Application Security Engineer

New York, NY, US • Posted 3 hours ago • Updated 3 hours ago
Full Time
No Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

✨ Finding the perfect fit...

Job Details

Skills

  • Application Security Engineer
  • LLM
  • Python
  • CI/CD
  • App Sec Tool

Summary

Application Security Engineer
NYC / Charlotte NC- 3 Days Onsite 
W2 Position
 
Overview:
 
This role will be an integral component of the application security program end-to-end — from discovery and inventory of business unit applications, through tooling implementation, through embedding security and AI-assisted controls into business unit DevOps pipelines. This is as much a relationship and influence role as it is a technical role; success requires partnering effectively with subsidiaries. This is a hybrid on-site position, with a requirement to be in office three times per week.
 
What You’ll Do
 
• Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering.
• Standing up and operating the AppSec tooling stack — SAST, SCA, secrets scanning, and container/IaC scanning — integrated into business unit CI/CD pipelines.
• Designing and implementing AI-assisted triage workflows on top of AppSec tooling so that finding volume does not overwhelm developers and false positives are filtered before reaching engineering teams.
• Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process.
• Partnering with business unit development leaders to build the relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.
• Contributing to AI security strategy — evaluating emerging tools (AI code review assistants, agentic security testing, automated security requirement generation) and recommending what to operationalize and what to defer.
• Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction.
 
Required Qualifications
 
• 7+ years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.
• Hands-on experience deploying and operating modern AppSec tooling (e.g., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security).
• Working code-level proficiency in at least three commonly-used languages (e.g., Python, JavaScript/TypeScript, Java, C#, Go) sufficient to read, review, and triage findings.
• Strong scripting and automation skills in Python or equivalent; comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
• Demonstrated ability to influence engineering organizations without direct authority — negotiating standards, driving adoption, and partnering with development leaders.
• Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks.
 
Preferred Qualifications
 
• Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).
• Familiarity with one or more compliance frameworks relevant to our environment (HITRUST, HIPAA, NIST AI RMF, SOC 2).
• Prior experience working in a regulated or healthcare-adjacent environment.
• Cloud security depth in at least one major provider (AWS, Azure, Google Cloud Platform).
• Public contribution to AppSec community — OSS, conference talks, published research, or detection/rule contributions.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91124621
  • Position Id: 334-38988-3174
  • Posted 3 hours ago

Company Info

About Arnex Solutions LLC


At Arnex Solutions LLC, we go beyond traditional consulting. We blend expertise with innovation to offer end-to-end solutions that bridge the gap between business challenges and technological advancements.

Our Services:
Strategic IT Advisory: Our experienced consultants collaborate with you to craft customized IT strategies that drive growth and efficiency. We transform technology into a competitive advantage.

Talent Resourcing: Access top IT talent with ease. Our staffing solutions connect you with skilled professionals who align with your unique business requirements.

Cloud Excellence: Leverage the power of the cloud with our tailored services. From strategy to execution, we help you harness cloud capabilities for innovation and scalability.
Why Choose Arnex Solutions LLC:

Holistic Approach: We're your all-in-one partner for both strategic consulting and talent acquisition. Our holistic solutions ensure your business stays ahead in a dynamic landscape.

Client-Centric Philosophy: Your success is at the heart of everything we do. Our collaborative approach ensures we understand your unique needs and deliver impactful solutions.

Innovation Infused: We embrace emerging technologies to drive innovation. Partnering with Arnex Solutions LLC means accessing solutions that position you for sustained success.

Enduring Partnerships: Our commitment extends beyond a single project. When you choose Arnex Solutions LLC, you choose a partner dedicated to your long-term growth.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

New York, New York

Today

Full-time, Third Party

Depends on Experience

Remote

Today

Full-time, Third Party

Depends on Experience

Search all similar jobs