Application Security Engineer

Philadelphia, PA, US • Posted 2 hours ago • Updated 2 hours ago
Contract Independent
On-site
USD $60.00 - 62.00 per hour
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Network
  • Bridging
  • Expect
  • Design Review
  • Application Development
  • Software Development Methodology
  • Product Engineering
  • Threat Modeling
  • Microservices
  • Migration
  • Inventory
  • Leadership
  • Security Operations
  • Incident Management
  • Software Engineering
  • Modeling
  • Software Security
  • OWASP
  • Web Applications
  • Continuous Delivery
  • GitHub
  • DevOps
  • GitLab
  • Continuous Integration
  • Jenkins
  • Authentication
  • Authorization
  • OAuth
  • OIDC
  • SAML
  • Management
  • Cloud Computing
  • Docker
  • Kubernetes
  • Computer Science
  • Information Security
  • Fortify
  • Cloud Security
  • Microsoft Azure
  • Amazon Web Services
  • API
  • Security QA
  • WAF
  • OSCP
  • GPEN
  • CISSP
  • Supply Chain Management
  • Oracle Linux
  • Insurance
  • Privacy
  • Marketing

Summary

Location: Philadelphia, PA Salary: $60.00 USD Hourly - $62.00 USD Hourly Description:
Title: Application Security Engineer

Location: Philadelphia, PA / Hybrid

Employment: (6-month CTH)

About the Role

Application development at Client is distributed across many engineering teams, and the company is modernizing its application portfolio and migrating workloads to the cloud.

The mission is to create scalable application security capability. A minimum baseline that every development team can meet, a risk-tiering model that focuses limited effort where it matters most, automated security testing integrated into delivery pipelines, and a Security Champions network that extends security practice into the teams where code is actually written. Success is measured by the capability adopted across engineering teams, not by the volume of reviews one person performs.

This role bridges shift-left secure development practice with detection and response capabilities that reveal how applications are attacked in the real world, which grounds the engineer's secure-design guidance in genuine attack patterns and makes them a stronger partner to the teams rebuilding applications for the cloud.

This is a hands-on technical role. Expect to read unfamiliar codebases, configure tooling, lead design reviews, and triage findings. The measure of success is the operating model built and adopted across the organization, not personal throughput.

What You'll Do
  • Inventory and assess the environment by cataloging applications, development pipelines, source repositories, and existing AppSec tooling across the decentralized engineering organization, so standardization starts from an accurate picture rather than an assumption.
  1. Create an application risk-tiering model that focuses limited application security effort on the applications carrying the most risk, so time is spent where it changes outcomes.
  1. Define a minimum AppSec baseline that every development team is expected to meet, regardless of their tooling or SDLC, and socialize it with engineering leadership as the common standard.
  1. Build and lead a Security Champions program across the decentralized product engineering teams.
  1. Lead threat modeling for modernization and migration including the new trust boundaries and attack surfaces introduced by monolith-to-microservices re-architecture containerization, and re-platforming.
  1. Provide secure-by-design guidance on migration decisions so security tradeoffs are understood before architecture is locked.
  1. Own application inventory, risk-tiering, and coverage metrics, alongside vulnerability and remediation metrics, so leadership can see reach and gaps across the portfolio.
  1. Triage and validate vulnerabilities surfaced through tooling, penetration tests, bug bounty submissions, and detection alerts, and drive remediation with the responsible engineering teams.
  1. Partner with Security Operations and incident response on application-layer incidents, providing technical depth on attack paths, exploit feasibility, and remediation validation.

What You Bring
  • 4+ years in software engineering, cloud engineering, or application security, including hands-on security work.
  1. Experience wit hthreat modeling (STRIDE, PASTA, or equivalent), or a strong demonstrated ability to translate findings into engineering action.
  1. Strong software or cloud engineering ability paired with real, load-bearing security instincts.
  1. Enough application security depth to define what good looks like, including OWASP Top 10, OWASP ASVS, CWE Top 25, and modern attack patterns against web applications, APIs, and cloud-native services.
  1. Experience integrating security tooling into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or equivalent).
  1. Working knowledge of authentication and authorization patterns, including OAuth 2.0, OIDC, SAML, and modern session management.
  1. Ability to communicate risk and remediation guidance to engineering audiences in language they will accept and act on.
  1. Familiarity with containerization and cloud-native design (Docker, Kubernetes, etc.) and their security considerations.
  1. Ability to win credibility with engineers and communicate risk in language they will act on.
  1. Bachelor's degree in computer science, information security, or a related field, or equivalent practical experience.

Nice to Have
  • Experience working with code scanner platforms such as Fortify, Veracode, or Wiz Code
  1. Cloud security experience in Azure and AWS, including hands-on time with CSPM and CNAPP tooling such as Wiz.
  1. Exposure to API security testing, runtime application protection, and modern WAF tuning.
  1. Industry certifications such as OSCP, OSWE, GWAPT, GPEN, or CISSP.
  1. Experience with software supply chain security frameworks (SLSA, S2C2F, OpenSSF Scorecard).


  1. Prior work in a distributed, multi-tenant, or franchise-like operational environment.

Medical, dental, and vision insurance are available to qualified candidates who meet eligibility requirements.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact:
This job and many more are available through The Judge Group. Please apply with us today!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: cxjudgpa
  • Position Id: 1149975
  • Posted 2 hours ago

Company Info

About Judge Group, Inc.

The Judge Group, is a leading professional services firm specializing in talent, technology, and learning solutions. We consult, staff, train, and solve. Through our work we make people and organizations better.

Our services are successfully delivered through a network of more than 30 offices across the United States, Canada, and India. The Judge Group is proud to partner with the best and brightest companies in business today, including over 60 of the Fortune 100. We serve organizations in financial services, healthcare, life sciences, insurance, government (including aerospace and defense), manufacturing, and technology and telecommunications.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Malvern, Pennsylvania

Today

Contract

Malvern, Pennsylvania

Today

Contract

West Conshohocken, Pennsylvania

Today

Contract

USD 200,000.00 - 250,000.00 per year

Burlington, New Jersey

Today

Contract

USD 120,000.00 - 145,000.00 per year

Search all similar jobs