Application Security Engineer
Our client is looking for an experienced Application Security Engineer to build, mature, and scale their application security program from the ground up. In this role you'll embed directly with Product and Engineering teams to secure both third-party SaaS applications and home-grown software, serving as both a trusted security consultant and a hands-on engineer. You'll review complex API designs, lead threat modeling on new features, build custom security tooling, and automate security controls directly into CI/CD pipelines. This is a high-impact opportunity for someone who brings an automation-first mindset and knows how to balance developer velocity with risk-informed pragmatism, bridging the cultures of development, security, and operations.
As part of our process after applying, you may receive an invitation from our AI Recruiter Avery for a short conversation that lets you share more about your background beyond your resume. For questions, contact .
Job Type: Direct Hire
Location: New York, NY or Los Angeles, CA (Onsite, 4 days per week)
Compensation: This job is expected to pay about $240,000-$260,000 W2
No Visa Sponsorship Available for this role
What You'll Do:
- Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tooling into CI/CD pipelines for home-grown applications
- Lead security design and threat modeling sessions with Product and Engineering teams based on OWASP Top 10 and MITRE ATT&CK
- Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks
- Define AppSec coverage, tooling, and assessment processes from scratch across the application landscape
- Develop secure Infrastructure as Code patterns and validate security controls for Azure and Kubernetes
What Gets You the Job:
- Significant hands-on application security experience, including expert knowledge of OWASP Top 10, API Security Top 10, and OWASP LLM Top 10 and how common vulnerability classes manifest in production
- Proficiency integrating SAST/SCA/DAST, container/IaC scanners, and secret scanning into one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins)
- Proficiency in Terraform/IaC, Kubernetes, and cloud provider security, with Azure preferred
- Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch
- Experience building security tooling or automation; policy gates with OPA/Gatekeeper or Kyverno a plus
Irvine Technology Corporation (ITC) connects top talent with exceptional opportunities in IT, Security, Engineering, and Design. From startups to Fortune 500s, we partner with leading companies nationwide. Our AI recruiter, Avery helps streamline the first step of your journey-so we can focus on what matters most: helping you grow. Join us. Let us ELEVATE your career!
Irvine Technology Corporation provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Irvine Technology Corporation complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.
![]()