Application Security Engineer
New Charter Technologies, Llc
**We believe talent deserves a human touch. Your application will be read by an actual person who’s excited to discover the real you.****Application Security Engineer**Location: Remote (United States) | Employment Type: Full-Time**About the Role**We are looking for an Application Security Engineer to join our product engineering team. You will serve as the named security function for a team building internal tooling for a portfolio of managed service provider companies, with a roadmap toward a public-facing SaaS product. This role sits inside engineering and works closely with developers and information security day to day.The team you are joining is experienced and moves quickly. The right person for this role is comfortable operating as a peer to strong engineers, contributing practical security judgment and ensuring overall security of our solutions. As our product matures toward public availability, you will help ensure our security posture scales with it.You should be comfortable operating in an exploratory, innovation-oriented environment where not everything will become production software. Right-sizing your security posture to the actual risk is a core expectation of this role.**Key Responsibilities****Embedded Security Partnership**• Serve as the primary security resource for engineering teams in direct close coordination with information security teams, advising on design decisions, authentication patterns, and API security as features are built rather than after the fact• Conduct lightweight, developer-friendly threat modeling for new features and services, right-sized to the actual audience and risk profile (internal vs. public-facing)• Lead collaboration between engineering and information security teams through architecture and code reviews with actionable, specific guidance that helps teams ship, not slow down• Responsible for remediation and enforcement of security standards as set forth by the information security team• Define and maintain a tiered security standard that distinguishes expectations for internal tooling vs. production SaaS vs. public-facing products• Engage constructively with the enterprise security organization, translating between compliance and governance language and the engineering team's operational reality**Tooling & Automation**• Responsible for adherence to GitHub Advanced Security (GHAS) configuration and security standards through ongoing tuning across code scanning, secret scanning, Dependabot, and security campaigns within GitHub Enterprise• Integrate security tooling into CI/CD pipelines as policy-as-code feedback loops, not manual gates• Develop and maintain GitHub Actions workflows with reusable, security-enforcing components• Drive remediation velocity metrics and coverage reporting across engineering teams**Cloudflare & Azure Security**• Collaborate with information security teams to assess and secure workloads across both Cloudflare and Azure, including Cloudflare Workers, Access policies, WAF, and Zero Trust for public-facing infrastructure, and Azure security controls (Managed Identities, Key Vault, Defender, IAM) for internal and opco-facing services• Apply platform-appropriate security controls as our architecture spans both environments, calibrating to the risk profile of each workload• Evaluate and harden authentication flows, API security patterns, and service-to-service trust boundaries across Cloudflare and Azure environments• Contribute to container and cloud workload security as infrastructure patterns evolve**Development Contributions**• Contribute to internal security tooling, automation, and integrations using Python and/or Go• Build security utilities such as vulnerability aggregation pipelines, policy enforcement tooling, or developer-facing security dashboards• Collaborate with information security and engineering teams on secure service design patterns, OAuth 2.0/OIDC flows, and API security controls**Compliance & Risk**• Support SOC 2 readiness as the product matures toward public customers, mapping application security controls to Trust Services Criteria• Triage and prioritize vulnerability findings based on actual business risk rather than CVSS scores alone, distinguishing real issues from noise in a SaaS-native environment• Partner with GRC and the enterprise security organization on evidence collection and audit preparation, without allowing compliance prep to dominate engineering time**Required Qualifications**• 7+ years in application security, secure software development, or a closely related discipline• Demonstrated ability to operate as an embedded security partner within engineering, working side by side with developers• Deep, hands-on experience with GitHub Advanced Security or equivalent security tooling, including code scanning, secret scanning, Dependabot, and security policy enforcement within GitHub Enterprise• Experience with threat modeling methodologies (STRIDE, PASTA, or similar) applied to real-world systems, with instinct for right-sizing the process to actual risk• Proficiency in Python and/or Go, comfortable reading, writing, and reviewing production-grade code• Strong command of OWASP Top 10, common vulnerability classes, and secure design principles• Experience securing SaaS or product engineering workloads rather than enterprise IT or perimeter-focused environments• Experience securing workloads on Cloudflare (WAF, Access, Zero Trust, Workers) and Microsoft Azure (IAM, Managed Identities, Key Vault, Defender), with demonstrated depth in one and working familiarity in the other• Solid understanding of container security concepts with hands-on Docker experience• Excellent communication skills, with the ability to translate complex security risk into developer-actionable guidance and executive-level business context• Familiarity with SOC 2 Trust Services Criteria and how application security controls map to compliance requirements**Preferred Qualifications**• Experience with DAST tooling (e.g., OWASP ZAP, Burp Suite Pro) integrated into automated pipelines• Familiarity with infrastructure-as-code security scanning (Terraform or similar)• Experience with API security standards including OAuth 2.0, OpenID Connect, and API gateway security patterns• Relevant certifications such as CSSLP, GWEB, or OSCP• AI/LLM security awareness, with a practical understanding of how AI-powered applications introduce unique security considerations including prompt injection, data exposure, and model supply chain risks• Familiarity with MCP (Model Context Protocol) server architectures and the security implications of LLM-to-tool integrations• Exposure to OWASP Top 10 for LLM Applications or similar emerging AI security frameworks**What Success Looks Like**In this role, success means developers ship more secure code faster, not slower. You earn trust by speaking the language of engineering, making the secure path the easy path, and knowing when to raise a flag versus when to let something ship. You apply proportionate security judgment across a spectrum from exploratory internal tooling to production SaaS, and you never mistake compliance theater for actual security.The ideal candidate brings the depth to identify serious security issues, the engineering credibility to help teams fix them at scale, and the pragmatism to distinguish real risk from noise in a SaaS-native, developer-first environment.**Who We are:**At New Charter, we’re building a caliber of business the IT industry hasn’t yet seen. We are serving small-to-medium sized #J-18808-Ljbffr New Charter Technologies, Llc
- ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development...SuggestedFull time
- ...Because at Valence, the work worth doing is the kind that redefines work itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be...SuggestedFull timeFreelanceWork from home
- ...Application Security Engineer We are seeking an Application Security Engineer who will support our client with ensuring security is integrated into all stages of software development. This role will be responsible for designing and building secure applications while...Suggested
- ...Application Security Engineer | Location: New York, NY or Charlotte, NC | Contract his Application Security Engineer contract role will embed security into the software development lifecycle to protect enterprise applications across web, mobile, and API ecosystems...SuggestedContract work
- ...catch regressions - turning production data into better AI with every release. About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted...SuggestedFlexible hours
$135k - $200k
...defense, intelligence, and commercial applications. We are trusted by our customers to protect... .... The mission of the Application Security Team is to enable developers to be highly... ...important. As an Application Security Engineer, you will be hands-on and have wide-...Work experience placementWork at officeRemote workWork from homeRelocation package- ...Senior Application Security Engineer AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people...Flexible hours
$80 - $85 per hour
...identifying and prioritizing risks specifically related to application security. ? Develop, socialize, and implement security strategies... ...control Requirements Senior Application Security Engineer Mandatory Skills/Experience • 12 years of...Contract workFlexible hours- ...Application Security Engineer - Vulnerability Operations (Mid-Level) Position: Contract Location: NJ/TX/NC Duration: 12+ months Job description: Required Qualifications & Skills: ~ Bachelor's degree in Computer Science,...Contract work
- ...Lead Application Security Engineer We are a specialized technology staffing agency supporting professional and financial services companies. Why do we stand out in technology staffing? We listen and act as advisors for our candidates on how they can best add value,...Work at office
$130k - $218k
A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants...Remote job- ...beacon of truth in global media and we need your help adding fuel to the fire. About the Role Polymarket is looking for an Application Security Engineer to embed security throughout our software development lifecycle. You'll partner directly with product and engineering...Contract workImmediate start
$215k - $230k
A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should...$180k - $225k
Summary Join our dynamic team as a Senior Application Security Engineer, where you’ll play a pivotal role in securing Temporal’s development pipeline, product, and customer execution environment. In this position, you’ll work closely with software engineering teams and...Temporary workRemote workWork from homeHome office- A leading financial services provider is looking for a remote security engineer to enhance application security. You will work across diverse security projects and partner with product teams to protect user trust. Candidates should have at least 5 years of tech experience...Remote job
$140k - $200k
Role As a Senior Application Security Engineer on the Application Security team, you will be a trusted partner to engineering, product, and business teams across Gemini. You will help guide teams to design and build secure products while building systems and culture that...Work at officeRemote workFlexible hours- ...providing a wide range of investment banking, securities, investment management and wealth... ...Strategy by architecting, engineering, deploying and operating technical security... ...agile delivery and adoption of Cloud and application security control implementations by development...Work experience placement
$128k - $181.25k
...capture moments that reflect who they uniquely are. This is an exciting time for Shutterfly and we are looking for a Senior Application Security Engineer to join our team! In this position you will be an integral part of a developing and expanding Application Security...Remote work$130k - $218k
...MetaMask MetaMask aims to create a thriving engineering organization that supports the well‑... ...a cryptographic key manager and web3 application development platform. As this user base... ...us that we keep our users as safe and secure as possible. We are looking for a Senior...Remote workShift work$89k - $130k
Far Coder is hiring a remote Application Security Engineer II to enhance our information security posture. This full-time role focuses on protecting our systems from cyber threats and requires expertise in GraphQL, Azure, and Linux. Applicants should have a Bachelor’s Degree...Remote jobFull time$220k - $350k
Senior Application Security Engineer [Remote-US] remote To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors...Remote jobExtra incomeLocal areaWork from homeHome office- Security | Application Security Engineer SOFTSWISS is growing, and we are seeking a skilled Application Security Engineer to join our team. If you are driven by excellence and share our values, we would love to hear from you. Purpose of the role: Our goal is to make...Local area
$89.3k - $130k
American Specialty Health Incorporated is looking for an Application Security Engineer II to enhance their Information Security team. The role focuses on protecting information assets from cybersecurity threats, ensuring compliance, and coordinating security measures across...Remote jobWork from homeHome office$80 - $90 per hour
...Genesis10 is currently seeking a Fullstack application developer- Hybrid position with a... ...We are seeking a highly skilled engineer who can design and build enterprise applications endtoend while also embedding security into every layer of the SDLC. You will work...Hourly payPermanent employmentContract work3 days per week- Bitwise Asset Management, Inc. is looking for a Staff Application Security Engineer to own the design and implementation of our application security program. This role provides the opportunity to build functions critical to the security of customer-facing products and internal...Remote job
$120.25k - $181.25k
A creative technology company is seeking a Senior Application Security Engineer to lead the Application Security program. Responsibilities include managing a bug bounty program, identifying vulnerabilities, and implementing secure development practices. Candidates should...- ...at massive scale as Adaptive builds the security layer for the AI era. Trusted by... ...protecting organizations from AI-powered social engineering - deepfake phone calls, spear phishing,... ...be best in class. We're looking for an Application Security Engineer to own application...
$190k - $250k
...delivering uncommon value to our investors and shareholders. We are seeking a Director of Application Security to join Apollo’s global Cyber Security & Risk team within Engineering. The leader will define and drive the firm’s application security strategy, strengthening...$10 per hour
...we’re excited about what’s ahead. About the Role: Our engineering organization is growing, and with that growth comes an expanding application and infrastructure footprint that requires dedicated application security ownership. This role exists to build that function...Full timeTemporary workFor contractorsWork at officeRemote workVisa sponsorshipFlexible hours$176.53k - $264.8k
Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries around the... ...looking for a hands‑on Principal Application Security Engineer to lead our Secure Development Lifecycle assurance...Local areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- application system engineer New York, NY
- junior application support engineer New York, NY
- hydraulic application engineer New York, NY
- senior application security engineer New York, NY
- application performance engineer New York, NY
- application engineer New York, NY
- application engineering manager New York, NY
- network applications engineer New York, NY
- cnc applications engineer New York, NY
- field applications engineer New York, NY


