Senior Application Security Engineer (Hybrid - US)

  1. Home
  2. Remote jobs
  3. Architecture
  • Company Energy Solutions - USA
  • Employment Full-time
  • Location 🇺🇸 United States nationwide
  • Submitted Posted 5 days ago - Updated 10 hours ago
<div class="content-intro"><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus on the big impacts. And we believe that market-based programs can be a powerful force to deliver large-scale energy, carbon, and water-use savings. Since 1995, we’ve harnessed that power to offer proven, performance-based solutions for our utility, government, and institutional customers.</span></p></div><p><span style="text-decoration: underline;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><strong>Summary:&nbsp;&nbsp;</strong></span></span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">We are seeking a Senior Application Security Engineer who will work with our development team to manage security and risk on our internally developed applications. The engineer will make risk-based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms. This role is primarily focused on execution and consulting but should be familiar with roadmap and strategy and contribute where appropriate. Must have the ability to read, review, and make recommendations on secure Django/Python patterns.&nbsp;</span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><strong><span style="text-decoration: underline;">Responsibilities:</span>&nbsp;</strong></span></p><ul><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Contribute to the application security roadmap for our internal applications—prioritize risks and sequence work across codebases, application layer, and DevOps.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Consult with engineers to communicate requirements, create actionable tickets/acceptance criteria, and drive adoption.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Conduct pull request reviews focused on security, provide guidance on refactors, and approve/deny with clear rationale.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Serve as a steward for SAST/scanning: review static code scan results, triage findings, eliminate noise, and drive remediation with owners.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Build reference implementations in Django/Python (i.e. authentication patterns, input validation, secrets handling, rate limiting, geo-based access) without direct responsibility for production feature development.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Map SOC 2/NIST to engineering work: translate requirements into stories, controls, and automated evidence in CI/CD.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Threat modeling &amp; architecture: navigate libraries/architectures and document secure patterns (ADRs/RFCs) that teams follow.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Collaborate with software developers and code base leads.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Act as a liaison between technical requirements from the business (i.e. security, privacy, compliance) and development teams.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Participate as a subject matter expert in security architecture, including new designs and design reviews.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Review architecture and compliance-related code changes for security impact.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Ensure compliance with all company security policies and standards.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Manage and maintain all security related tickets, including recommendations, testing, and validation.</span></li></ul><p>&nbsp;</p><p><span style="text-decoration: underline;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><strong>Qualifications:&nbsp;</strong></span></span></p><ul><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Minimum of 5 years' experience in application security experience.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Practice and implementation with Django/Python with a clear application-security focus (production experience and impact, not theory).</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Engineering background (software or DevOps/SRE) with the ability to read/modify code, review PRs, and build PoCs.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Experience embedding secure SDLC into Git-based workflows and CI/CD (pre-commit, pipeline gates, policy-as-code).</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging/monitoring).</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Clear, persuasive communication (verbal and written) and prioritization.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Excellent time management skills with a proven ability to meet deadlines.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Excellent interpersonal and negotiation skills.</span></li></ul><p>&nbsp;</p><p><span style="text-decoration: underline;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><strong><span data-contrast="auto"><span data-ccp-parastyle="CTbullet">Preferred</span><span data-ccp-parastyle="CTbullet"> Qualifications: </span></span></strong><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:648,&quot;335559737&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:240,&quot;335559991&quot;:360}">&nbsp;</span></span></span></p><ul><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Bachelors degree in Computer Science or equivalent work experience preferred.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">CISSP, GIAC, Security+, AWS Security and other related security certifications.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Prior experience reporting to or partnering with a security architect, or being the app-sec lead in a smaller org.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Strong organizational skills and attention to detail.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Strong analytical and problem-solving skills.</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Ability to prioritize tasks according to severity</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Ability to adapt to the needs of the organization</span></li><li style="font-family: 'times new roman', times, serif; font-size: 14pt;"><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Proficient in AWS Security services (I.E. Cloud watch, Guard Duty)</span></li></ul><p>&nbsp;</p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><strong>Compensation to commensurate with experience with the pay band of&nbsp; $119,100 - $147,400</strong></span></p><div class="content-conclusion"><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Compensation is commensurate with experience and includes a generous retirement package. Energy Solutions provides an excellent benefits package including medical, dental and vision insurance, other pre-tax contribution plans and an Employee Stock Ownership Plan (ESOP).</span></p><p><span style="text-decoration: underline;"><strong><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">AI Use </span></strong></span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">At Energy Solutions we believe in the importance of authentic interactions and equitable opportunities. We base our candidate selection on one’s own skills, knowledge, and experience. To ensure the integrity and fairness of our interview process, the use of artificial intelligence (AI) tools (including Generative AI) or other means to generate or assist with responses during interviews is strictly prohibited. This practice supports our commitment to create a transparent and equitable space where skills, knowledge and experience skills can truly shine.</span></p><p><span style="text-decoration: underline;"><strong><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Equal Opportunity Employer</span></strong></span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Energy Solutions is an affirmative action-equal opportunity employer and prohibits discrimination and harassment of any type. We afford equal employment opportunities to employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristics protected by law. Energy Solutions conforms to the spirit as well as to the letter of all applicable laws and regulations.</span></p><p><span style="text-decoration: underline;"><strong><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Office Locations and a Remote Workforce</span></strong></span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Energy Solutions operates as a predominantly remote workforce with offices in&nbsp;&nbsp;</span><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><a class="c-link" href="https://energy-solution.com/contact-us/" target="_blank" data-stringify-link="https://energy-solution.com/contact-us/" data-sk="tooltip_parent">six different locations</a></span><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">. Employees who reside within 40 miles of an office (except New York) will be assigned to that location, though in-office attendance requirements may vary by team. At this time, we are not accepting applications from candidates residing in the following states: Delaware, Kentucky, Mississippi, Montana, Nebraska, North Dakota, and Wyoming.</span></p><p><span style="text-decoration: underline; font-family: 'times new roman', times, serif; font-size: 14pt;"><strong>Background Check Information</strong></span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Information will be requested to perform the compulsory background check. A drug screen and authorization to work in the U.S. indefinitely are preconditions of employment. Energy Solutions is an equal opportunity employer.</span></p><p><span style="text-decoration: underline; font-family: 'times new roman', times, serif; font-size: 14pt;"><strong>Reasonable Accommodations&nbsp;</strong></span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;">Energy Solutions is committed to providing access and reasonable accommodation for individuals with disabilities. If you require accommodations in completing this application, interviewing, and/or completing any pre-employment testing, or otherwise participating in the employee selection process, please email <a href="mailto:accommodation@energy-solution.com">accommodation@energy-solution.com</a>.</span></p><p><span style="font-family: 'times new roman', times, serif; font-size: 14pt;"><a href="https://energy-solution.com/wp-content/uploads/2023/07/ES-Privacy-Notice-for-Job-Applicants.pdf" target="_blank">Privacy Notice for Job Applicants&nbsp;</a></span></p><p>&nbsp;</p><p>&nbsp;</p></div>

Loading similar jobs...

USA Remote Jobs

Discover fully remote job opportunities in the United States at USA Remote Jobs. Apply for roles like Software Developer, Customer Service Specialist, Project Manager, and more!

© 2025 Created by USA Remote Jobs. All rights reserved.