Sr. Application Security Engineer

  1. Home
  2. Remote jobs
  3. Ansible
  • Company Jobgether
  • Employment Full-time
  • Location 🇺🇸 United States nationwide
  • Submitted Posted 20 hours ago - Updated 6 hours ago

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in the United States.

This is a senior application security opportunity for an engineer who combines strong software development experience with deep security and DevSecOps expertise.
You will help embed security throughout the software development lifecycle, from secure coding and threat modeling to automated testing and production deployment.
The role works closely with engineering and DevOps teams to strengthen cloud-native applications, APIs, CI/CD pipelines, and infrastructure.
You will also help establish secure governance around emerging agentic AI coding technologies and address new risks introduced by AI-assisted development.
Your expertise will contribute to meeting demanding security and compliance requirements across standards such as PCI-DSS, GDPR, CCPA, and SOC 2.
You will influence engineering practices, develop security metrics, communicate risks to leadership, and mentor other engineers.
This is an ideal role for a hands-on security professional who wants to shape application security strategy while remaining close to technology and engineering teams.


Accountabilities:
  • Partner with DevOps and engineering teams to design, implement, and maintain secure CI/CD pipelines with security controls and testing integrated throughout the software development lifecycle.
  • Implement, configure, and continuously improve automated security testing, including SAST, DAST, software composition analysis (SCA), vulnerability scanning, and container security.
  • Deploy and support API security solutions while ensuring security findings are consistently captured, centralized, tracked, and addressed.
  • Collaborate with development teams to promote secure coding practices and provide practical security guidance throughout application design, development, testing, and deployment.
  • Establish and strengthen application security practices for cloud-native environments, including appropriate controls for identity, networking, encryption, secrets, and infrastructure.
  • Evaluate the secure adoption of agentic and AI-assisted coding tools across engineering teams and establish appropriate guardrails, governance, detection, and risk-mitigation strategies.
  • Identify and address AI-specific application security risks, including hallucinated or vulnerable dependencies, insecure code generation, malicious code injection, and insufficient human oversight.
  • Support compliance with applicable security and privacy standards, including PCI-DSS, GDPR, CCPA, and SOC 2.
  • Develop application security KPIs, metrics, dashboards, and reporting to demonstrate program effectiveness and communicate findings to leadership.
  • Conduct or support threat modeling, security assessments, penetration testing, and risk analysis across applications and technology environments.
  • Contribute to security architecture decisions and help engineering teams build resilient, secure applications and APIs.
  • Mentor junior security engineers and developers while promoting a security-first culture across engineering organizations.
  • Support emerging security initiatives involving AI/ML systems, model security, data pipeline protection, and AI/ML supply-chain risks.
  • Stay current on application security threats, emerging technologies, development practices, and industry trends to continuously improve the security program.

Requirements

  • 5+ years of professional software development experience, with strong proficiency in three or more programming or scripting languages such as Python, Go, Java, C#, Ruby, JavaScript/TypeScript, Bash, PowerShell, Swift, Kotlin, Objective-C, or Dart.
  • 3+ years of hands-on experience in application security, DevSecOps, or a closely related security engineering discipline.
  • Strong understanding of the OWASP Top 10 and modern secure software development practices.
  • Deep knowledge of API security, authentication protocols, authorization, and secure API design.
  • Strong cloud security expertise with at least one major cloud platform such as AWS, Azure, or GCP; multi-cloud experience is highly valuable.
  • Understanding of cloud-native security concepts including IAM, network security, encryption, secrets management, workload protection, and compliance.
  • Hands-on experience with CI/CD technologies such as Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or Azure DevOps.
  • Experience with infrastructure-as-code, containerization, and orchestration technologies such as Terraform, Docker, Kubernetes, Helm, or Ansible.
  • Familiarity with application security tools including SAST/DAST scanners, SCA solutions, WAFs, SIEM platforms, vulnerability scanners, and secrets-management technologies.
  • Experience with AI-assisted or agentic development tools such as GitHub Copilot, Cursor, Claude Code, or similar technologies, along with a strong understanding of their security implications.
  • Experience establishing governance and guardrails for safe adoption of AI-assisted software development tools.
  • Knowledge of threat modeling methodologies, security risk assessment frameworks, and the ability to communicate technical risks effectively to both technical and non-technical stakeholders.
  • Knowledge of compliance requirements and frameworks including PCI-DSS, GDPR, CCPA, and SOC 2.
  • Background in penetration testing, red-team operations, or offensive security is highly valuable.
  • Familiarity with MLSecOps, including model security, data pipeline protection, and AI/ML supply-chain security.
  • Security certifications such as CISSP, GIAC, OSCP, AWS Security Specialty, Azure Security Engineer, or equivalent are advantageous.
  • Experience in travel, hospitality, e-commerce, or another high-volume digital industry is a plus.
  • Strong communication, mentoring, collaboration, and problem-solving skills, with the ability to influence engineering teams and promote security best practices.
  • Ability to work independently while partnering effectively across engineering, DevOps, security, and other technology functions.

Benefits

  • Base salary: $104,300–$193,700 USD annually, with actual compensation based on role scope, complexity, experience, skills, knowledge, and work location.
  • Eligibility for a discretionary annual bonus based on individual and organizational performance.
  • Comprehensive U.S. benefits programs covering health and welfare, retirement, parental leave, adoption assistance, and wellbeing resources.
  • Flexible benefits designed to support employees and their families.
  • Travel-related employee perks, including access to deals on flights, hotels, cruises, car rentals, and other travel services.
  • Access to 20,000+ learning courses, leadership development programs, and ongoing professional development opportunities.
  • Opportunities to grow technical and leadership skills within a collaborative global environment.
  • Remote work opportunity within the United States.
  • Inclusive workplace culture that values collaboration, diverse perspectives, and employee development.
  • Reasonable accommodations available for qualified individuals with disabilities throughout the recruitment process.
  • Opportunity to work with modern cloud-native technologies, application security tooling, DevSecOps practices, and emerging AI security capabilities.
  • Opportunity to influence security strategy and help shape secure software development practices at scale.


How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

 Why Apply Through Jobgether? 

 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

 

 

#LI-CL1

Loading similar jobs...

USA Remote Jobs

Discover fully remote job opportunities in the United States at USA Remote Jobs. Apply for roles like Software Developer, Customer Service Specialist, Project Manager, and more!

© 2026 Created by USA Remote Jobs. All rights reserved.