Sr. Application Security Engineer
$130k - $190kjobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States.
This is a highly technical Application Security role focused on protecting software products, APIs, and cloud-native applications throughout the development lifecycle.
You will work hands-on with Java, Python, and Go codebases to identify vulnerabilities, trace root causes, assess exploitability, and guide secure remediation.
The role bridges Information Security and Engineering, giving you significant ownership while keeping you deeply connected to software development teams.
You will help strengthen the Secure SDLC through security gates, threat modeling, automated controls, and developer-focused security workflows.
The position also covers SAST, DAST, SCA, API security, dependency risk, cloud-native architectures, and hands-on vulnerability validation.
Beyond addressing individual findings, you will build preventative controls and secure coding practices that reduce recurring vulnerability classes.
This opportunity is ideal for an experienced Application Security professional who enjoys solving complex technical problems and influencing engineering teams through practical security expertise.
Accountabilities: As a Sr. Application Security Engineer , you will serve as a hands-on technical authority for application security, partnering closely with Engineering and Security teams to identify risks, drive remediation, and embed security into development practices.
Perform hands-on security analysis of applications, APIs, services, and supporting components.
Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths.
Reproduce and validate vulnerabilities independently, assessing exploitability, reachability, exposure, data sensitivity, business criticality, and compensating controls.
Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure.
Maintain remediation SLAs and escalate unresolved Critical and High findings when appropriate.
Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities.
Mature security gates and review checkpoints across architecture, design, sprint, and release processes.
Integrate preventative security controls into developer workflows and CI/CD pipelines.
Configure, operate, and tune SAST, DAST, and SCA tooling to deliver actionable security feedback.
Assess software dependency and supply-chain risks using application context, reachability, exploitability, and remediation options.
Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies.
Review authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, data flows, trust boundaries, cryptographic controls, and abuse scenarios.
Evaluate application security across AWS, Kubernetes/EKS, containers, Linux/Ubuntu, distributed services, and cloud-native architectures.
Partner with Engineering as a technical advisor, providing clear and actionable remediation guidance.
Deliver secure-coding guidance and training based on real vulnerabilities and recurring security patterns.
Help establish and mature a Security Champions program across development teams.
Create security runbooks, standards, and reusable development patterns that teams can apply independently.
Validate application and API vulnerabilities through hands-on testing and coordinate external penetration-testing engagements.
Drive first-year improvements in vulnerability remediation, threat modeling, dependency security, secure development practices, and the overall effectiveness of the Application Security function.
Requirements The role requires deep Application Security expertise combined with strong software engineering capabilities, hands-on vulnerability analysis, and the ability to collaborate effectively with technical and engineering leadership.
7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
Strong hands-on coding and secure code review experience with Java, Python, and Go.
Ability to read, debug, and reason about production application code and communicate technical findings clearly to software engineers.
Proven ability to reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
Hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows.
Strong knowledge of software dependency and supply-chain security.
Experience prioritizing vulnerabilities based on application and business context rather than scanner severity alone.
Strong understanding of the OWASP Top 10 and OWASP API Security risks.
Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
Strong communication and collaboration skills, with the ability to influence developers, architects, and engineering leadership.
Hands-on application and API penetration-testing experience is preferred.
Experience in financial services, fintech, identity, fraud, regulated SaaS, or other highly regulated environments is a plus.
Familiarity with PCI-DSS application security requirements is preferred.
Experience building or leading a Security Champions program is a plus.
Experience developing Application Security automation or internal security tooling is desirable.
OSCP, GWEB, CSSLP, or a similar technical security certification is preferred.
Benefits Salary: $130,000–$190,000 per year, with individual compensation varying based on experience, professional competencies, and geographic differentials.
Remote flexibility: A virtual-first working environment designed to support remote work from a home office as well as in-person collaboration.
Career growth: Opportunities for professional development, meaningful technical ownership, and work in an innovative, collaborative environment.
Healthcare: Universal, supplemental, or private healthcare plan options depending on geographic location.
Financial future: Retirement or pension contributions and participation in a stock plan.
Income protection: Life event and disability coverage.
Paid time off: Generous annual leave, company holidays, and volunteer time off.
Learning: E-learning resources, tuition reimbursement, and opportunities to participate in hackathons.
Home office: Home office setup allowance.
Additional benefits: Optional benefits may include pet insurance, identity theft protection, and legal assistance.
Technical scope: Exposure to internet-facing financial software, complex API integrations, cloud-native environments, and a dual US/EU regulatory context.
Visibility and ownership: Direct collaboration with senior Security and Engineering leadership and meaningful ownership of Application Security initiatives.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Sr. Application Security Engineer in New York, NY vacancy
$100.63k - $167.79k
...Sr. Application Security Engineer Where Ambition Meets Innovation Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you'll...SeniorWork from home$130k - $190k
...that a workforce reflecting the richness of our communities and customers helps us better serve their needs. The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security...SeniorRemote workWork from homeWorldwideHome office- ...partnered with a Financial Services firm in search for an Application Security professional to join their team. Responsibilities: Conduct... ...: Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent Certifications: CISSP, CEH,...SeniorFull timeVisa sponsorship
$121.4k - $166.7k
...industry.Rockstar is on the lookout for a passionate Senior Security Platform Engineer who is skilled at diving into complex software designs to... ...in Downtown Manhattan. WHAT WE DOThe Rockstar Games Application Security team partners with numerous development teams across...SeniorFull timeWork at office- The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software...Senior
- Estée Lauder Companies in New York seeks an experienced Application Security professional to lead secure SDLC initiatives, DevSecOps integration... ...and partners. This role emphasizes collaboration with IT, engineering, and security stakeholders to implement threat modeling,...Senior
$1,000 per month
...and keep building AI fluency in ways that support their role and our mission. Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role...SeniorFull timeWork experience placementRemote workWorldwide- ...across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...you! ABOUT THE ROLE We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across engineering...SeniorWork at officeWork from homeVisa sponsorshipWork visa
$192k - $240k
...support you need to grow your career. Engineering at Brex Engineering at Brex is about building... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...become leaders. What you’ll do As a Senior Application Security Engineer, you will focus on...SeniorRemote jobWork experience placement$169k - $220k
...lower cost through early diagnosis and longitudinal care management of chronic conditions. We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team,...SeniorWork experience placementWork at officeRemote workFlexible hours$190k - $237k
...more, and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing...SeniorWorldwideFlexible hours$160.3k - $240.5k
...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top... ...millions of creators and their users. We are seeking a Senior Application Security Engineer with profound expertise in application security. In this...SeniorWork at officeWorldwide$100k - $258k
...knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who... ...teammates.ABOUT THE ROLE:We are seeking a skilled and innovative Application Security Engineer to join ð Money. In this role, you will protect...Permanent employmentTemporary work$150 per hour
A financial firm is looking for an Application Security Engineer to join their team in Iselin, NJ or NYC.Compensation: $150-200kResponsibilities:Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknessesTriage...- ...SaaS Security Engineer 6–9 Month Contract | Potential Extension Hybrid – New York City | 2–3 Days/Week Onsite Overview Our client... ...help strengthen the security posture of its critical SaaS applications. This role will focus heavily on SaaS Security Posture...Contract work2 days per week3 days per week
$244k - $305k
As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently...- ...Application Security Engineer ALPHARETTA OR NYC (2 roles) 12 months+ Department: Cloud Security & Developer Enablement, CDRR What You'll Do: Be part of a team of engineers to implement Brokerage specific security policies in the CI/CD security...Work experience placement
- ...Because at Valence, the work worth doing is the kind that redefines work itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be...Full timeFreelanceWork from home
- ...Senior Application Security Engineer with Hands on Python Location- Princeton, NJ & NYC, NY (Hybrid) • 8-15+ years in software engineering and application security, with substantial hands-on development experience (not security-adjacent - you've shipped code...
$180k - $258k
...Product Security Engineer We are looking for a Product Security Engineer to join our team and act as a champion for security within our... ...security engineering, specifically focusing on product security or application security. Technical Skills: Proficiency in one or...Shift work- ...SpaceXAI is seeking an Application Security Engineer to protect the security and integrity of payments and financial products across the software development lifecycle. You will oversee code security, secure CI/CD practices, and SBOM‑driven supply chain controls while...
- ...Job Title: Application Security Engineer Client: JPMC Employment Type: W2 Contract Location: Albany, NY Hybrid Job Summary JPMC is seeking an experienced Application Security Engineer to work closely with development teams on enterprise Java...Contract work
- Overview Application Security Engineer Remote within the US US Citizen Approximately 8 Month Contract (w/ possible extensions) Summary The Application Security Engineer candidate will have a strong background in cybersecurity and understanding of web application and zero...Contract workRemote work
$82k - $118k
...available while providing a level of professionalism and service unsurpassed in the lending industry. Position Summary The Application Security Engineer at Guild Mortgage supports the security of our applications, including AI-enabled applications and services. Working...Minimum wageWork at officeLocal areaWork from homeMonday to FridayShift work$200k - $235k
...our New York City office to support collaborative team dynamics and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security strategy. This role focuses on securing high-growth FinTech and...SeniorFull timeWork at officeWorldwide$75.2k - $158.1k
Job Title: Application Security Engineer Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local * * * The Opportunity: Join a mission‑driven...Full timeContract workWork experience placementInterim roleLocal areaFlexible hours$177k - $225k
...Pacific Standard time zone** Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a... ...looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance...Remote work- Driving the technical direction for application security and vulnerability management programs, the full-time Staff Application Security Engineer will work remotely within the US (excluding specific metro areas) to lead strategy, improve processes, and mentor engineers...Full timeRemote work
$220k - $250k
...headquartered in New York City with offices around the world. To learn more, go to About the Role We’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices, intelligent...$120.38k - $192.6k
...location. Relocation assistance: is not available for this opportunity. Requisition #: 76525 The Role at a Glance The Lead Application Security Engineer is responsible for working with application development and infrastructure teams to ensure applications are designed,...Work experience placementWork at officeRemote workWork from homeRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Application Security Engineer. Be the first to apply!
Related searches
- application security engineer New York, NY
- field applications engineer New York, NY
- application engineer New York, NY
- application engineering manager New York, NY
- application operations engineer New York, NY
- application performance engineer New York, NY
- technical application engineer New York, NY
- project application engineer New York, NY
- junior application support engineer New York, NY
- network applications engineer New York, NY




