← Back to job listings
AR
Application Security Engineer
Arcadia · United States
About The Role
Join our Information Security team as an Application Security Engineer. In this role, you will own the vulnerability management lifecycle, integrate security automation into the CI/CD pipeline, perform threat modeling, and serve as a trusted advisor to our engineering organization. You will also launch and run a Security Champions program and act as the application-layer subject matter expert during security incidents. The ideal candidate has 3-5 years of dedicated Application Security experience in a SaaS or cloud-native environment and strong knowledge of CI/CD pipelines.
- Own the end-to-end vulnerability management lifecycle, including triage, prioritization, and driving remediation of findings from security tooling.
- Maintain, optimize, and extend security tooling integrations within the CI/CD pipeline, with the goal of automating security processes.
- Launch and run a Security Champions program, including workshops and office hours, to embed security knowledge directly into development teams.
- The ideal candidate is a builder who would rather automate a finding than file a ticket, and who can explain a critical vulnerability to a junior developer without making them feel two inches tall
- Strong working knowledge of CI/CD pipelines (e.g., GitHub Actions, Jenkins, GitLab CI) and the ability to write and maintain pipeline integrations
- Hands-on proficiency with at least two of the following: SAST, DAST, SCA, or CSPM tooling (e.g., Snyk, Checkmarx, Semgrep, Wiz)
- 3–5 years of dedicated Application Security experience in a SaaS or cloud-native environment
- Experience with container security (Docker, Kubernetes) and API security patterns (REST, GraphQL)
- Demonstrated ability to communicate technical risk to non-security engineers in a way that drives action, not anxiety
- Exposure to threat modeling frameworks (STRIDE, PASTA, or lightweight equivalents)
- Relevant certifications (OSCP, GWAPT, CSSLP) — valued but not required
- Familiarity with cloud-native AWS security services (GuardDuty, Security Hub, IAM Access Analyzer)
- Experience standing up or maturing a Security Champions program
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring