{"id":2057349,"url":"https://alion.io/job/purpose-brands-application-security-engineer","title":"Application Security Engineer","company":{"id":2231944,"name":"Purpose Brands","domain":"purposebrands.com","url":"https://alion.io/company/purposebrands-com","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Boca Raton, United States","Seattle, United States","United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":73000,"max_usd":145000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":318},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"Clair","optional":false},{"name":"Dependabot","optional":false},{"name":"GitHub","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"Syft","optional":false}],"status":"live","first_seen_at":"2026-10-07T00:00:00Z","employer_posted_date":"2026-10-07","last_verified_at":"2026-10-10T21:35:48Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Purpose Brands, the parent company of Orangetheory, Anytime Fitness, Waxing the City, and The Bar Method, is seeking a Application Security Engineer to join its team. This is a great position for someone who is looking to expand their career, and join a company with a fun, fast-paced and inspirational culture.The Application Security Engineer will report to the Staff Security Engineer and will be responsible for advancing application security capabilities as part of a DevSecOps operating model. This role focuses on embedding security controls, automation, and secure development practices directly into the software delivery lifecycle for cloud-based applications.\nThe Application Security Engineer will report to the Staff Security Engineer and will be responsible for advancing application security capabilities as part of a DevSecOps operating model. This role focuses on embedding security controls, automation, and secure development practices directly into the software delivery lifecycle for cloud-based applications.\nThe Application Security Engineer will partner closely with software engineering, DevOps, and cloud teams to mature security processes, improve vulnerability detection and remediation workflows, and reduce risk without slowing delivery. This position emphasizes hands-on application security engineering, security tooling integration, and developer enablement across applications deployed in AWS and Azure environments.\nPurpose/Impact: (Duties & Essential Functions)\nApplication Security & Secure SDLC\nEmbed application security practices into all phases of the software development lifecycle (SDLC), from design through deployment and maintenance \nPerform application security assessments including static code analysis (SAST), dynamic testing (DAST), and software composition analysis (SCA) \nDevelop and maintain threat models for critical systems and applications, collaborating with engineering teams to identify threats, assess risk, and drive remediation efforts \nPromote secure coding practices and contribute to secure development standards aligned with OWASP and industry best practices \nDevSecOps Enablement & Automation\nPartner with engineering and DevOps teams to integrate security tooling into CI/CD pipelines, enabling automated and repeatable security testing \nAnalyze and manage vulnerability findings from tools such as GitHub Advanced Security, Syft, Clair, Qualys, etc. \nHelp tune security tooling to reduce false positives and improve signal quality for development teams \nSupport the adoption of security automation to improve consistency, efficiency, and scalability across application environments \nCloud & Platform Security Collaboration\nAssist in securing applications deployed across AWS and Azure, including workloads running on IaaS, PaaS, and container-based platforms \nIdentify risks to the confidentiality, integrity, and availability of application data hosted in cloud-based environments \nCollaborate with cloud and platform security engineers to ensure application security controls align with broader cloud security architecture \nOwn and curate security controls within the Cloud Engineering and Platform Engineering space that align with security frameworks and controls like NIST CSF, CIS Benchmarks, and CSA CCM \nRisk Management, Monitoring & Response\nTriage, prioritize, and track remediation of application vulnerabilities based on risk and business impact \nAssist in security investigations involving application vulnerabilities or security events \nParticipate in periodic reviews of application security controls to validate effectiveness and compliance with organizational standards \nCollaboration & Continuous Improvement\nAct as a security partner to engineering teams by providing guidance, education, and actionable recommendations \nContribute to the continuous improvement of application security processes, standards, and metrics \nSupport governance, risk management, and compliance initiatives as they relate to application security \nQUALIFICATIONS\nBachelor’s degree in Computer Science, Information Systems, Engineering, or a related field \n3-5 years of experience in application security, security engineering, or software engineering with a strong security focus \nHands-on experience performing code reviews and application security testing across modern languages, frameworks, and APIs \nExperience working with application security tools such as SAST, DAST, and dependency scanning (e.g., GitHub Dependabot or similar) \nStrong understanding of OWASP Top 10, secure coding principles, authentication/authorization, and API security \nPractical experience supporting applications running in AWS and/or Azure cloud environments \nFamiliarity with CI/CD pipelines, DevOps workflows, and DevSecOps concepts \nAbility to communicate security risks and remediation guidance clearly to developers and non-security stakeholders \nStrong analytical skills with the ability to balance security risk with delivery velocity \nPreferred certifications include:\nSecurity+, CSSLP, GWAPT, GWEB, CEH, GPEN or other application security-focused certifications\nWhat’s in it for you?\nWe offer a competitive salary along with exceptional benefits such as:\nMedical, Dental and Vision Coverage\nHybrid Work Environment\nLife and Disability Insurance\nUnlimited Time off + Paid Holidays\nFlexible Friday's between Memorial Day and Labor Day\n401(K) Savings Plan Matching at 4%\n10 Coaching and Therapy sessions\nMental Health Benefits\nBrand Discounts & Reimbursements\nIn-house workout facilities\nProfessional Development Opportunities\nTeam Building, Employee Engagement Activities & so much more\nWORK SCHEDULE\nPurpose Brands LLC, currently observe the following hybrid work model for employees at our Boca Raton (FL), Woodbury (MN), and Seattle (WA) offices:\nRemote optional: Fridays\nOn-site days: Mondays, Tuesdays, Wednesdays and Thursdays\nDIVERSITY, EQUITY, AND INCLUSION STATEMENT\nPurpose Brands is committed to encouraging, facilitating, and upholding an environment centered on diversity, equity, and inclusion across every facet of the Purpose Brands. We will work to create a sustainable culture that supports a healthy space for learning and growing, valuing, and empowering every employee, inspiring a diverse franchise network, and uplifting the members and communities we serve.\n EEO STATEMENT\nPurpose Brands provides equal employment opportunity to all individuals regardless of their race, color, creed, religion, gender, age, sexual orientation, national origin, disability, veteran status, or any other characteristic protected by state, federal, or local law. Discrimination of any type will not be tolerated.","description_format":"text","description_chars":6674,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Equity","Hybrid work","Professional development"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"},{"name":"Florida","iso":null,"kind":"city"},{"name":"Minnesota","iso":null,"kind":"city"},{"name":"Washington","iso":null,"kind":"city"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Fitness"],"lifecycle":[{"event":"open","at":"2026-10-08T00:26:36Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":3,"expected_fill_days":30,"reasons":["conf:1","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/purpose-brands-application-security-engineer","json_url":"https://alion.io/job/purpose-brands-application-security-engineer.json","meta":{"generated_at":"2026-10-11T01:05:54Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1508,"day_limit":5000,"remaining_today":3492,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2231944},"rest":"https://alion.io/mcp/rest/get_company?id=2231944"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fpurpose-brands-application-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fpurpose-brands-application-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fpurpose-brands-application-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/purpose-brands-application-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fpurpose-brands-application-security-engineer"}]}