428,624open jobs
14,649companies
61,350added this week
Browse all
Salary
$104k – $194k per year
Location
Remote (United States)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in the United States.

This is a senior application security opportunity for an engineer who combines strong software development experience with deep security and DevSecOps expertise.

You will help embed security throughout the software development lifecycle, from secure coding and threat modeling to automated testing and production deployment.

The role works closely with engineering and DevOps teams to strengthen cloud-native applications, APIs, CI/CD pipelines, and infrastructure.

You will also help establish secure governance around emerging agentic AI coding technologies and address new risks introduced by AI-assisted development.

Your expertise will contribute to meeting demanding security and compliance requirements across standards such as PCI-DSS, GDPR, CCPA, and SOC 2.

You will influence engineering practices, develop security metrics, communicate risks to leadership, and mentor other engineers.

This is an ideal role for a hands-on security professional who wants to shape application security strategy while remaining close to technology and engineering teams.

Accountabilities:

    • Partner with DevOps and engineering teams to design, implement, and maintain secure CI/CD pipelines with security controls and testing integrated throughout the software development lifecycle.
    • Implement, configure, and continuously improve automated security testing, including SAST, DAST, software composition analysis (SCA), vulnerability scanning, and container security.
    • Deploy and support API security solutions while ensuring security findings are consistently captured, centralized, tracked, and addressed.
    • Collaborate with development teams to promote secure coding practices and provide practical security guidance throughout application design, development, testing, and deployment.
    • Establish and strengthen application security practices for cloud-native environments, including appropriate controls for identity, networking, encryption, secrets, and infrastructure.
    • Evaluate the secure adoption of agentic and AI-assisted coding tools across engineering teams and establish appropriate guardrails, governance, detection, and risk-mitigation strategies.
    • Identify and address AI-specific application security risks, including hallucinated or vulnerable dependencies, insecure code generation, malicious code injection, and insufficient human oversight.
    • Support compliance with applicable security and privacy standards, including PCI-DSS, GDPR, CCPA, and SOC 2.
    • Develop application security KPIs, metrics, dashboards, and reporting to demonstrate program effectiveness and communicate findings to leadership.
    • Conduct or support threat modeling, security assessments, penetration testing, and risk analysis across applications and technology environments.
    • Contribute to security architecture decisions and help engineering teams build resilient, secure applications and APIs.
    • Mentor junior security engineers and developers while promoting a security-first culture across engineering organizations.
    • Support emerging security initiatives involving AI/ML systems, model security, data pipeline protection, and AI/ML supply-chain risks.
    • Stay current on application security threats, emerging technologies, development practices, and industry trends to continuously improve the security program.
    • Requirements

      • 5+ years of professional software development experience, with strong proficiency in three or more programming or scripting languages such as Python, Go, Java, C#, Ruby, JavaScript/TypeScript, Bash, PowerShell, Swift, Kotlin, Objective-C, or Dart.
      • 3+ years of hands-on experience in application security, DevSecOps, or a closely related security engineering discipline.
      • Strong understanding of the OWASP Top 10 and modern secure software development practices.
      • Deep knowledge of API security, authentication protocols, authorization, and secure API design.
      • Strong cloud security expertise with at least one major cloud platform such as AWS, Azure, or GCP; multi-cloud experience is highly valuable.
      • Understanding of cloud-native security concepts including IAM, network security, encryption, secrets management, workload protection, and compliance.
      • Hands-on experience with CI/CD technologies such as Jenkins, GitLab CI/CD, GitHub Actions, CircleCI, or Azure DevOps.
      • Experience with infrastructure-as-code, containerization, and orchestration technologies such as Terraform, Docker, Kubernetes, Helm, or Ansible.
      • Familiarity with application security tools including SAST/DAST scanners, SCA solutions, WAFs, SIEM platforms, vulnerability scanners, and secrets-management technologies.
      • Experience with AI-assisted or agentic development tools such as GitHub Copilot, Cursor, Claude Code, or similar technologies, along with a strong understanding of their security implications.
      • Experience establishing governance and guardrails for safe adoption of AI-assisted software development tools.
      • Knowledge of threat modeling methodologies, security risk assessment frameworks, and the ability to communicate technical risks effectively to both technical and non-technical stakeholders.
      • Knowledge of compliance requirements and frameworks including PCI-DSS, GDPR, CCPA, and SOC 2.
      • Background in penetration testing, red-team operations, or offensive security is highly valuable.
      • Familiarity with MLSecOps, including model security, data pipeline protection, and AI/ML supply-chain security.
      • Security certifications such as CISSP, GIAC, OSCP, AWS Security Specialty, Azure Security Engineer, or equivalent are advantageous.
      • Experience in travel, hospitality, e-commerce, or another high-volume digital industry is a plus.
      • Strong communication, mentoring, collaboration, and problem-solving skills, with the ability to influence engineering teams and promote security best practices.
      • Ability to work independently while partnering effectively across engineering, DevOps, security, and other technology functions.
      • Benefits

        • Base salary: $104,300-$193,700 USD annually, with actual compensation based on role scope, complexity, experience, skills, knowledge, and work location.
        • Eligibility for a discretionary annual bonus based on individual and organizational performance.
        • Comprehensive U.S. benefits programs covering health and welfare, retirement, parental leave, adoption assistance, and wellbeing resources.
        • Flexible benefits designed to support employees and their families.
        • Travel-related employee perks, including access to deals on flights, hotels, cruises, car rentals, and other travel services.
        • Access to 20,000+ learning courses, leadership development programs, and ongoing professional development opportunities.
        • Opportunities to grow technical and leadership skills within a collaborative global environment.
        • Remote work opportunity within the United States.
        • Inclusive workplace culture that values collaboration, diverse perspectives, and employee development.
        • Reasonable accommodations available for qualified individuals with disabilities throughout the recruitment process.
        • Opportunity to work with modern cloud-native technologies, application security tooling, DevSecOps practices, and emerging AI security capabilities.
        • Opportunity to influence security strategy and help shape secure software development practices at scale.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
428,624 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$25k – $62k per year (Estimated) • Remote • Full-Time • 12+ years exp • Bachelor's Degree • Hyderabad
Python
JavaScript
TypeScript
Python
FastAPI
Databases
PostgreSQL
Frontend
Angular
React.js
DevOps
CI/CD
AWS
Docker
Kubernetes
Apply
$79k – $170k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Belfast
Python
Java
SQL
Databases
Snowflake
DynamoDB
Apache Kafka
AI/ML
Claude
Spark
dbt
Function Calling
AI Agents
OpenAI
Multi-Agent Systems
Tool Use
DevOps
Terraform
CI/CD
AWS
Kubernetes
Grafana
Amazon EKS
AWS Lambda
GitLab
Amazon S3
IAM
Amazon Kinesis
Amazon EventBridge
AWS Step Functions
Analytics
QlikSense
ETL/ELT
AWS Glue
Alation
Apply
AI Senior Engineer 2 days ago
$141k – $247k per year (Estimated) • Remote • Full-Time • 7+ years exp • Bachelor's Degree
Python
SQL
DevOps
Azure
Apply
$122k – $215k per year (Estimated) • Remote • Top Secret • Full-Time • 3+ years exp • Bachelor's Degree
Python
DevOps
GCP
Azure
AWS
Cybersecurity
SOC 2
Apply
$114k – $150k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
Databases
Oracle
MS SQL
Amazon Redshift
DevOps
Azure DevOps
Azure
CI/CD
Git
AWS
Amazon S3
Cybersecurity
HIPAA
Analytics
Power BI
ETL/ELT
Apply
$118k – $180k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree
Python
MATLAB
Analytics
Microsoft Excel
Apply
$87k – $172k per year (Estimated) • Remote • Contractor • 5+ years exp
JavaScript
DevOps
GitHub
Management
ClickUp
QA
Selenium
Cypress
Playwright
BrowserStack
Apply
$19k – $44k per year (Estimated) • Remote • Contractor • 5+ years exp
JavaScript
DevOps
GitHub
Management
ClickUp
QA
Selenium
Cypress
Playwright
BrowserStack
Apply
$76k – $159k per year (Estimated) • Remote • Contractor • 5+ years exp
JavaScript
DevOps
GitHub
Management
ClickUp
QA
Selenium
Cypress
Playwright
BrowserStack
Apply
$37k – $89k per year (Estimated) • Remote • Contractor • 5+ years exp
JavaScript
DevOps
GitHub
Management
ClickUp
QA
Selenium
Cypress
Playwright
BrowserStack
Apply
See all jobs
This is one of many
428,624 more open roles from verified company boards, updated every day.