Lead Cybersecurity - Application Security Engineer - Dynamic, Runtime & API Security
$128.4k - $192.6kAT&T
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered. Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it. We are seeking an Application Security Engineer to strengthen the security of our applications and APIs through a combination of dynamic application security testing (DAST), runtime application self-protection (RASP), and API security engineering. This is an application security engineering role, not a traditional security operations position. The ideal candidate is a security-minded engineer with strong hands-on experience in web application and API security, who understands modern application attacks and can translate that understanding into practical testing, protection, and remediation strategies. This role sits at the intersection of AppSec engineering and production defense, with responsibility for identifying exploitable vulnerabilities both before deployment and while applications are running in production, reducing risk from active attacks, misuse, and exposed application behavior. This candidate will also evaluate and implement AI-assisted security capabilities to improve coverage, prioritization, and speed — such as intelligent scan orchestration, alert triage, anomaly detection for API abuse, and developer-facing remediation guidance — while ensuring results are valid, measurable, explainable, and safe for production use. Job Summary: You will own and scale dynamic security capabilities across the Software Delivery Lifecycle (SDLC) and production, with a strong emphasis on: DAST automation and integration into CI/CD pipelines RASP and in-process runtime protection (e.g., JVM/.NET CLR instrumentation) API Security engineering for internal and external/internet-facing endpoints, including edge/API gateway protections and continuous API discovery (shadow/zombie APIs) This role is best suited for a candidate with an application security mindset first: someone who can assess real-world exploitability, validate findings, work directly with developers on durable remediation, and build or extend automation in code when existing tooling does not fully solve the problem. You’ll partner closely with security teams, platform teams, and developers to define policy, deploy controls safely, tune security tool detections, reduce false positives, and measurably improve security outcomes. Detailed Job Description: This role focuses on active defense for web applications and APIs through a combination of security testing, runtime instrumentation, and API protection. The candidate will help design and mature security programs that combine: Dynamic application and API testing to identify exploitable vulnerabilities, logic weaknesses, and misconfigurations as early as possible Runtime protection and instrumentation via runtime security principals and tools such as RASP to detect and, where appropriate, block exploit attempts in production, with an emphasis on protecting API traffic, application workflows, and business logic API security capabilities such as API gateway onboarding and policy enforcement, abuse prevention (e.g., scraping/bots), technical reviews and deep-dives, and continuous discovery of undocumented, unmanaged, or exposed APIs Success in this role requires deep application security knowledge — including web and API attack patterns, authentication and authorization weaknesses, exploitability analysis, and vulnerability remediation — as well as ability to script, automate, integrate, and build lightweight solutions when commercial tooling is insufficient. The right candidate will be comfortable moving between hands-on security testing, technical analysis, developer partnership, and security engineering automation, with a focus on reducing meaningful application risk. Key Responsibilities: AI-Assisted Security Engineering Identify practical opportunities to apply AI-assisted approaches across DAST, API testing, runtime telemetry, and security workflows (e.g., prioritization, correlation, anomaly detection, automated enrichment, and remediation support). Implement AI-enabled workflows to reduce false positives, improve triage efficiency, and accelerate remediation (e.g., intelligent deduplication, exploitability scoring, and auto-generated developer guidance with human review). Partner with platform and engineering teams to integrate AI-assisted and automated security capabilities into pipelines and operational processes in a measurable, repeatable, and secure way. DAST & Dynamic Testing (Scale and Automation) Own the DAST lifecycle, including onboarding, authenticated scanning, scan orchestration, environment readiness, tuning, and false-positive reduction. Integrate DAST and automated API testing into CI/CD pipelines using repeatable, maintainable security-as-code patterns. Create standards and runbooks for scan profiles, test data, authentication/session handling, and release readiness criteria. Perform triage and validate exploitability of findings, distinguishing between theoretical issues and meaningful application risk. Translate findings into clear, actionable developer remediation guidance, and partner with teams to verify effective fixes. API Security Engineering (Internet-Facing, Gateway, Discovery) Partner with API gateway and edge teams to implement and tune security controls such as schema/contract validation, request filtering, threat protections, rate limiting, and throttling. Drive API discovery and inventory capabilities to identify and govern “shadow” and “zombie” APIs and establish processes to bring them under security review and lifecycle management. Perform and automate security testing aligned to the OWASP API Security Top 10, including authorization failures such as BOLA/BFLA. Assess API exposure and abuse risk, including authentication/authorization weaknesses, object access patterns, input validation issues, data leakage, and business logic abuse. Help implement protections against abuse of exposed endpoints, including bot/automation defenses, scraping prevention, and volumetric misuse controls. RASP & Runtime Active Defense (In-Process Instrumentation) Deploy, configure, and tune runtime security solutions (such as RASP) integrated into application runtimes (e.g., JVM, .NET CLR) to monitor execution and defend against attacks in production. Establish safe rollout patterns (detect-only → tuned detection → selective enforcement), with guardrails to minimize performance impact and avoid breaking application behavior. Analyze runtime telemetry to identify attack patterns such as injection attempts, exploitation chains, abnormal access behavior, and policy violations. Tune runtime protections based on observed application behavior and threat patterns, with a focus on reducing exploitability while supporting development teams in achieving long-term remediation. Collaborate closely with developers and architects to ensure runtime protections complement, rather than replace, secure design and code-level fixes. Security Engineering & Collaboration Build and maintain metrics that reflect meaningful security outcomes, such as coverage, false-positive rate, exploit validation rate, time-to-triage, and time-to-remediation. Develop automation, integrations, scripts, and lightweight internal tooling to improve testing coverage, reduce manual effort, and extend security capabilities where needed. Create documentation, templates, and self-service enablement that help engineering teams adopt secure patterns and scale security practices. Support application/API-related security investigations by providing technical analysis, exploit context, and remediation guidance. Qualifications / Requirements / Skills: 5+ years (or equivalent) of experience in application security, product security, offensive security, or secure software engineering with strong hands-on technical depth. Strong hands-on experience in web application and API security, including vulnerability identification, exploit validation, remediation support, and secure design considerations. Demonstrated ability to evaluate, implement, and operationalize AI-assisted security tooling/workflows (build vs. buy), with a focus on measurable improvements in signal quality, coverage, and remediation efficiency. Demonstrated experience scaling DAST and automated dynamic testing, including authenticated scanning, scan tuning, and CI/CD integration. Strong expertise in API security, including OAuth2/OIDC, JWT, API gateways, authorization testing, and testing techniques for REST and GraphQL APIs. Practical experience implementing and tuning RASP or similar in-process runtime protections in production environments. Deep understanding of the OWASP Top 10 and OWASP API Security Top 10, especially authorization failures (BOLA/BFLA), injection, SSRF, deserialization, security misconfiguration, and business logic abuse. Ability to write code and build technical solutions to automate workflows, develop integrations, create test harnesses/utilities, or build lightweight internal security tools when needed. Proficiency in one or more scripting/programming languages such as Python, Go, JavaScript, or Bash, with demonstrated ability to apply coding skills to security engineering problems. Strong understanding of modern application architectures, including APIs, microservices, cloud-native design patterns, authentication flows, and runtime environments. Working knowledge of cloud-native platforms and production concepts (containers, Kubernetes, observability/logging/tracing), with the ability to use that knowledge in support of application security engineering. Strong communication skills and the ability to translate security findings into clear, prioritized engineering actions for developers and stakeholders. Nice-to-Haves / Preferred or Desired Skills: Experience developing internal security tools, custom integrations, reusable libraries, or testing frameworks to extend AppSec capabilities. Background in offensive security, adversarial testing, bug bounty, web exploitation, or vulnerability research. Experience applying analytics/ML concepts to security telemetry (behavior baselining, anomaly detection, clustering/deduplication) for APIs and runtime signals. Familiarity with AI-assisted secure SDLC use cases such as code/query generation for test cases, guided threat modeling, and intelligent fuzzing, with strong validation practices. Experience defining quality metrics for AI outputs (precision/recall proxies, FP/FN tracking, drift detection) and operating feedback loops. Experience with API discovery platforms and managing shadow/zombie API reduction programs (inventory, ownership, governance workflows). Hands-on experience with GraphQL-specific risks, including introspection exposure, depth/complexity attacks, and field-level authorization weaknesses. Experience designing safe enforcement strategies for production protections, including progressive rollout, canarying, SLO awareness, and performance testing. Familiarity with service mesh patterns (mTLS, traffic policies) and edge protections (WAF/WAAP concepts) as they relate to API protection. Relevant certifications such as OSWE, GIAC GWAPT/GWEB, or similar hands-on application security credentials. Supervisor: No Our Lead Cybersecurity earns between $128,400-$192,600 USD Annual Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training. Joining our team comes with amazing perks and benefits: Medical/Dental/Vision coverage 401(k) plan Tuition reimbursement program Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays) Paid Parental Leave Paid Caregiver Leave Additional sick leave beyond what state and local law require may be available but is unprotected Adoption Reimbursement Disability Benefits (short term and long term) Life and Accidental Death Insurance Supplemental benefit programs: critical illness/accident hospital indemnity/group legal Employee Assistance Programs (EAP) Extensive employee wellness programs Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone. #LI-Onsite – Full-time office role- Ready to join our team? Apply today Our Lead Cybersecurity jobs earn between $141,300.00 - $237,400.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training. Joining our team comes with amazing perks and benefits: Medical/Dental/Vision coverage 401(k) plan Tuition reimbursement program Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays) Paid Parental Leave Paid Caregiver Leave Additional sick leave beyond what state and local law require may be available but is unprotected Adoption Reimbursement Disability Benefits (short term and long term) Life and Accidental Death Insurance Supplemental benefit programs: critical illness/accident hospital indemnity/group legal Employee Assistance Programs (EAP) Extensive employee wellness programs Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone Weekly Hours: 40 Time Type: Regular Location: Alpharetta, Georgia, Atlanta, Georgia, Bedminster, New Jersey, Bothell, Washington, Dallas, Texas, Middletown, New Jersey, USA:NC:Charlotte / Research Dr - Dat:9139 Research Dr Salary Range: $141,300.00 - $237,400.00 It is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made. We are pioneers of making connections and have been ever since Alexander Graham Bell invented the telephone and founded our company. That was nearly 150 years ago, and we haven’t stopped innovating since. At our core, we help bring families, communities, and businesses together with the products and services they need to thrive every day. From the widespread and growing availability of 5G and Fiber to working on things we once only dreamed of—at AT&T, we create connections that change the world.
$85k - $165k
Nuclear Physical Security Design Engineer Due to continued growth... ...join our team. In this dynamic role, you'll forge... ...Security, while leading engineering efforts... ...process computer, and cybersecurity systems Nuclear plant... ...skills, and education. Applicants must be legally...SuggestedFull timeContract workPart timeImmediate startRemote workWork visa- ...world. Our Chief Security Office ensures... ...and master cybersecurity to stay ahead... ...are seeking an Application Security Architect... ...model-serving APIs, and AI... ...with AI security engineering to reduce risk... ...governance - and lead AI Security... ...deployment, and runtime validation....SuggestedFull timeWork at officeRelocation
- ...for an experienced and driven Senior Security Test Engineer to join our awesome Engineering team.... ...parts of our SDLC, including DAST, SCA, API, and penetration testing. Perform security... ...security vulnerabilities in complex applications, including the ability to reproduce...SuggestedWork from homeMonday to Friday
- Index Engines is seeking a Senior Security Test Engineer to enhance the security of its CyberSense product. Responsibilities include developing a security testing strategy, performing security assessments, and collaborating with engineering teams. Ideal candidates have...SuggestedWork from home
- ...Network security engineer Location: Working on-site in Middletown, NJ - Local Candidates... .... Root Cause Analysis (RCA): Lead systematic RCA sessions and facilitate... ...systems involving multiple integrated applications and cross-functional teams. SAFe Agile...SuggestedPermanent employmentTemporary workLocal areaImmediate start
$85k - $165k
A leading engineering company is seeking a Nuclear Physical Security Design Engineer. In this role, you'll build strong relationships with clients while providing engineering leadership in Physical Security solutions. Ideal candidates have a Bachelor's degree and 6+ years...Remote jobFull timeContract workPart time- ...Principal Cyber Security Engineer Highly skilled Principal Cyber Security Engineer with expertise in reverse engineering and cybersecurity product development is needed for our Monmouth County, NJ based client. This senior-level position requires deep technical...
- ...Creative Solutions Services, LLC is looking for a Microsoft Dynamics 365 & .NET FS Developer for a contract role based in Middletown Township... ...like C#, Dynamics 365, and React. Responsibilities include leading project teams, developing system documentation, and...Contract workRemote work
- ...Middletown Township, PA is seeking a SAP Security / GRC Consultant to join their... ...ensuring compliance with audit requirements. Applicants should have 3-7 years of experience in SAP... ...for training and collaboration within a dynamic team. #J-18808-Ljbffr Data-Core Systems...
$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Keyport. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training to...Shift workNight shiftWeekend work$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Navesink. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training to...Shift workNight shiftWeekend work$112k - $179k
...Full-Stack Software Engineer Job Locations... ...of the application and its users, proactively... ...maintain REST APIs and containerized... ...pipeline experience Cybersecurity best practices in... ...national security company that drives... .... As the world's leading mission capability...Contract workLocal areaShift work- Job Title: MS Dynamics CE CRM Functional Lead Duration: Long Term Location: Middletown, PA (Hybrid) Job... ..., integrating with Contact Center applications and self-service portals. Collaborate... .... Experience as a CE Data Engineer in at least 2 implementation projects...Work at office
- Creative Solutions Services, LLC is seeking a CRM Functional Lead for a long-term position. The role primarily involves defining technical requirements and delivering solutions using Dynamics 365 CE. Candidates should have over 7 years of experience in this area, with...Remote job
- ...managing and deploying containerized applications using Redhat OpenShift... ...vulnerabilities identified in the Static/Dynamic scan & container registry scans... ...relevant administrator duties. Secure access to the Elasticsearch cluster, its data, and APIs according to required access...For contractors
- ...Job Description We are currently seeking for a Network Security Engineer with a minimum of 3-5 years of hands-on experience. Manage our... ...switches. Engage with Engineering, Medical, PCI Compliance and application development teams to determine segmentation requirements....Remote workAfternoon shift
- Creative Solutions Services, LLC is hiring for a CE Functional Lead/Architect to assist with Dynamics 365 CE project implementations. This long-term position is primarily remote, requiring occasional onsite presence in Middletown, PA. The ideal candidate will have significant...Remote job
- Creative Solutions Services, LLC is seeking an MS Dynamics CE CRM Functional Lead to define functional and technical requirements for Dynamics 365 CE. The role involves working closely with technical teams and conducting comprehensive analyses. The ideal candidate will...
- ...SAP BRIM & Microsoft Dynamics CE. Data-Core Systems... ...implementation of complex applications, often using new... ...source systems. Develop APIs, interfaces, and integration... ...enterprise coding and security standards.... ...planning and charging engine optimization initiatives...For contractors
- ...SAP BRIM & Microsoft Dynamics CE. Data-Core Systems... ...implementation of complex applications, often using new... ...interfaces, workflows, forms, APIs, and automation... ...development standards, security requirements, and governance... ...Information Systems. Engineering. Related technical...Contract work
$92.6k - $231.6k
...**Senior Software Engineer, Throtle (an IQVIA... ...high-performance applications that power our core... ...distributed services* Lead technical design... ...services and APIs using Python and/or... ...ensure scalability, security, and performance*... ...in a fast-paced, dynamic environment* Passion...Full timePart timeImmediate startWorldwide- A leading enterprise communications organization is seeking a Voice Solutions Architect to design and implement large-scale cloud-based... ...+ years in contact center architecture, expertise in Microsoft Dynamics, and a strong understanding of PCI compliance. This remote...Remote job
- Data-Core System, Inc. is seeking a Junior MS Dynamics CRM Data Migration Developer who will contribute to the design, development, and implementation of data migration solutions. The role involves working with KingswaySoft and Microsoft SQL Server Integration Services...
- ...solution based on SAP BRIM & Microsoft Dynamics CE. Junior MS Dynamics CRM Data Migration... ..., and implementation of complex applications, often using new technologies. You will... ...Computer Science, Information Systems, Engineering, or related field preferred. Equivalent...
$95.17k - $156.36k
As a Senior Software Engineer, you will develop and execute... ...of the Enterprise API Technology Services strategy... ...and execute modern application platform roadmap ensuring... .... Experience with secure programming practices,... ...accelerate impact and lead change. You will As part...Full timeWork at officeFlexible hours3 days per week- ...Mobile Developer to join us. JOB REQUIREMENTS: Develop mobile applications/components based on documented requirements Develop mobile application... ..., and App Store deployment Knowledge of mobile application security Knowledge of writing automated unit tests Knowledge of...Visa sponsorshipWork visa
- ...for a Full Stack Software Engineer to join our DevOps team... ...design, develop and test applications for internal software systems... ...the customer’s industry leading automation and technology... ...and maintain scalable, secure, high-performance RESTful APIs and backend services. Develop...Worldwide
- Senior DevOps Engineer Azure Healthcare SaaS 2025/11/10... ...other mature operators, a dynamic but still laid-back... ...native capabilities and lead full implementation Migrate... ...templates, integrate security scanning (SAST/DAST),... ...staging slots, Azure SQL, API Management, App Gateway...Immediate startFlexible hoursNight shift
- .... Integrate systems using APIs and automation tools. Collaborate... ...focusing on design patterns, security, and performance.... ...debugging scripts. Work with leads and architects to refine requirements... ...Computer Science, Software Engineering, or a related field. 10 15...Work from home
- ...operations. The successful candidate will conduct systems analysis, project leadership, and security oversight while ensuring compliance with state regulations. Suitable applicants must have solid IT experience, including technical roles and relevant education. #J-18808...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cybersecurity - Application Security Engineer - Dynamic, Runtime & API Security. Be the first to apply!
- senior application security Middletown, NJ
- director of enterprise application services Middletown, NJ
- cash app Middletown, NJ
- application team lead Middletown, NJ
- app support Middletown, NJ
- now accepting applications Middletown, NJ
- application development Middletown, NJ
- director enterprise applications Middletown, NJ
- cash application representative Middletown, NJ
- app Middletown, NJ


