Verified current Job

Sr. Application Security Engineer

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United

Job Remote Full source details
Jobgether Source published Oct 2, 2026 Verified 3 hours ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States. This is a highly technical Application Security role focused on protecting software products, APIs, and cloud-native applications throughout the development lifecycle. You will work hands-on with Java, Python, and Go codebases to identify vulnerabilities, trace root causes, assess exploitability, and guide secure remediation. The role bridges Information Security and Engineering, giving you significant ownership while keeping you deeply connected to software development teams. You will help strengthen the Secure SDLC through security gates, threat modeling, automated controls, and developer-focused security workflows. The position also covers SAST, DAST, SCA, API security, dependency risk, cloud-native architectures, and hands-on vulnerability validation. Beyond addressing individual findings, you will build preventative controls and secure coding practices that reduce recurring vulnerability classes. This opportunity is ideal for an experienced Application Security professional who enjoys solving complex technical problems and influencing engineering teams through practical security expertise.

As a Sr. Application Security Engineer , you will serve as a hands-on technical authority for application security, partnering closely with Engineering and Security teams to identify risks, drive remediation, and embed security into development practices. Perform hands-on security analysis of applications, APIs, services, and supporting components. Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths. Reproduce and validate vulnerabilities independently, assessing exploitability, reachability, exposure, data sensitivity, business criticality, and compensating controls. Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure. Maintain remediation SLAs and escalate unresolved Critical and High findings when appropriate. Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities. Mature security gates and review checkpoints across architecture, design, sprint, and release processes. Integrate preventative security controls into developer workflows and CI/CD pipelines. Configure, operate, and tune SAST, DAST, and SCA tooling to deliver actionable security feedback. Assess software dependency and supply-chain risks using application context, reachability, exploitability, and remediation options. Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies. Review authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, data flows, trust boundaries, cryptographic controls, and abuse scenarios. Evaluate application security across AWS, Kubernetes/EKS, containers, Linux/Ubuntu, distributed services, and cloud-native architectures. Partner with Engineering as a technical advisor, providing clear and actionable remediation guidance. Deliver secure-coding guidance and training based on real vulnerabilities and recurring security patterns. Help establish and mature a Security Champions program across development teams. Create security runbooks, standards, and reusable development patterns that teams can apply independently. Validate application and API vulnerabilities through hands-on testing and coordinate external penetration-testing engagements. Drive first-year improvements in vulnerability remediation, threat modeling, dependency security, secure development practices, and the overall effectiveness of the Application Security function. Requirements The role requires deep Application Security expertise combined with strong software engineering capabilities, hands-on vulnerability analysis, and the ability to collaborate effectively with technical and engineering leadership. 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field. Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation. Strong hands-on coding and secure code review experience with Java, Python, and Go. Ability to read, debug, and reason about production application code and communicate technical findings clearly to software engineers. Proven ability to reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation. Hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows. Strong knowledge of software dependency and supply-chain security. Experience prioritizing vulnerabilities based on application and business context rather than scanner severity alone. Strong understanding of the OWASP Top 10 and OWASP API Security risks. Experience with threat modeling using STRIDE, PASTA, or similar methodologies. Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments. Strong communication and collaboration skills, with the ability to influence developers, architects, and engineering leadership. Hands-on application and API penetration-testing experience is preferred. Experience in financial services, fintech, identity, fraud, regulated SaaS, or other highly regulated environments is a plus. Familiarity with PCI-DSS application security requirements is preferred. Experience building or leading a Security Champions program is a plus. Experience developing Application Security automation or internal security tooling is desirable. OSCP, GWEB, CSSLP, or a similar technical security certification is preferred. Benefits Salary: $130,000–$190,000 per year, with individual compensation varying based on experience, professional competencies, and geographic differentials. Remote flexibility: A virtual-first working environment designed to support remote work from a home office as well as in-person collaboration. Career growth: Opportunities for professional development, meaningful technical ownership, and work in an innovative, collaborative environment. Healthcare: Universal, supplemental, or private healthcare plan options depending on geographic location. Financial future: Retirement or pension contributions and participation in a stock plan. Income protection: Life event and disability coverage. Paid time off: Generous annual leave, company holidays, and volunteer time off. Learning: E-learning resources, tuition reimbursement, and opportunities to participate in hackathons. Home office: Home office setup allowance. Additional benefits: Optional benefits may include pet insurance, identity theft protection, and legal assistance. Technical scope: Exposure to internet-facing financial software, complex API integrations, cloud-native environments, and a dual US/EU regulatory context. Visibility and ownership: Direct collaboration with senior Security and Engineering leadership and meaningful ownership of Application Security initiatives.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from jobgether (lever) →

Related opportunities

Other current verified records you may want to review.

Job

My HR Live Support Specialty Advisor (S)

Amazon Support Services Costa Rica SRL - B20 · Costa Rica

The My HR Live Support (MHLS) team is currently seeking to hire an MHLS Sr. Advisor to support our Tier 2 Specialty Operation. The MHLS Tier 2 Sp...

Job

Deal and Contract Ops Manager, eero Business Operations

Amazon.com Services LLC · United States

We are hiring a Deal and Contract Operations Manager to join our Business Operations team in San Francisco. In this role, you will design and own...

Job

Technical Account Manager, Enterprise Support, ES – APJC-ASEAN

Amazon Web Services Singapore Private Limited · Singapore

The AWS Enterprise Support team is growing to meet the demands of a portfolio of always-on, latency-sensitive enterprise customers whose producti...

Job

Principal Product Manager, Technical , AWS Healthcare AI

Amazon Development Center U.S., Inc. · United States

AWS Applied AI Solutions (AAIS) is building toward a future where every business innovates with Amazon AI teammates. To get there, we build AI so...

Job

Ads Product Marketing Manager, Prime Video AUNZ

Amazon Commercial Services Pty Ltd · Australia

Prime Video is seeking an experienced Product Marketing Manager to drive advertising product marketing, brand partnership programs, and house ads...

Job

Supplier Quality Manager, Electromechanical Supplier Quality Management

Amazon Innovation Center (Shenzhen) Company Limited · China

Amazon Devices is strengthening its electro-mechanical supply chain in China. We are hiring a Supplier Quality Manager to take end-to-end ownersh...

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books