Job Title: Application Security Engineer
Location: New York, NY, USA or Charlotte, NC, USA
Work Arrangement: Hybrid – 3 Days/Week Onsite
Duration: Contract-to-Hire
Experience: 7+ Years
Job Summary
We are seeking an experienced Application Security Engineer to support and strengthen an enterprise Application Security program across multiple business units.
The ideal candidate will have strong hands-on experience with SAST, SCA, secrets scanning, container/IaC security, DevSecOps, CI/CD, threat modeling, and security automation. This role requires both strong technical skills and the ability to collaborate with development and engineering teams to integrate security into the software development lifecycle.
Responsibilities
Perform application discovery, inventory, ownership mapping, technology profiling, and risk assessment across multiple business units.
Deploy, configure, and manage modern Application Security tools, including SAST, SCA, secrets scanning, container scanning, and IaC scanning.
Integrate security tools and security gates into CI/CD pipelines.
Develop automated and AI-assisted vulnerability triage workflows to reduce false positives and improve remediation.
Define and implement Secure SDLC requirements, security standards, and development practices.
Conduct threat modeling using STRIDE, PASTA, or similar methodologies.
Partner with application development and engineering teams to drive adoption of security practices.
Evaluate emerging AI security technologies, including AI code review, agentic security testing, and automated security requirements.
Build security automation and integrations using Python, scripting, and REST APIs.
Develop security metrics and executive-level reporting related to application risk.
Identify and address application, dependency, software supply-chain, container, and infrastructure-as-code security risks.
Required Qualifications
7+ years of experience in Application Security, Product Security, or Security Engineering.
3+ years of experience working across multiple business units, products, brands, or engineering organizations.
Hands-on experience with modern AppSec tools such as Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, or GitHub Advanced Security.
Strong experience with SAST, SCA, secrets scanning, container security, and IaC scanning.
Experience integrating security tooling into GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or similar CI/CD platforms.
Strong programming/code-level experience with at least 3 languages, such as Python, Java, JavaScript/TypeScript, C#, or Go.
Strong Python or scripting experience for security automation.
Experience working with REST APIs and automation integrations.
Strong understanding of OWASP Top 10 and modern application security vulnerabilities.
Practical experience with threat modeling methodologies such as STRIDE or PASTA.
Understanding of software supply-chain security and dependency risks.
Strong communication, collaboration, and stakeholder-management skills.
Ability to influence engineering teams and drive security adoption without direct authority.
Willingness to work onsite 3 days per week in either New York, NY or Charlotte, NC.
Preferred Qualifications
Experience integrating LLM/AI technologies into security workflows.
Experience with AI-assisted vulnerability triage, finding summarization, or automated remediation guidance.
Knowledge of NIST AI RMF, SOC 2, HIPAA, or HITRUST.
Experience working in regulated or healthcare-related environments.
Cloud security experience with AWS, Azure, or GCP.
Contributions to open-source security projects, security research, conference presentations, or AppSec detection/rule development.
Key Skills
Application Security | AppSec | Product Security | DevSecOps | SAST | SCA | Snyk | Semgrep | Checkmarx | Veracode | GitHub Advanced Security | Secrets Scanning | Container Security | IaC Security | Python | REST APIs | CI/CD | Jenkins | GitHub Actions | GitLab | Azure DevOps | OWASP | Threat Modeling | STRIDE | PASTA | Software Supply Chain Security | AI Security | LLM | AWS | Azure | GCP
Work Arrangement
Hybrid – 3 Days/Week Onsite
Location: New York, NY, USA or Charlotte, NC, USA