luminasadvisor Logo

luminasadvisor

Senior Application Security Engineer

Posted 2 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Own and evolve the application security program, partnering with engineering teams on secure design, code reviews, threat modeling, vulnerability remediation, and secure SDLC practices. Manage SAST, DAST, ASM, WAF, and mobile security tooling; automate integrations with CI/CD pipelines; support AWS, container, and infrastructure security; and develop standards, training, and playbooks. Lead application vulnerability investigations and remediation while influencing secure architecture and development decisions.
The summary above was generated by AI

While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

 

As our Senior Application Security Engineer, you will be the primary owner and driver of our application security program. You’ll work hands‑on with engineering teams to embed secure development practices, improve tooling and automation, and guide security considerations for new features, architectures, and services.

This is a high‑impact role where you’ll shape the future of AppSec at a company that values security as a core part of product quality.

What You’ll Do

Application Security Ownership

  • Lead and evolve the company’s application security strategy, roadmap, and day‑to‑day operations.
  • Serve as the primary AppSec partner for numerous dev teams working on Ruby on Rails web apps, React Native mobile apps, and various other projects including Python and Go.
  • Provide security guidance during design, development, and code review for new features and projects.
  • Drive adoption of secure coding practices and threat‑modeling across engineering teams.

Tooling & Automation

  • Manage and optimize existing AppSec tooling, including:
    • GitHub Advanced Security (SAST, SCA, Secret Scanning)
    • Invicti (DAST)
    • Hadrian (ASM)
    • AppDome (mobile application security)
    • Cloudflare WAF
  • Improve automation and integration of security tools into CI/CD pipelines.
  • Identify and implement additional tools or processes to strengthen the security posture.

Secure SDLC & Developer Enablement

  • Build and maintain secure development standards, playbooks, and training materials.
  • Partner with engineering teams during sprint planning and feature design to proactively address risks.
  • Conduct security reviews, code assessments, and vulnerability triage with development teams.

Cloud & DevOps Collaboration

  • Work with DevOps to ensure secure AWS infrastructure deployments and configurations.
  • Contribute to hardening efforts across ECS, IAM, networking, and supporting cloud services.
  • Assist in designing and maintaining secure CI/CD workflows.

Incident & Vulnerability Management

  • Lead or support investigation and remediation of application‑level vulnerabilities.
  • Monitor, prioritize, and track findings from SAST/DAST/ASM tools.
  • Collaborate with engineering to ensure timely and effective remediation.

What We’re Looking For

Required Skills & Experience

  • 3–7+ years of experience in Application Security, Product Security, or related engineering roles.
  • Strong understanding of secure coding practices, common vulnerabilities (OWASP Top 10), and modern SDLC.
  • Experience working with cloud‑native applications, ideally in AWS.
  • Understanding of SSL certificates & cryptographic key management
  • Hands‑on experience with SAST, DAST, WAFs, and/or mobile application security tools.
  • Ability to partner effectively with developers and influence secure design decisions.
  • Familiarity with GitHub‑based workflows and CI/CD pipelines.

Nice to Have

  • Development experience with Ruby on Rails or similar dynamic languages.
  • Knowledge of AWS ECS/EKS, container security, secrets management and infrastructure‑as‑code (CloudFormation, Terraform).
  • Experience building or maturing an AppSec program from early stages.
  • SOAR Automation & Scripting experience
  • Experience working in a PCI compliant environment working with annual reporting needs

Similar Jobs

7 Days Ago
Remote
United States
145K-183K Annually
Senior level
145K-183K Annually
Senior level
Fintech • Financial Services
Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams.
Top Skills: Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript
17 Days Ago
Remote or Hybrid
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
One Month Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-165K Annually
Senior level
140K-165K Annually
Senior level
Fintech • Financial Services
Own and evolve the application security program: embed secure SDLC practices, partner with engineering on design and code reviews, manage AppSec tooling (SAST/DAST/ASM/WAF/mobile), harden AWS deployments, integrate security into CI/CD, and lead vulnerability investigation and remediation efforts.
Top Skills: AppdomeAsmAWSCi/Cd PipelinesCloudflare WafCryptographic Key ManagementDastEcsGithub Advanced SecurityGoHadrianIamInvictiMobile Application Security ToolsPythonReact NativeRuby On RailsSastScaSecret ScanningSsl Certificates

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account