Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer

$100k - $140k
Full-time

SOSHACE

Job Summary: 

The Application Security Engineer will help with our Secure Development Lifecycle assurance processes, our security automation technologies, drive the security hardening strategy across our product and respond to current and emerging security threats. This role will contribute tremendously to our Product Security team working with development teams globally to define new security capabilities, and partnering with leaders across the organization to deliver company-wide security initiatives. 

Job Expectations:

  • Drive cross-functional projects and establish cutting-edge security development lifecycle practices

  • Lead security design reviews and threat modeling for new and existing services at iHerb

  • Evaluate, prototype, implement, and operate security-focused tools and services

  • Develop new secure architecture standards, frameworks and patterns spanning multiple layers

  • Understand and analyze emerging security threats, determining applicability to iHerb and proactively implement centralized mitigations

  • Evaluate, prototype, implement, and operate security tools and services (DAST, SAST, SCA...)

  • Maintain a strong knowledge of current security threats and operational best practices

  • Take part in our security assessment, penetration testing and bug bounty programs

  • Participate in security incident response

The duties and responsibilities described above may provide only a partial description of this position. This is not an exhaustive list of all aspects of the job. Other duties and responsibilities not outlined in this document may be added as necessary or desirable, with or without notice.

Knowledge, Skills and Abilities:

Required:

  • Demonstrated technical foundation

  • Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25…)

  • Proficiency implementing SDL process, technology, and automation in a DevOps environment

  • Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection and encryption

  • Excellent problem solving, critical thinking, collaboration and communication skills

  • Experience driving application security training, security champions and awareness campaigns

  • Active contributor to the security community (research, open source, publications…) 

Equipment Knowledge:

  • Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)

Experience Requirements:

Generally requires three (3) plus years of technical security experience at top-tier software companies including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security, and broader cloud computing technologies

Education Requirements: 

Computer Science / Engineering degree or equivalent experience with an ability to translate technical vulnerabilities into organizational risks

Judgment/Reasoning Ability: Able to identify, troubleshoot and resolve problems quickly using sound judgment, poise and diplomacy. Ability to use judgment and reasoning skills, and determine when to escalate issues, as required, in a timely manner.

Physical Demands:  The physical demands described here are representative of those that must be met by a Team Member to successfully perform the essential functions of this job. While performing the duties of this job, the Team Member is regularly required to talk and hear. The Team Member is frequently required to sit, walk, climb stairs, use hands and fingers, bend, stoop and reach with hands and arms. Reaching above shoulder heights, below the waist or lifting as required to file documents or store materials throughout the work day. The Team Member may occasionally lift or move office products and supplies up to 25 pounds. Proper lifting techniques required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Work Environment: The noise in the work environment is usually moderate. Other factors are:

  • Hectic, fast-paced with multi-level distractions

  • Professional, yet casual work environment

  • Office / Warehouse environment

  • Ability to work extended hours as required

#LI-JC1 #LI-REMOTE

The anticipated pay scale for this position can be found below, however the pay range applicable to you may vary by geographic location based on where the job is located or where you work. The final pay offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and years of experience within the job, the type of years and experience within the industry, education, etc. iHerb, LLC is a multi-state employer and this pay scale may not reflect positions that work in other states or locations. Employees (and their families) that meet eligibility criteria as outlined in applicable plan documents are eligible to participate in our medical, dental, vision, and basic life insurance programs and may enroll in our company’s 401(k) plan. Employees will also be eligible for Time Off and Paid Sick Leave pursuant to the company’s policies. Employees will enjoy paid holidays throughout the calendar year. Eligibility requirements for these benefits will be controlled by applicable plan documents. Hired applicant may be awarded Restrict Stock Units and receive annual bonuses pursuant to eligibility and performance criteria defined in the respective plan documents and policies. For more information on iHerb benefits, visit us at  iHerbBenefits.com .

Anticipated Pay Scale:

$100,000—$140,000 USD

Staffing Agency Submission Notice iHerb does not accept unsolicited 3rd party ('Agency') candidates. If you are an Agency, please send any requests to be considered as a supplier in our Vendor Management System to  View email address on codingjobboard.com . Do not contact iHerb employees directly. If requested to work on a role, any Agency candidates would be presented through the internal recruiting organization.

About iHerb  iHerb is on a mission to make health and wellness accessible to all. We offer Earth’s best-curated selection of health and wellness products, at the best possible value, delivered with the most convenient experience. We’re the world’s largest eCommerce platform dedicated to vitamins, minerals, and supplements, and other health and wellness products. For more than 25 years, we’ve been making it simple for people all over the world to purchase the highest quality products. From supplements to skincare to grocery items, we ship over 50,000 products, from over 1,800 brands direct to our customers in 180+ countries. Our vision is to become the #1 destination for health and wellness across the world. With a passion for wellness and a mind for innovative solutions, iHerb team members share a vision for a healthier world that drives them each day. Our 5 Shared Values unite our global team:

Focus on the Customer · Empower Our People · Be Entrepreneurial & Pivot Quickly · Embrace Diversity & Inclusion · Strive for Simplicity

iHerb Benefits  At iHerb, we are dedicated to offering programs designed to help our employees and their families stay healthy, live well, and plan for their financial future. Built on a strong foundation, our programs provide options and upgrades with flexibility, protection, and security in mind. For the comprehensive benefits list, visit  . For our international team members, you may be eligible for benefits depending on the country where you are employed. The Talent Acquisition Partner/local HR representative will go over the benefits you are eligible for. 

iHerb is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment.

Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in Remote vacancy
  • $120.25k - $181.25k

     ...This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Application Security Engineer (Offensive / Red Team) in United States. This is a unique opportunity for an experienced offensive security professional to play... 
    Suggested
    Remote job
    Full time
    Flexible hours

    jobgether

    United States
    5 hours ago
  •  ...A venture-backed tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role focuses on ensuring secure multi-tenancy within Kubernetes, leading threat modeling initiatives, and managing vulnerability lifecycles... 
    Suggested
    Remote work
    Flexible hours

    vCluster

    Saint Louis, MO
    4 days ago
  • $62k - $141k

     ...Job Number: R0231845 Location: Washington,DC,US Share job via: Share Application Security Engineer The Opportunity: Work together with the client and application community to maintain a resilient security posture... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    United States
    4 days ago
  • $160k

     ...Application Security Engineer We believe talent deserves a human touch. Your application will be read by an actual person who's excited to discover the real you. Location: Remote (United States) | Employment Type: Full-Time About the Role We are looking for... 
    Suggested
    Full time
    Remote work

    New Charter Technologies

    United States
    4 days ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Suggested
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    2 days ago
  •  ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution... 
    Remote work
    All shifts
    Shift work

    RegScale

    United States
    3 days ago
  •  ...Application Security Engineer This role is primarily focused on security administration for ERP applications such as Oracle HCM Cloud, PeopleSoft HCM and Peoplesoft Financials. Under general direction, defines, implements, and maintains application security processes... 
    Remote work

    TriOptus LLC

    United States
    9 hours ago
  •  ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a...  ...reimbursement and more. We’re Looking For We are seeking an Application Security Engineer with expertise in Static and Dynamic Application Security... 
    Contract work
    Remote work

    ShorePoint Inc

    Herndon, VA
    7 days ago
  •  ...Application Security Engineer One of our large financial clients is looking for an experienced Application Security Engineer to join their team. If the below requirements fit your skillset, feel free to apply. Duration: Long Term/Multi Year Contract Location:... 
    Long term contract
    Remote work

    Software Technology Inc

    United States
    4 days ago
  • $175k

     ...Overview: Corporate Tools is hiring an Security Engineer for $175,000/year. You will be a traditional company employee. This is a...  ...understanding of security knowledge of testing mobile, native applications, web applications, distributed and database systems ~... 
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours
    Weekend work

    Corporate Tools

    United States
    1 day ago
  • $320k - $405k

     ...whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role: The Application Security team is at the forefront of building security into every phase of... 
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Anthropic

    New York, NY
    3 days ago
  • $130k - $218k

     ...A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants... 
    Remote work

    ConsenSys

    New York, NY
    5 days ago
  •  ...Perform expert-level secure code reviews focusing on OWASP Top 10 and CWE vulnerability...  .... Identify, triage, and remediate application-layer vulnerabilities, including broken...  ...strong relevant experience in software engineering or security operations with a focus on... 
    Remote work

    Crossing Hurdles

    New York, NY
    9 hours ago
  •  ...A leading web platform company is seeking a Senior Application Security Engineer to enhance their secure development practices. This remote role involves collaborating with engineering teams, identifying security vulnerabilities, and leading security initiatives. Candidates... 
    Remote work

    Webflow

    New York, NY
    9 hours ago
  •  ...Senior Application Security Engineer Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web security, applied cryptography, software security vulnerabilities, IAM solutions, including federation... 
    Remote work

    InterSources

    United States
    3 days ago
  • A leading IT staffing firm is seeking an experienced Application Security Engineer for a remote role lasting over 12 months. Candidates should have extensive experience in Static and Dynamic Application Security Testing, along with knowledge of Java, Python, and .NET. Familiarity... 
    Remote work

    Polarits

    Wilmington, DE
    1 day ago
  •  ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This... 
    Remote work

    e.l.f Cosmetics

    United States
    1 day ago
  •  ...Swapcard Security Engineer Swapcard is the leading AI-powered event platform designed to drive revenue growth and foster meaningful connections...  ...tools (eg. Burp Suite). Solid understanding of common application vulnerabilities (OWASP Top 10, SSRF, IDOR, etc.).... 
    Work experience placement
    Remote work
    Work from home

    Swapcard

    United States
    1 day ago
  •  ...Application Security Engineer Client: Securian Financial Location: Remote - Preferrably local to St. Paul, MN (Will consider A+ candidates from permissible locations). The manager sees value in being able to come onsite, but he is open to considering fully remote... 
    Contract work
    Temporary work
    Local area
    Remote work

    Samprasoft

    United States
    9 hours ago
  •  ...A dynamic tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role requires a strong background in application security and Kubernetes, along with proficiency in Go. You will lead security reviews, threat... 
    Remote work
    Flexible hours

    vCluster

    Boston, MA
    7 days ago
  • $150k - $190k

     ...As a Sr. Application Security Engineer at vCluster Labs, you are the architect of trust in our diverse ecosystem. In this role, you will be responsible for the end-to-end security of our product, ensuring that vCluster remains the de facto standard for secure Kubernetes... 
    Remote work
    Flexible hours
    Shift work

    vCluster

    Austin, TX
    7 days ago
  •  ...Must Have:- • Seeking candidates with solid expertise in Manual web application penetration testing and Manual secure code review. • Expertise is performing Manual Test Case Scenarios is a must. • Identification of Vulnerabilities in Source Codes manually is a must... 
    Remote work

    Yochana

    United States
    3 days ago
  • $100k - $150k

     ...Application Security Engineer Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable... 
    Full time
    H1b
    Remote work
    Visa sponsorship

    Bright Vision Technologies

    United States
    2 days ago
  • $180k - $225k

     ...Senior Application Security Engineer United States - Remote Opportunity About Us Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster... 
    Full time
    Temporary work
    Part time
    Remote work
    Work from home
    Home office

    Temporal Technologies

    United States
    9 hours ago
  •  ...Appsecops Engineer The Application Security Engineer is responsible for designing, building, and maintaining the technical infrastructure that enables scalable application security across the organization. This role bridges software engineering and security disciplines... 
    Remote work

    Diverse Lynx

    United States
    3 days ago
  •  ...and maintain $1.21 billion in surplus. Amerisure is hiring!! This role can sit remote . We're looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to... 
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Mutual Insurance Company

    United States
    3 days ago
  • $150k - $160k

     ...Senior Cybersecurity Engineer (Application Security) The Senior Cybersecurity Engineer (Application Security) is responsible for protecting our organization's software applications and services from threats by embedding security practices into the software development... 
    For contractors
    Work at office
    Remote work
    Flexible hours

    United Natural Foods

    United States
    2 days ago
  •  ...A tech startup is looking for a Sr. Application Security Engineer to secure their Kubernetes multi-tenancy solutions. This role involves core product security, threat modeling, and vulnerability management while collaborating on feature development. Ideal candidates will... 
    Remote work
    Flexible hours

    vCluster

    Salt Lake City, UT
    4 days ago
  •  ...pioneering projects, and fast‐tracking careers. Together, we turn ideas into action — let's get started! We invite a Senior Application Security Engineer to join our team remotely . Responsibilities Demonstrated ability to collaborate with other teams to achieve complex... 
    Remote work
    Relocation

    BrainRocket

    Staten Island, NY
    2 days ago
  • $120k - $150k

     ...Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware enterprise...  ...quality patient care. IDEXX is seeking a Senior Application Security Engineer to join our Product & Application Security team... 
    Local area
    Remote work
    Worldwide
    Flexible hours

    IDEXX Laboratories

    United States
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!