{"id":1332946,"url":"https://alion.io/job/verisign-senior-application-security-engineer","title":"Senior Application Security Engineer","company":{"id":1753436,"name":"VERISIGN","domain":"verisign.com","url":"https://alion.io/company/verisign-com","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"A","score":95,"open_postings":4,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":66,"computed_at":"2026-10-07T05:47:15Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Reston, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":164300,"max":222300,"currency":"USD","period":"year","gross":null,"usd_annual":222300},"salary_estimate":null,"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"CI/CD","optional":false},{"name":"DNS","optional":false},{"name":"Fortify","optional":false},{"name":"LLM","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Agile","optional":true},{"name":"C++","optional":true},{"name":"Java","optional":true},{"name":"Kanban","optional":true},{"name":"Linux","optional":true},{"name":"Perl","optional":true},{"name":"Python","optional":true},{"name":"Rust","optional":true},{"name":"Scrum","optional":true}],"status":"live","first_seen_at":"2026-09-23T11:07:30Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-10-08T00:53:27Z","board_verified":true,"closed_at":null,"days_open":14,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":14},"description":"Verisign helps enable the security, stability, and resiliency of the internet. We are a trusted provider of internet infrastructure services for the networked world and deliver unmatched performance in domain name system (DNS) services. \nWe are a mission focused, values driven company where each individual can contribute to building a stronger, more secure internet. We offer a dynamic and flexible work environment with competitive benefits and the ability to grow your career.\nThe Senior Application Security Engineer will play a lead role in securing all software built and/or used by Verisign. The engineer will work with application development teams as well as 3rd party organizations to ensure that security, privacy, and compliance are built into applications from design through production. The engineer should be a technical leader helping determine the future of the application security program and actively participating in a broad spectrum of activities by leading assessments, following security research and best practices, and helping set the standards of the program. The individual should possess strong interpersonal skills, be highly motivated, results oriented, have excellent communication and presentation skills, and be a strong team player.\nResponsibilities:\nServe as the application security subject matter expert for development teams during requirement, design, and architecture phases, including application threat modeling for new and significantly changed applications\nPerform and lead deep dive manual and automated application vulnerability assessments, documenting findings, and provide clear remediation guidance to the responsible engineering teams\nOwn the application security vulnerability management lifecycle across the security toolchain, including software composition analysis, static and dynamic testing, interactive testing, secrets scanning\nReview and provide remediation guidance for submissions from Verisign’s public Bug Bounty program\nTrack open issues against defined SLAs, follow up with development teams, and escalate overdue items to engineering and InfoSec leadership\nProvide guidance to support integration of security testing into CI/CD pipelines\nReview third party and vendor supplied applications against internal security requirements\nMentor junior engineers and analysts, review peer work, and provide constructive feedback\nContribute to Information Security standards, secure coding guidance, and be an active participant in the broader Verisign technical community\nAI and Application Security:\nAssess applications that embed large language models or other AI services for risks such as prompt injection, sensitive data exposure, insecure output handling, and over permissioned agents and integrations\nDevelop and maintain internal guidance for developers using AI coding assistants, including expectations for review, testing, and scanning of AI generated code\nEvaluate and pilot AI assisted capabilities within the application security workflow such as finding triage, false positive reduction, and remediation guidance\nTrack developments in AI security guidance and standards and translate them into practical internal requirements and guidance\nKey skills and experience:\n10+ years’ experience in Information Technology, including hands on application development experience\n6+ years’ experience conducting application security assessments using COTS and open-source tooling (Burp Suite, Fortify, or equivalent)\nHands-on experience with software composition analysis, dynamic application security testing, and secrets scanning platforms\nExperience running a vulnerability management program through ticketing and workflow systems, including SLA definition and executive level reporting\nStrong working knowledge of the OWASP Testing Framework and OWASP Top 10\nProficiency in currently accepted software development life cycles and associated standards and procedures\nKnowledge of current application architectures (Single Page Application, 3 tier, microservices, containerized workloads)\nPractical familiarity with AI and LLM application security risks and current industry guidance in that area\nMethodical and organized, able to manage multiple opportunities, projects, and partners concurrently\nAble to multitask and work independently with minimum supervision to meet firm deadlines\nExcellent communication, presentation, and leadership skills, including the ability to present to senior technical and non-technical audiences\nPreferred skills and experience:\n6+ years software development using Java, C++, Rust, Go and/or scripting languages such as Python or Perl\nExperience implementing security assessments within a Continuous Integration pipeline\nAdvanced experience with Linux operating systems, high comfort level with working at the command line\nUnderstanding of Agile methodologies (Kanban, Scrum, pair programming, etc.)\nUnderstanding of DevOps and security integration\nExperience with API security testing\nExperience running or supporting a public or private bug bounty program\nThis position is based in our Reston, VA office and offers a hybrid work schedule.\nThe pay range is $164,300 - $222,300.\nThe anticipated annual base salary range for this position is noted above, however, base pay offered may vary depending on job-related knowledge, skills, experience. Verisign offers a discretionary bonus which is based on individual and company performance, and certain roles may be eligible for discretionary stock awards.\nVerisign is an equal opportunity employer. That means we recruit, hire, compensate, train, promote, transfer, and administer all terms and conditions of employment without regard to their race, color, religion, national origin, sex, sexual orientation, gender identity, age, protected veteran status, disability, or other protected categories under applicable law.\nAdditional Information:\nOur Careers Page\nOur Benefits Summary\nVerisign in the Community\nOur EEO Statement\nOur Privacy Notice for Job Applicants/Candidates\nReasonable Accommodations\nStaffing agency policy: No fees will be paid for unsolicited resumes submitted to Verisign or our employees by third parties.","description_format":"text","description_chars":6175,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Flexible schedule","Hybrid work"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Domain Registrars & Registries","DNS Services"],"lifecycle":[{"event":"open","at":"2026-09-27T13:16:52Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 15 · green card filings: 2","filings_12m":15,"filings_prev_12m":18,"green_card_filings_12m":2,"median_offered_wage_usd":163382,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)","US Department of Labor: PERM disclosure data (green cards)"],"filings_for_role_12m":1}],"liveness":{"score":88,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.881,"p_room":1,"age_days":13,"expected_fill_days":66,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-10-07T05:47:15Z"},"pay":{"stated_usd_annual":222300,"is_top_pay":true},"html_url":"https://alion.io/job/verisign-senior-application-security-engineer","json_url":"https://alion.io/job/verisign-senior-application-security-engineer.json","meta":{"generated_at":"2026-10-08T02:34:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4441,"day_limit":5000,"remaining_today":559,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":1753436},"rest":"https://alion.io/mcp/rest/get_company?id=1753436"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fverisign-senior-application-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fverisign-senior-application-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fverisign-senior-application-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/verisign-senior-application-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fverisign-senior-application-security-engineer"}]}