Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer

Salmon Group Inc

The Role

You'll own application security across our mobile banking platform, payments stack, and a growing set of regulated products. The work is hands-on, you'll conduct a threat modeling, security reviews, CI/CD tooling - with real process ownership. You'll report to the Group CISO and work closely with both our engineering teams and the Bank IS function.

Justification

As Salmon expands its product lineup like cards, payments, ATM network - the need for a dedicated Application Security function has become critical. Currently there is no specialist owning secure development practices, mobile security testing, or supply chain risk.

This role fills gap: ensuring internal systems and customer data are protected, embedding security into the product delivery process, and building the AppSec practices needed to meet regulatory expectations and support secure growth.

Responsibilities

Risk-driven security ownership

  • Identify which systems, data flows, and product changes carry the highest real-world risk and build your work around that, not around tool coverage or compliance checklists
  • Decide when a security gate is worth slowing down a release and when it isn't, own that call, and be able to explain it to engineering and the CISO
  • Maintain a risk register for application-layer exposures: what's open, what's accepted, what's being fixed, and why in that order

Secure SDLC

  • Figure out where in our delivery process security decisions are actually being made and put controls there
  • Run threat modeling for high-stakes product changes before design is locked, not after
  • Build a mobile security testing baseline that the team runs themselves

CI/CD and supply chain

  • Assess what the current pipeline actually catches versus what it produces as noise, and fix the ratio before adding more scanners
  • Own supply chain posture: dependency pinning, SBOM, internal registry, and the response process when a package gets compromised
  • Own secrets detection and remediation end-to-end

Regulatory and cross-team work

  • Translate application security gaps into language that satisfies BSP examiners without over-engineering the evidence
  • Coordinate security input into new product launches across our Group and Bank structure
Requirements

Experience

  • 7+ years in application security, with meaningful ownership over both technical work and process
  • Has built or substantially improved a secure SDLC in a fast-moving product org
  • Has run threat modeling on real product features and influenced design decisions as a result
  • Has owned vulnerability management end-to-end: triage, remediation tracking, SLA management, risk acceptance
  • Has done hands-on mobile security testing (iOS and/or Android) in a production context, not just UAT
  • Understands modern supply chain attack vectors like compromised packages (npm, PyPI), malicious IDE plugins, typosquatting, dependency confusion - and knows how to reduce exposure at the tooling and process level
  • Comfortable writing Python or Bash to automate repetitive security work

Technical skills

  • SAST, DAST, SCA in CI/CD pipelines: knows how to tune for signal, not just coverage
  • API security: authentication flows, token handling, common abuse patterns
  • Mobile security: OWASP ASVS/MASVS applied in practice
  • Supply chain: SBOM generation and dependency risk management
  • Secrets management: detection, remediation, and structural prevention
  • Working knowledge of AWS and containers sufficient to understand where application risks extend into infrastructure

Nice to have

  • Experience in a regulated environment (financial services or similar)
  • Familiarity with PCI-DSS, ISO 27001, or BSP MORB
  • Certifications: OSCP, GWEB, GWAPT, CSSLP

Communication

  • Strong written English; most day-to-day alignment is async
  • Can explain a security issue clearly to an engineer and summarize the same issue for a non-technical stakeholder
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in United States vacancy
  •  ...MANTECH seeks a motivated, career and customer-oriented Application Security (AppSec) Engineer to join our team in Hanover, MD. The Application Security (AppSec) Engineer will leverage their strong technical background and knowledge to support software assurance... 
    Suggested
    Work at office

    MANTECH

    Hanover, MD
    4 hours ago
  • $190k - $273k

     ...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This is a senior-level individual contributor role focused on strengthening... 
    Suggested
    Remote job
    Full time
    Temporary work
    Flexible hours

    jobgether

    United States
    6 days ago
  • $80.2k - $117.1k

     ...Application Security Engineer The Application Security Engineer is responsible for embedding security throughout the software development lifecycle (SDLC), leading application security testing, and driving vulnerability remediation efforts. At CivicPlus, we strive... 
    Suggested
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    CivicPlus

    United States
    4 days ago
  • $100k - $150k

     ...their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.  As we continue to grow, we’re looking for a skilled Application Security Engineer to join our dynamic team and contribute to our mission of transforming... 
    Suggested
    Full time
    H1b
    Local area
    Immediate start
    Remote work
    Visa sponsorship
    Work visa

    Bright Vision Technologies

    Lawrenceville, GA
    5 days ago
  •  ...across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has...  ...ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security... 
    Suggested
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours

    AgileEngine

    New York, NY
    4 days ago
  •  ...Application Security Engineer This is a remote role D&H is growing! Join 100+ year old Employee-Owned technology distributor, offering end-to-end solutions for today's resellers, retailers, and the clients they serve across the SMB and Consumer markets. We... 
    Temporary work
    Work experience placement
    Remote work
    Work from home

    D and H Distributing Co

    Harrisburg, PA
    1 day ago
  •  ...across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has...  ...ABOUT THE ROLE We are looking for a Senior Application Security Engineer to architect and build automated security layers within the... 
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Flexible hours

    AgileEngine

    Atlanta, GA
    4 days ago
  •  ...Senior Application Security Engineer This role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days per week from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people... 
    Work experience placement
    Work at office
    2 days per week

    HPE

    Spring, Montgomery County, TX
    3 days ago
  • $150.2k - $225.4k

     ...About the team: The Information Security organization advances the overall state of security at Rubrik through purposeful...  ...information. About the role: Rubrik is seeking an Application Security Engineer. In this role, you will be responsible for ensuring that... 
    Work experience placement
    Local area
    Remote work
    Shift work

    Rubrik

    Salt Lake City, UT
    4 days ago
  • $80 - $85 per hour

     ...identifying and prioritizing risks specifically related to application security. ? Develop, socialize, and implement security strategies...  ...control Requirements Senior Application Security Engineer Mandatory Skills/Experience • 12 years of... 
    Contract work
    Flexible hours

    Network Temp Inc

    New York, NY
    5 days ago
  •  ...Senior Application Security Engineer Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? We're looking for a very experienced and highly motivated Senior Application Security Engineer to join our team as one of... 
    Hourly pay
    Full time
    Remote work
    Flexible hours

    Abridge

    United States
    2 days ago
  •  ...Application Security Engineer We are seeking an Application Security Engineer who will support our client with ensuring security is integrated into all stages of software development. This role will be responsible for designing and building secure applications while... 

    Damco

    Brooklyn, NY
    12 days ago
  • $47 - $49 per hour

     ...Akkodis is seeking an Application Security Engineer for a Contract with a client in Cleveland, OH/ Cincinnati, OH/ Edison, NJ. The ideal candidate is responsible for implementing and managing Claude-based security scans, supporting pipeline integration, and driving... 
    Hourly pay
    Contract work
    Temporary work
    Local area

    Akkodis

    Cleveland, OH
    3 days ago
  • $180k - $220k

     ...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States; Seattle, Washington, United States Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Lightning AI

    Seattle, WA
    2 days ago
  • $5,250 per month

     ...innovative technology-driven B2B payments organization seeking a curious, inquisitive, highly skilled and motivated Senior Application Security Engineer to join our team. Our company values collaboration, creativity, and excellence in delivering cutting-edge solutions to... 
    16 hours
    Full time
    Temporary work
    Local area
    Remote work

    AvidXchange

    United States
    2 days ago
  •  ...Application Security Engineer | Location: New York, NY or Charlotte, NC | Contract his Application Security Engineer contract role will embed security into the software development lifecycle to protect enterprise applications across web, mobile, and API ecosystems... 
    Contract work

    Delphi-US

    New York, NY
    1 day ago
  • $128.4k - $172.3k

     ...across Cisco. Our mission is to build secure, scalable AI platforms that empower teams...  ...and security —partnering across engineering, security, compliance, and product teams...  ...deployment phases. Integrate and optimize application security tooling, including SAST, DAST,... 
    Full time
    Temporary work
    Local area
    Flexible hours

    Webex Events (formerly Socio)

    Durham, NC
    4 days ago
  • $86.9k - $198k

     ...Application Security Engineer The Opportunity: Everyone is trying to "harness the cloud," but not everyone knows how. As a cloud computing infrastructure architect, you know how to take advantage of cloud capabilities. On our team of experienced professionals, you... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    BOOZ, ALLEN & HAMILTON, INC.

    Maryland
    5 days ago
  • $97.1k - $161.8k

     ...Information Security Specialist Responsible for capturing and refining information...  ...leadership in the areas of secure coding, application authentication, encryption, and quickly...  ...: Develop and implement engineering's technical security policies and procedures... 
    Work experience placement
    Remote work
    Worldwide

    M&T Bank

    United States
    3 days ago
  • $85 - $90 per hour

     ...A client of Innova Solutions is immediately hiring for a Application Security Engineer - AI . Position type: Contract Duration: 6-12 months contract Location: Charlotte, NC As a Application Security Engineer - AI you will: Define and lead the... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Immediate start
    Worldwide
    Flexible hours

    Innova Solutions

    Charlotte, NC
    4 days ago
  •  ...Application Security Engineer I Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation support, and incident response participation, contributing to secure development practices across... 

    Bloomberg Industry Group

    Arlington, VA
    5 days ago
  • $160k

     ...VISA CANDIDATES FOR THIS ROLE! Required Qualifications: Minimum of 5 years experience working "hands-on" in application security engineering Hands-on experience with Fortify, Veracode, Tenable, Black Duck, or similar platforms Hands-on experience with... 
    2 days per week

    Griffin Global Systems Inc

    Herndon, VA
    21 days ago
  •  ...Title: Senior Application Security Engineer Location: Austin, TX / Dallas, TX (hybrid) Reports To: Sr. Manager, Cybersecurity About Hippo Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us.... 
    Temporary work
    Flexible hours

    Hippo Insurance

    Austin, TX
    3 days ago
  •  ...against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR...  ...Envision yourself at Barracuda   As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll... 
    Remote work
    Worldwide
    Flexible hours

    Barracuda Networks Inc

    Ann Arbor, MI
    4 days ago
  •  ...Because at Valence, the work worth doing is the kind that redefines work itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be... 
    Full time
    Freelance
    Work from home

    Valence

    New York, NY
    2 days ago
  •  ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development... 
    Full time

    AGS

    New York, NY
    4 hours ago
  •  ...Job Description We are looking for an Application Security Engineer to work for our client. The ideal candidate aligns with the responsibilities and qualifications outlined below. This is a high-impact opportunity to join a growing security function focused on... 

    Ringside Talent Acquisition Partners

    Worthington, OH
    3 days ago
  • $145k - $155k

     ...per quarter), leaving 5 additional remote days to be used as needed. As a key member of the Security Engineering team, this person will help lead HarbourVest's Application Security program. The Application Security Engineer (ASE) will serve in a multi-functional role... 
    Work at office
    Local area
    Remote work
    1 day per week

    Harbourvest

    Boston, MA
    1 day ago
  • $180k - $210k

     ...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products bring together users from across the... 
    Work at office
    Remote work

    Qualia

    United States
    1 day ago
  • $200k - $340k

     ...Application Security Engineer Palo Alto, CA About XAI XAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This... 
    Temporary work

    Xai

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!