Application Security Engineer
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Oct 2, 2026
We are seeking an Application Security Engineer to join our Cyber Defense & Engineering (CDE) team who will be responsible to establish, scale, and own the Application Security operating model across a decentralized product engineering organization undergoing cloud modernization. They will be focused on creating a scalable AppSec capability rather than managing a legacy program. They will design risk-tiering frameworks, integrate automated security gates into CI/CD pipelines, lead threat modeling for cloud migrations, and establish a Security Champions network to embed secure coding practices directly into development teams.
Type: 6 months contract-to-hire
Location: Philadelphia, PA 19103 (Onsite Preferred/Remote for the right talent)
Key Responsibilities
Catalog applications, development pipelines, source repositories, and existing security tools across decentralized teams to establish an accurate baseline.
Create and deploy a risk-tiering framework to prioritize security efforts and resources on high-risk applications.
Define, publish, and socialize a minimum application security baseline across engineering leadership regardless of team tooling or SDLC variations.
Build, launch, and lead a Security Champions network across distributed product engineering teams to scale security practices natively.
Lead threat modeling exercises (STRIDE/PASTA) for monolith-to-microservices re-architecture, containerization, and cloud migration projects.
Provide technical architectural guidance during cloud migration decisions to identify security trade-offs before architecture is locked.
Integrate static and dynamic security testing tools seamlessly into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins).
Triage, validate, and prioritize vulnerabilities from automated scanners, penetration tests, bug bounty programs, and detection alerts.
Partner with Security Operations and Incident Response teams on application-layer incidents, analyzing attack paths and exploit feasibility.
Define and track key performance indicators for application coverage, risk tiering, vulnerability density, and remediation velocity.
Evaluate and enforce secure authentication and authorization implementation, including OAuth 2.0, OIDC, SAML, and session management.
Review unfamiliar codebases across diverse languages, configure security scanning engines, and partner with developers to guide remediation.
Required Skills & Experience
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
4+ years of combined experience in software engineering, cloud engineering, or application security, including direct hands-on security responsibilities.
Demonstrated capability in executing threat modeling frameworks (STRIDE, PASTA, or equivalent) and translating findings into actionable developer tasks.
Strong technical depth in OWASP Top 10, OWASP ASVS, CWE Top 25, and modern attack patterns against web applications, REST APIs, and microservices.
Experience embedding security tooling into modern CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins).
Solid working knowledge of enterprise authentication and authorization standards (OAuth 2.0, OIDC, SAML) and session security.
Familiarity with containerization and cloud-native architecture (Docker, Kubernetes) and their associated security vectors.
Ability to communicate risk and remediation guidance to engineering audiences in language they will accept and act on.
Preferred Qualifications
Experience configuring and tuning enterprise code scanning platforms (Fortify, Veracode, Wiz Code).
Exposure to Azure/AWS security controls, CSPM, and CNAPP tooling (e.g., Wiz).
Hands-on experience with API security testing, runtime application protection (RASP), and WAF tuning.
Active professional security certifications such as OSCP, OSWE, GWAPT, GPEN, or CISSP.
Familiarity with supply chain security frameworks (SLSA, S2C2F, OpenSSF Scorecard).
Prior work in a distributed, multi-tenant, or franchise-like operational environment.