Staff Application Security Engineer
UniUni
Application Security Engineer
UniUni is a late-stage last-mile logistics company moving millions of parcels across the United States and Canada for some of the largest e-commerce platforms in North America. Our technology is cloud-native on AWS. We hold an active ISO 27001 certification and SOC 2 Type II attestation, and security is central to how we operate and how our customers trust us. This role reports to the Information Security Officer and is based in North America (remote with periodic travel to UniUni hubs).
About the Role
We are hiring an Application Security Engineer to be the senior technical anchor for product and platform security at UniUni. You will set the bar for how we build secure software, embed security into our engineering pipelines, and harden our customer-facing products. You will spend your time shoulder-to-shoulder with engineering, not adjacent to it.
This is a hands-on role. You will write code, review code, build tooling, and lead the technically hardest work across application security, DevSecOps and platform security, and product security. You will set standards that scale, but you will also dig into real systems to find real problems and ship real fixes.
What You'll Do
- Application Security
- Lead threat modeling on new and existing services, focusing on the systems where the risk is real and the architecture is in motion.
- Run our secure code review program, including the design of review playbooks, the hardest reviews yourself, and coaching engineers to catch issues earlier.
- Operate and tune our AppSec tooling stack across SAST, DAST, SCA, and secrets scanning, keeping signal high and noise low.
- Own the third-party penetration testing program in partnership with the ISO, from scoping through findings triage and fix verification.
- Drive standards for authentication, authorization, session management, and API security across our products, and engineer the hard parts yourself when needed.
Platform Security and DevSecOps
- Embed security controls into our CI/CD pipelines so the secure path is the default path: pre-commit checks, build-time scans, signed artifacts, and policy-as-code gates.
- Harden our cloud workloads on AWS, including container and Kubernetes security, secrets management, and runtime protections.
- Codify infrastructure security baselines as IaC and policy (e.g., OPA/Conftest, AWS SCPs, Terraform guardrails) and own the rollout across the platform.
- Partner with the platform team on identity-aware access to infrastructure, including non-human identities, short-lived credentials, and privileged access patterns.
Product Security
- Engineer enterprise SSO (SAML 2.0 and OpenID Connect) into customer-facing products in support of contractual security commitments to enterprise shippers.
- Set the technical direction for API security, including authentication, authorization, rate limiting, abuse prevention, and tenant isolation.
- Drive secure-by-default patterns for data handling in our products, including encryption, key management, and access controls for customer and operational data.
- Be the senior technical voice in customer security reviews when the questions go past what a questionnaire can answer.
Across All of It
- Triage and lead response to application and platform security incidents, including root cause analysis and durable fixes.
- Mentor engineers on secure design and secure coding, and raise the security fluency of the engineering organization through training, office hours, and example.
- Contribute to ISO 27001 and SOC 2 evidence, control design, and audit readiness for the controls you operate.
Qualifications
- 8+ building and securing production software, with the last several focused on application security, product security, or DevSecOps as your primary discipline.
- Deep, demonstrable software engineering ability. You read code fluently across multiple languages, you write production-quality code, and engineers respect your technical judgment.
- Hands-on experience securing AWS workloads at scale, including IAM, networking, container and Kubernetes security, and IaC (Terraform or equivalent).
- Working command of modern AppSec tooling (SAST, DAST, SCA, secrets scanning) and how to deploy it in a CI/CD pipeline without grinding delivery to a halt.
- Strong threat modeling skills and a track record of turning models into shipped controls.
- Practical experience implementing SAML 2.0 and OpenID Connect, and a clear mental model of identity, session, and authorization design
- Experience leading the technical response to security incidents in production environments.
- Ability to influence engineers and engineering leaders without authority. You explain risk in terms that engineers act on, and you partner rather than police.
Nice to Have
- Experience in logistics, supply chain, marketplaces, or other high-volume transactional businesses.
- Background contributing to or maintaining open source security tooling.
- Prior experience supporting ISO 27001 or SOC 2 control design from the engineering side.
- Offensive security background (CTFs, bug bounty, red team) that informs how you think about defense.
- Experience hardening LLM-integrated or AI-powered features in production.
Why This Role
This is a senior IC role with real scope. You will set standards that the engineering organization actually adopts because you will have built them, shipped them, and proved they work. You will report to the Information Security Officer in a security function with executive commitment, a live ISO 27001 certification, and an active SOC 2 Type II attestation, and you will have the autonomy and the mandate to make UniUni's products and platform meaningfully more secure.
$96k - $146k
...technologies in support of U.S. National Security and Defense. For the past forty-five... ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will... ...an immediate opportunity for a talented engineer to support our programs delivering Next-...SuggestedTemporary workFor contractorsWork experience placementImmediate startRemote workFlexible hours$120.25k - $181.25k
...This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Application Security Engineer (Offensive / Red Team) in United States. This is a unique opportunity for an experienced offensive security professional to play...SuggestedRemote jobFull timeFlexible hours- ...MANTECH seeks a motivated, career and customer-oriented Application Security (AppSec) Engineer to join our team in Hanover, MD. The Application Security (AppSec) Engineer will leverage their strong technical background and knowledge to support software assurance...SuggestedWork at office
- ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development...SuggestedFull time
$150k - $160k
...Senior Cybersecurity Engineer (Application Security) The Senior Cybersecurity Engineer (Application Security) is responsible for protecting our... ...details to partners and senior leadership, mentor junior staff, and provide technical direction to the program. Job Responsibilities...SuggestedFor contractorsWork at officeRemote workFlexible hours$180k - $225k
...Senior Application Security Engineer United States - Remote Opportunity About Us Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster...Full timeTemporary workPart timeRemote workWork from homeHome office$67.67 - $112.78 per hour
...Job Description Title : Senior Application Security Engineer Location : Remote Job Type : Contract (12 Months) Compensation : $67.67 - $112.78/hr Industry: Retail --- About the Role We are partnering with a leading enterprise...Contract workRemote work- ...Senior Application Security Engineer Become a founding member of the Application Security team at CookUnity. You'll work closely with disparate groups inside of CookUnity's engineering organization, ranging from our Infrastructure and Software Engineering teams to ensure...Remote workFlexible hours
- ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This...Remote work
- ...Job Title: Senior Application Security Engineer Get AI-powered advice on this job and access more exclusive features. Direct message the job poster from Unisys. Key Skills and Bonuses: Pentest, OWASP, SAST/DAST/IAST. Bonus: LLM, US citizenship preferred, AWS,...Full time
$128k - $181.25k
...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments that...Remote work$160k - $220k
...Join to apply for the Senior Application Security Engineer role at Zip The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally...Full timeHome officeFlexible hours- ...Application Security Engineer Are you looking for a company where your voice is heard? Where you can make a difference? Do you thrive in a fast-paced work environment? Do you wake every morning excited to work with great people and create success together? Then Intermedia...Remote workDay shift
$70.3k - $101.3k
...Application Security Engineer The Application Security Engineer is responsible for embedding security throughout the software development lifecycle (SDLC), leading application security testing, and driving vulnerability remediation efforts. At CivicPlus, we strive...Work experience placementLocal areaImmediate startRemote workFlexible hours- ...I have an opportunity for "Application Security Engineer - REMOTE" and I am looking for a candidate who can join Immediately if you are interested, reply to me with your updated resume or if you could refer someone I would really appreciate it. Position : Application...Immediate startRemote work
$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...foundational hire with a clear path to Staff / Tech Lead as the team grows. What You...Contract workLocal areaRemote work- ...Senior Application Security Engineer Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? We're looking for a very experienced and highly motivated Senior Application Security Engineer to join our team as one of...Hourly payFull timeRemote workFlexible hours
$160k
...Application Security Engineer We believe talent deserves a human touch. Your application will be read by an actual person who's excited to discover the real you. Location: Remote (United States) | Employment Type: Full-Time About the Role We are looking for...Full timeRemote work- ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution...Remote workAll shiftsShift work
$120k - $140k
...Application Security Engineer Location: Fully Remote (East Coast) Clearance: Public Trust, Secret Clearance preferred Employment Type: Full-time Salary: $120,000-$140,000 Role Overview : The Application Security Engineer will support the secure development...Full timeRemote work$125k - $140k
...nobody gets locked out of the financial system. The Opportunity We are seeking a talented and motivated Senior Application Security Engineer with a strong background in AWS and DevOps practices. In this role, you will be responsible for ensuringthe security of...Work at officeLocal areaRemote workFlexible hours- ...SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This...
$125.6k - $172.7k
...Application Security Engineer (Solventum) 3M Health Care is now Solventum At Solventum, we enable better, smarter, safer healthcare to improve lives. As a new company with a long legacy of creating breakthrough solutions for our customers' toughest challenges, we...H1bRemote workRelocation packageFlexible hours- ...Application Security Engineer AMERISAFE is seeking a detail-oriented, productivity driven professional to add to our Excellence Team. The Application... ...and demonstrated ability to effectively communicate with staff, co-workers, management, and external personnel...Work experience placementRemote workWeekend work
$60 - $62 per hour
...talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days...Contract workH1bRemote work$5,250 per month
...innovative technology-driven B2B payments organization seeking a curious, inquisitive, highly skilled and motivated Senior Application Security Engineer to join our team. Our company values collaboration, creativity, and excellence in delivering cutting-edge solutions to...16 hoursFull timeTemporary workLocal areaRemote work$100k - $150k
...Application Security Engineer Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions... ...lunch-and-learns, and onboarding content for engineering staff. Respond to security incidents involving application...Full timeH1bImmediate startRemote workVisa sponsorshipWork visa$180k - $210k
...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling... ...leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own...Work at officeRemote workFlexible hours- ...Find out more about our hiring culture: Dream Team Culture Job Description At ZetaChain, we are seeking a dedicated Protocol Security Engineer to play a pivotal role in fortifying the security of our cutting-edge protocol. You will be deeply involved in the development...Contract workRemote workHome office
- ...Title: Software and Application Security Engineer Location: Lake Mary, Florida - Fully Remote Need to have good experience in Application security as well as a development Background. We are seeking a Sr Software Engineer to join our progressive information...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!
- software engineer staff United States
- staff devops engineer United States
- information technology support assistant United States
- assistant engineer United States
- structural engineering assistant United States
- assistant engineering manager United States
- engineering administrative assistant United States
- staff design engineer United States
- project engineer assistant project manager United States
- technology administrator United States





