreds of thousands of Vertafore users rely on our solutions to write business faster, reduce costs, and fuel growth by increasing collaboration and streamlining processes. Vertafore leads the industry with secure, cloud-based mobile products that provide superior reporting and analytics, delivering actionable insight- right when customers need it most. We partner with other leading technology companies to deliver comprehensive solutions to improve the way our customers do business and serve their customers.


The Vertafore Way

Insurance is about relationships, and technology should make those relationships stronger. That's why, at Vertafore, it's our mission to transform the way the industry operates by putting people at the heart of insurance technology. By focusing on our customers, becoming better every day, and delivering results you can see, we provide the level of trust and security that insurance is all about.
Bias to Action: We're united by an innate drive to take action and make a difference in the technology and insurance spaces.
Win Together: We work together as one team, showing empathy and respect along the way.
Show Up Curious: We work to challenge one another to push boundaries and think beyond the box.
Say It, Do It: We honor every one of our commitments because integrity is important to us.
Customer Success is Our Success: We cultivate authentic relationships and follow up by actively listening to their needs.
We Love Insurance: We appreciate the impact insurance has on the world.

Is this role not an exact fit for you? Keep an eye on our Careers Page for other positions!

Vertafore is a drug free workplace and conducts preemployment drug and background screenings.

The selected candidate must be legally authorized to work in the United States.

The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all the job responsibilities, duties, skill, or working conditions. In addition, this document does not create an employment contract, implied or otherwise, other than an "at will" relationship.


Vertafore strongly supports equal employment opportunity for all applicants regardless of race, color, religion, sex, gender identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, sexual orientation, genetic information, or any other characteristic protected by state or federal law.

We do not accept resumes from agencies, headhunters, or other suppliers who have not signed a formal agreement with us.
Qualifications


Why Vertafore is the place for you: *Canada Only
  • The opportunity to work in a space where modern technology meets a stable and vital industry
  • Medical, vision & dental plans
  • Life, AD&D
  • Short Term and Long Term Disability
  • Pension Plan & Employer Match
  • Maternity, Paternity and Parental Leave
  • Employee and Family Assistance Program (EFAP)
  • Education Assistance
  • Additional programs - Employee Referral and Internal Recognition
Why Vertafore is the place for you: *US Only
  • The opportunity to work in a space where modern technology meets a stable and vital industry
  • We have a Flexible First work environment! Our North America team members use our offices for collaboration, community and team-building, with members asked to sometimes come into an office and/or travel depending on job responsibilities. Other times, our teams work from home or a similar environment.
  • Medical, vision & dental plans
    • PPO & high-deductible options
  • Health Savings Account & Flexible Spending Accounts Options:
    • Health Care FSA
    • Dental & Vision FSA
    • Dependent Care FSA
    • Commuter FSA
  • Life, AD&D (Basic & Supplemental), and Disability
  • 401(k) Retirement Savings Plain & Employer Match
  • Supplemental Plans - Pet insurance, Hospital Indemnity, and Accident Insurance
  • Parental Leave & Adoption Assistance
  • Employee Assistance Program (EAP)
  • Education & Legal Assistance
  • Additional programs - Tuition Reimbursement, Employee Referral, Internal Recognition, and Wellness
  • Commuter Benefits (Denver)
The selected candidate must be legally authorized to work in the United States.


The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all the job responsibilities, duties, skill, or working conditions. In addition, this document does not create an employment contract, implied or otherwise, other than an "at will" relationship.


Vertafore strongly supports equal employment opportunity for all applicants regardless of race, color, religion, sex, gender identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, sexual orientation, genetic information, or any other characteristic protected by state or federal law.


The Professional Services (PS) and Customer Success (CX) bonus plans are a quarterly monetary bonus plan based upon individual and practice performance against specific business metrics. Eligibility is determined by several factors including: start date, good standing in the company, and actives status at time of payout.

The Vertafore Incentive Plan (VIP) is an annual monetary bonus for eligible employees based on both individual and company performance. Eligibility is determined by several factors including: start date, good standing in the company, and actives status at time of payout.

Commission plans are tailored to each sales role but common components include quota, MBO's and ABPMs. Salespeople receive their formal compensation plan within 30 days of hire.

Vertafore is a drug free workplace and conducts preemployment drug and background screenings.

We do not accept resumes from agencies, headhunters or other suppliers who have not signed a formal agreement with us.

We want to make sure our recruiting process is accessible for everyone. if you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact View email address on click.appcast.io

Just a note, this contact information is for accommodation requests only.
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Sr. Application Security Engineer in Denver, CO vacancy
  • $165k - $225k

     ...with the talent and ambition to build the technology that secures it.OUR MISSIONTrue Anomaly delivers decisive capabilities...  ...advantage and we are better together.YOUR MISSIONAs a Senior Application Security Engineer, you will be instrumental in implementing and auditing... 
    Senior
    Permanent employment
    Shift work

    True Anomaly

    Denver, CO
    2 days ago
  • $90k - $125k

     ...united by our mission of creating opportunities for people where they live, learn, and work.We are seeking a highly skilled Application Security Engineer with strong experience across secure code review, penetration testing, automation, and modern SDLC practices—including... 
    Suggested
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Remote work
    3 days per week

    Nelnet

    Centennial, CO
    3 hours ago
  •  ...Job Title Key Responsibilities (with Technologies): Application Security Testing: Conduct in-depth security testing on front-end web...  ...Modeling Tools (e.g., Microsoft Threat Modeling Tool) Social Engineering Simulation: Use real-world breach tactics to refine testing... 
    Suggested

    My3Tech Inc

    Englewood, CO
    4 days ago
  • $130k - $150k

     ...be part of a high-performing team that believes in each other, come build with us at Crusoe. About This Role: As an Application Engineer III, you will serve as the primary technical interface between our Estimating, Customer, and Engineering/Manufacturing teams... 
    Senior
    Temporary work
    Work at office

    Crusoe

    Arvada, CO
    4 days ago
  • $165k - $235k

     ...and ambition to build the technology that secures it.OUR MISSIONTrue Anomaly delivers...  ...YOUR MISSIONAs a Senior Embedded Security Engineer, you will be responsible for hardening the...  ...is successfully filled. To submit your application, please follow the directions below.To conform... 
    Senior
    Permanent employment

    True Anomaly

    Denver, CO
    2 days ago
  • $110k - $180k

     ...Energy (Nasdaq: AEIS) is a global leader in the design and manufacturing of highly engineered, precision power conversion, measurement and control solutions for mission-critical applications and processes. AE’s power solutions enable customer innovation in complex... 
    Senior
    Full time
    Temporary work
    Work at office
    Flexible hours

    Advanced Energy Industries, Inc

    Denver, CO
    1 day ago
  • $99k - $145k

     ...Infrastructure Solutions (GEIS) division is currently seeking a Regional Application Engineer supporting the commercial and industrial markets as part of...  ...competencies, and all candidates’ privacy rights and data security will be protected in accordance with applicable laws. The... 
    For contractors
    H1b
    Local area
    Remote work
    Visa sponsorship

    Eaton Corporation

    Littleton, CO
    3 hours ago
  •  ...buyers at Fortune 1000 companies to tap into global manufacturing capacity.Xometry is seeking a driven and technically-minded Application Engineer, Injection Molding to join our team. In this role, you'll be a critical link between our customers, sales team, and... 

    Xometry

    Denver, CO
    1 day ago
  • $143.25k - $252.12k

     ...AMER NAS division is currently seeking a Digital Solutions Application Engineer - West Region. This is a home-based position where candidates...  ...related competencies, and all candidates’ privacy rights and data security will be protected in accordance with applicable laws. The... 
    Full time
    Work at office
    Local area
    Work from home
    Relocation package

    Eaton Corporation

    Littleton, CO
    7 hours ago
  •  ...Access Management organization delivers secure, reliable digital identity services...  ...the enterprise. This role is a senior engineering position focused on our PingDirectory-based...  ...automation. The position partners closely with application engineering teams, cybersecurity,... 
    Work experience placement
    Flexible hours

    Kaiser Permanente

    Denver, CO
    7 hours ago
  •  ...Applications Engineer Summary: The Applications Engineer will design, select, and configure pumps and fluid systems, support applications engineering with equipment sizing, pricing, and quoting, provide technical support to sales, service, and customers, manage project... 

    DXP Enterprises

    Englewood, CO
    5 days ago
  • $70k

     ..., Metal Working, Supply Chain Services and Service Centers. Check out our many videos to learn more! Summary: The Applications Engineer will design, select, and configure pumps and fluid systems, support applications engineering with equipment sizing, pricing,... 
    Full time
    Work at office
    Flexible hours
    Shift work

    DXP Enterprises

    Sheridan, CO
    3 days ago
  •  ...Applications Engineer 2 We are from US IT Solutions, an ISO Certified, E-Verify, WMBE Certified organization established in 2005 in CA. Our company is serving various State, Local and County Departments for over 10 years. USITSOL has been helping clients innovate across... 
    Local area

    Tech Marketing

    Denver, CO
    5 days ago
  •  ...Sr. .Net Developer (.Net & SQL) - UIM This role will be part of the development team...  ...architecture and the existing enterprise application UFacts. This role will work and...  ...approaches and leverage best practices in coding, security and documentation. The role will work... 
    Contract work
    For contractors
    Work experience placement

    Advance American Tech, Inc.

    Denver, CO
    12 hours ago
  • $87.9k - $115.12k

     ...Position: Applications Engineer Job Description: What You'll Be Doing: Designs and develops software solutions to meet business requirements. Manages full software development life cycle including testing, implementation, and auditing. Performs product design... 
    Hourly pay
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Monday to Friday

    Arrow Electronics

    Greenwood Village, CO
    5 days ago
  • $91.52k - $128.38k

     ...your colleagues. Fridays, choose your work location, balancing what your work requires. Trane in Denver, CO is hiring for Application Engineer II . In this role, you will be responsible for the equipment portion of various projects including validating the equipment... 
    Hourly pay
    Work experience placement
    Local area
    Work from home

    Trane Technologies

    Denver, CO
    2 days ago
  • $114.6k - $234.6k

     ...transforming the future of healthcare by building secure, scalable, AI-enabled healthcare...  ...combines industry-leading healthcare applications, electronic health records (EHR), healthcare...  .... We're seeking a versatile Software Engineer to contribute across platform... 
    Temporary work
    Flexible hours

    Oracle

    Denver, CO
    2 days ago
  • $114k - $171k

     ...Grumman Space Systems is seeking a Principal or Sr Principal RF Microwave Design Engineer to join our team. This position is based in...  ...PhDMust have an active U.S. Government Top Secret security clearance at time of application, current and within scope, with the ability to... 
    Senior
    Full time
    Relocation
    Shift work

    Northrop Grumman

    Aurora, CO
    2 days ago
  • $150k - $190k

     ...62Apply: JobMolex is seeking a dynamic and proactive Field Application Engineer (FAE) to lead, promote, and resolve all technical and engineering...  ...engineering. A key function of this role is to promote and secure new design wins for high-speed copper products and... 
    Flexible hours

    Molex

    Denver, CO
    3 days ago
  •  ...phases, and provide budgeting/financial flexibility by offering contingent labor as a variable cost.Job DescriptionApplication support Engineer for IP Television, Video delivery stream for partners. Linux System Administration with strong Networking Skills.Backgroundo Sys... 
    Immediate start

    Artech

    Denver, CO
    1 day ago
  • $65k - $85k

     ...chance to make a lasting impact in the communities we serve. We review every application carefully and appreciate your interest in growing your career with our team. The Application Engineer will provide technical support for CFM Engineering Sales and Contractor... 
    Full time
    Temporary work
    For contractors
    Work experience placement
    Casual work
    Work at office
    Local area
    Monday to Friday

    CFM

    Denver, CO
    16 days ago
  • $108k - $158k

    Eaton’s Electrical Engineering Services & Systems Division (EESS) is currently seeking a Service Application Engineer. This role is hybrid from Roseville, CA or Pleasanton, CA...  ...all candidates’ privacy rights and data security will be protected in accordance with applicable... 
    Contract work
    For subcontractor
    H1b
    Local area
    Relocation
    Visa sponsorship

    Eaton Corporation

    Littleton, CO
    3 days ago
  • $71k - $126k

     ...excellence has earned us several prestigious awards, such as Best Engineering Team, Best Company for Diversity, Compensation, and Work-Life...  ...during installation, operation, maintenance or product application or compatibility matters. Interpersonal skills and product... 

    Arista Networks

    Denver, CO
    a month ago
  • $97k - $137k

     ...Systems division is currently seeking a Power Systems Controls Application Engineer.This position is fully remote for candidates residing within...  ...competencies, and all candidates’ privacy rights and data security will be protected in accordance with applicable laws. The... 
    H1b
    Local area
    Remote work
    Visa sponsorship
    Afternoon shift

    Eaton Corporation

    Denver, CO
    1 day ago
  •  ...continents. Angst-Pfister is rapidly expanding its new US entity and is seeking a highly motivated and detail-oriented Sales Application Engineer (SAE) to join our dynamic Sales Team. The SAE must increase sales through growing existing customer accounts along with a... 
    Work at office
    Remote work
    Work from home

    GrabJobs

    Aurora, CO
    3 days ago
  • $70k - $90k

     ...APPLICATION SALES ENGINEER Smarts & Parts Program | Build solutions. Grow relationships. Earn more. TURN YOUR HVAC & CONTROLS EXPERTISE INTO A HIGH-IMPACT SALES CAREER This is not your typical engineering role. You will work directly with contractors and customers... 
    Full time
    For contractors

    Setpoint Systems Corporation

    Littleton, CO
    10 days ago
  •  ...United States Government Space Technology Export Regulations, the applicant must be a U.S. citizen, lawful permanent resident of the U.S.,...  ...team. We are looking to add several Senior Applications Engineer II to our rapidly growing customer-facing team. In this... 
    Senior
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Local area

    CesiumAstro

    Westminster, CO
    3 days ago
  • A leading technology company is seeking a Bilingual Japanese Application Engineer. You will interface with engineering teams in Japan, provide technical support for semiconductor manufacturing, and manage customer relationships. A Bachelor’s Degree in Engineering and 2... 

    Interplace, Inc.

    Denver, CO
    4 days ago
  •  ...others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking an Associate Director, AI Application Engineer to join our Digital Nexus Technology organization. This is a hybrid work opportunity.Responsibilities:Lead a team of... 
    H1b
    Local area

    KPMG

    Denver, CO
    2 days ago
  •  ...Field Applications Engineer (FAE) – US Team Teledyne Technologies Incorporated provides enabling technologies for industrial growth markets that require advanced technology and high reliability. These markets include aerospace and defense, factory automation, air and... 
    Minimum wage
    Work experience placement
    Local area

    Teledyne Vision Solutions

    Englewood, CO
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Application Security Engineer. Be the first to apply!