← Все вакансии/Middle/Jobgether
MiddleRemoteUS

Application Security Engineer

J
Jobgether
Зарплата
$6,800–$9,800
Уровень
Middle
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Engineer based in the United States.

Responsibilities
  • Apply and maintain secure software development practices, including code reviews and security testing integrated into CI/CD pipelines.
  • Identify, validate, prioritize, and triage application vulnerabilities using automated security tools and manual testing techniques.
  • Support Shift Left security initiatives by helping development teams adopt secure coding practices and remediate identified vulnerabilities.
  • Support Security Champions programs by answering development-team questions and helping deliver security training.
  • Assist developers with vulnerability reproduction, risk assessment, and remediation guidance, escalating complex or high-risk issues when appropriate.
  • Operate, tune, maintain, and improve application security tools, including open-source solutions.
  • Collaborate with product, engineering, DevOps, and compliance stakeholders to incorporate security requirements into application architecture and design.
  • Participate in threat modeling, security design reviews, recurring security assessments, and vulnerability testing.
  • Maintain security control documentation, testing evidence, findings, and remediation guidance.
  • Apply secure development standards to AI-enabled applications, including LLM integrations, RAG pipelines, and agentic workflows.
  • Configure, test, and monitor AI security guardrails, including prompt-injection defenses, input/output validation, least-privilege controls, and data-loss prevention measures.
  • Conduct AI red-team testing covering prompt injection, jailbreaks, sensitive-data exposure, insecure outputs, and excessive agency, using recognized security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Support security reviews of new AI use cases and third-party AI capabilities, including controls protecting nonpublic personal information.
  • Help establish secure-use practices for AI coding assistants, including appropriate human review and security scanning of AI-generated code.
  • Assist incident response teams with investigation and remediation of application-related security incidents.
  • Monitor emerging application and AI security threats and contribute to security awareness and compliance initiatives.
Requirements
  • Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline preferred; equivalent education and experience may be considered.
  • At least 3 years of experience as a software developer or in a comparable technical role.
  • Experience with application security, secure software development, vulnerability management, code review, or security testing is highly relevant.
  • Familiarity with automated and manual application security testing methodologies.
  • Experience with AI/LLM security concepts, including prompt injection, jailbreaks, RAG security, agentic workflows, and AI guardrails, is valuable.
  • Familiarity with OWASP application security principles and emerging AI security frameworks such as OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Certifications such as Burp Suite Certified Practitioner, Hack The Box Certified Web Exploitation Specialist (HTB CWES), or Practical Web Pentest Professional (PWPP) are preferred.
  • Strong analytical, troubleshooting, organizational, and problem-solving skills, with the ability to manage multiple priorities.
  • Excellent written and verbal communication skills and the ability to explain technical security concepts clearly to developers and business stakeholders.
  • Ability to work effectively both independently and collaboratively in a fast-paced, metrics-driven environment.
  • Strong attention to detail and sound judgment when handling confidential or sensitive information.
  • Proficiency with Microsoft Office, collaborative cloud platforms, wikis, and third-party software applications.
  • Demonstrated commitment to integrity, customer service, respect, collaboration, continuous learning, and high-quality work.
  • Ability to learn new technologies, maintain focus, work independently, and make timely decisions within established workflows.
  • Comfortable working remotely with limited travel, generally no more than 5%.
  • Availability to work primarily Monday through Friday during standard business-week schedules.
  • Must be legally authorized to work in the United States without requiring immigration sponsorship.
Conditions
  • Targeted annual salary range of $82,000–$118,000, with actual compensation influenced by experience, education, qualifications, and geographic location.
  • Medical, dental, and vision insurance.
  • Life insurance and AD&D coverage.
  • Long-term disability insurance.
  • 401(k) retirement plan with employer matching.
  • Fully remote work environment.
  • Primarily Monday–Friday schedule.
  • Professional development opportunities within an evolving application and AI security landscape.
Стек и навыки

С чем работаем