Home

NO -100% Remote Role-Senior Application Security Engineer at Remote, Remote, USA
Email: [email protected]
http://bit.ly/4ey8w48
https://jobs.nvoids.com/job_details.jsp?id=3319264&uid=7207f8f8c8e2437da367cc46585be4f3

Hello All,

Position: Senior Application Security Engineer
Location: 100% Remote
Duration: 6+Months Contract

US s or holders or are eligible to apply

Job Description:
About the Role:
We are seeking a Senior Application Security Engineer to serve as a senior subject-matter expert in application security and to provide strong technical leadership and decision-making influence across the engineering organization.
This role is application-securityfirst, with intentional overlap into cloud and platform security where applications, identity, CI/CD, and infrastructure intersect. The role does not own infrastructure, security programs, or departmental priorities; however, it is accountable for driving application-security outcomes and influencing technical direction through deep expertise, partnership, and trusted advisory relationships.
At this level, the Senior Application Security Engineer operates with significant autonomy and broad scope, independently owning complex and ambiguous application security challenges end-to-end. The role is relied upon to guide high-impact security decisions across multiple teams, products, and services, ensuring outcomes align with business objectives and risk tolerance.
This is a senior individual contributor role with strong expectations for technical leadership, cross-team influence, mentorship, and independent judgment, rather than people management or formal program ownership.

Success in this role means:
Senior Application Security Subject-Matter Expertise
You are a recognized internal authority in application security. You provide authoritative guidance on secure design, authentication and identity flows, API security, and cloud-native application risks. Engineering teams consistently rely on your judgment to make high-confidence security decisions in complex and high-impact scenarios.
Influence Within Security Programs
You play a leading, technical role within broader security programs by shaping technical approaches, standards, patterns, and best practices. You influence outcomes through expertise, credibility, and sustained cross-team collaboration rather than formal ownership or authority.
Trusted Advisor to Engineering, Product, & Infrastructure
You act as a trusted security advisor during design reviews, architecture discussions, and risk assessments across multiple teams. You help stakeholders understand security implications and tradeoffs, enabling informed decisions that balance risk, delivery velocity, and business needs.
Application-Centric Risk Identification
You identify, articulate, and contextualize security risks at the intersection of application code, identity and access, CI/CD pipelines, and cloud infrastructure. You are accountable for application security outcomes across multiple services and products, informing security prioritization by clearly surfacing risk tradeoffs and ensuring risks are visible, understood, and appropriately addressed.
Independent Ownership of Complex Problems
You independently own complex, ambiguous application security challenges with broad organizational impact. You define and drive practical solutions end-to-end, coordinating across multiple teams, products, and services to ensure consistent, high-quality security decisions at scale that align with business objectives and risk tolerance.
Threat-Informed Security Guidance
You apply adversarial thinking (threat modeling, attack-path analysis, and application-focused testing) to inform defensive improvements and strengthen real-world resilience across the application landscape.
Incident Response and Threat Hunting Support
You provide senior application security expertise during security incidents and targeted threat-hunting activities. You support investigation and containment by analyzing application behavior, attack paths, and root causes, partnering with detection, infrastructure, and response teams. You do not serve as a primary responder, but help ensure incidents are correctly understood, effectively resolved, and translated into durable security improvements.
Standards and Best-Practice Contribution
You make significant, sustained contributions to application security standards, guidance, and reusable patterns. You integrate these into engineering workflows and practices, helping mature security capabilities across the organization over time.
Clear Communication and Influence
You communicate risks, recommendations, standards, and progress clearly to senior engineers and security leadership, influencing technical decisions through clarity, technical credibility and sound judgment.
Cross-Team Mentorship and Capability Building
You actively mentor engineers and security partners across teams and disciplines, helping elevate application security knowledge, decision-making, and secure design practices. You act as a force multiplier. enabling others to identify risks, apply secure patterns, and make effective security tradeoffs independently.

Qualifications
Required
6+ years of experience in application or product security roles.
Demonstrated impact improving application security outcomes across multiple teams, systems, or business domains.
Deep experience securing web applications, APIs, WAFs, customer identity platforms, and distributed systems.
Proven ability to review system designs, data flows, and identify architectural security risks.
Strong understanding of authentication and identity protocols (OAuth2, OIDC, SAML, JWT, MFA).
Solid understanding of cloud-native application architectures and CI/CD pipelines from an application-risk perspective.
Proven ability to design and maintain automated pipelines for SAST, DAST, SCA, secrets detection, etc.
Proficiency in one or more modern programming languages.

Preferred:
Experience assessing or threat modeling AI-powered features or LLM integrations, including risks such as prompt injection, data leakage, and abuse.
Experience with application-focused penetration testing or adversarial security testing.
Familiarity with Kubernetes, container security, and infrastructure-as-code as they relate to application security.
Experience operating in regulated environments and aligning security practices with compliance requirements.
Relevant security certifications are a plus (e.g., OSWE, GWAPT, or CSSLP), but certifications are not a substitute for demonstrated application security impact.

Job Skills Were Looking For
Web Application Security
Web Application Firewall (WAF)
OWASP
API Security
Customer Identity and Access Management (CIAM)
Continuous Integration/Continuous Delivery (CI/CD)
Cloud Security
Automation
Threat Modeling
Secure SDLC
Secure design review
Authorization models
Secrets management

Technical Skills / Aptitude
SAML
OIDC
CIAM
JWT
OAuth 2
SCA
SAST
DAST
CSPM
Node.js
React
Kubernetes
Terraform
Docker
JavaScript
Python
TypeScript

Thanks & Regards
Manohar Reddy
Direct: (703) 884-0897
Email: [email protected]
Web: https://www.aptivacorp.com
LinkedIn: linkedin.com/in/s-m-reddy-71561237

--

Keywords: continuous integration continuous deployment artificial intelligence javascript information technology card
NO -100% Remote Role-Senior Application Security Engineer
[email protected]
http://bit.ly/4ey8w48
https://jobs.nvoids.com/job_details.jsp?id=3319264&uid=7207f8f8c8e2437da367cc46585be4f3
[email protected]
View All
06:01 PM 23-Apr-26


To remove this job post send "job_kill 3319264" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.

Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]


Time Taken: 22

Location: , Remote