Talent.com
Sr. Application Security Engineer
Sr. Application Security EngineerOpenGov • Boston, MA, United States
Sr. Application Security Engineer

Sr. Application Security Engineer

OpenGov • Boston, MA, United States
1 day ago
Job type
  • Full-time
Job description

OpenGov is the leader in AI and ERP solutions for local and state governments in the U.S. More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov Public Service Platform to operate efficiently, adapt to change, and strengthen the public trust. Category-leading products include enterprise asset management, procurement and contract management, accounting and budgeting, billing and revenue management, permitting and licensing, and transparency and open data. These solutions come together in the OpenGov ERP, allowing public sector organizations to focus on priorities and deliver maximum ROI with every dollar and decision in sync. Learn about OpenGov's mission to power more effective and accountable government and the vision of high-performance government for every community at OpenGov.com.

Summary

The Senior Application Security Engineer is a technical leader responsible for ensuring the security, integrity, and resilience of our cloud-native SaaS applications. This role partners closely with Software Engineering, Product, DevOps, and Security Operations to embed security into every phase of the SDLC. The ideal candidate is hands-on, highly collaborative, and capable of scaling AppSec processes that align with best practices, regulatory requirements, and the needs of a rapidly growing technology organization.

Key Responsibilities

Embed security into CI / CD pipelines through scalable guardrails, automated security checks, and continuous improvements to developer workflows.

Drive adoption of secure coding best practices across engineering teams through tooling, guidance, and direct partnership.

Lead threat modeling exercises for high-risk features and new architecture patterns.

Own, maintain, and tune AppSec tooling including SAST, DAST, SCA, secrets scanning, container scanning, and dependency management.

Partner with DevOps to ensure automated testing integrates into build, test, and deploy workflows with high signal-to-noise and minimal developer friction.

Evaluate emerging technologies and automation opportunities to strengthen AppSec capabilities.

Lead triage, prioritization, and root-cause analysis for application vulnerabilities discovered through internal testing, bug bounty programs, pentests, and external researchers.

Ensure timely remediation through strong cross-functional partnership, driving the right balance of risk, velocity, and operational maturity.

Support security reviews, pen test scoping, and remediation programs tied to GovRAMP, SOC 2, and customer requirements.

Conduct manual reviews of critical code paths, APIs, backend services, and cloud components to identify security defects that automation may miss.

Advise on secure design patterns for microservices, cloud-native architectures, authentication / authorization mechanisms, secrets management, and data protection.

Collaborate with Security Operations during active incidents involving application or product vulnerabilities.

Perform deep-dive analysis of new vulnerabilities, exploit techniques, frameworks, and supply-chain risks affecting our tech stack.

Mentor engineering teams on secure design, secure coding, and modern AppSec patterns.

Lead internal workshops, brown bags, and knowledge-sharing sessions.

Contribute to internal AppSec documentation, policies, and secure development standards.

Qualifications Required

6+ years of application security, secure development, or software engineering experience (or equivalent real-world experience).

Strong knowledge of modern application architectures : microservices, REST / GQL APIs, React / Node / Java / Kotlin / Go, containerized workloads, Kubernetes.

Hands-on experience with SAST, DAST, SCA, secrets scanning, container scanning, and CI / CD integration.

Expertise in OWASP Top 10, ASVS, SANS CWE Top 25, and secure coding principles.

Ability to perform threat modeling, code review, and architecture analysis.

Experience partnering with Engineering to drive remediation and long-term maturity improvements.

Preferred

Experience in SaaS, multi-tenant systems, or high-scale cloud environments (AWS preferred).

Familiarity with SOC 2, GovRAMP, & TX-RAMP.

Prior background in DevOps, software engineering, or cloud security.

Compensation :

Boston, MA : $140,000 - $167,500

On target ranges above include base plus a portion of variable compensation that is earned based on company and individual performance.

The final compensation will be determined by a number of factors such as qualifications, expertise, and the candidate's geographical location.

Why OpenGov?

A Mission That Matters.

At OpenGov, public service is personal. We are passionate about our mission to power more effective and accountable government. Government that operates efficiently, adapts to change, and strengthens public trust. Some people say this is boring. We think it's the core of our democracy.

Opportunity to Innovate

The next great wave of innovation is unfolding with AI, and it will impact everything-from the way we work to the way governments interact with their residents. Join a trusted team with the passion, technology, and expertise to drive innovation and bring AI to local government. We've touched 2,000 communities so far, and we're just getting started.

A Team of Passionate, Driven People

This isn't your typical 9-to-5 job; we operate in a fast-paced, results-driven environment where impact matters more than simply clocking in and out. Our global team of 800+ employees is united in our commitment to challenge the status quo. OpenGov is headquartered in San Francisco and has offices in Atlanta, Boston, Buenos Aires, Chicago, Dubuque, Plano, and Pune.

A Place to Make Your Mark

We pride ourselves on our performance-based culture, where every employee is encouraged to jump in head-first and take action to help us improve. If you have a great idea, we want to hear it. Excellent performance is recognized and rewarded, and we love to promote from within.

Compensation Range : $140K - $167.5K

Create a job alert for this search

Application Security Engineer • Boston, MA, United States

Related jobs
Security Engineer

Security Engineer

Nutanix • Boston, MA, United States
Full-time
Hungry, Humble, Honest, with Heart.Are you a forward-thinking security professional with a passion for implementing cutting-edge technology and a strong understanding of Zero Trust principles? If s...Show more
Last updated: 6 hours ago • Promoted • New!
Senior Product Security Engineer

Senior Product Security Engineer

Mondo • Danvers, MA, United States
Full-time
Apply now : Senior Product Security Engineer, location is Remote.The start date is February 24th for this contract position. Senior Product Security Engineer.February 24th (to participate in a three-...Show more
Last updated: 2 days ago • Promoted
Security Engineer

Security Engineer

Eastern Bank • Wakefield, MA, United States
Full-time
Open to Remote workers in certain states : CT, FL, ME, MA, NH, NY (except the 5 boroughs) , RI, SC, VT.Protecting enterprise systems and information by promptly responding to security threats and in...Show more
Last updated: 30+ days ago • Promoted
Sr. Application Security Engineer

Sr. Application Security Engineer

Glaukos Corporation • Burlington, MA, United States
Full-time
As an Application Security Engineer, you will play a critical role in securing the software that powers our medical devices and offer your expertise as we develop other applications such as mobile ...Show more
Last updated: 23 days ago • Promoted
Sr Security Analyst

Sr Security Analyst

Kyyba • Quincy, MA, United States
Full-time
Our client Public sector client is looking for a talented.Founded in 1998 and headquartered in Farmington Hills, MI, Kyyba has a global presence delivering high-quality resources and top-notch recr...Show more
Last updated: 30+ days ago • Promoted
Workday Application Security & Controls Director

Workday Application Security & Controls Director

PwC • Boston, MA, United States
Full-time
Workday Application Security & Controls Director.Workday Application Security & Controls Director.Be among the first 25 applicants. Specialty / Competency : Workday.Industry / Sector : Not Applicable....Show more
Last updated: 6 days ago • Promoted
Product Security Engineer

Product Security Engineer

Bose • Framingham, MA, United States
Full-time
It's the first notes of that song you love, the intro to your favorite movie, or simply the sound of someone you love saying "hello. It's in these moments that sound matters most.At Bose, we believe...Show more
Last updated: 2 days ago • Promoted
Sr. Reliability Engineer

Sr. Reliability Engineer

Raytheon • Westford, Massachusetts, US
Permanent
While professional experience and qualifications are key for this role, make sure to check you have the preferable soft skills before applying if required. MA133 : Tewksbury, Ma Bldg 3 Concord 50 App...Show more
Last updated: 29 days ago • Promoted
Application Security Engineer (AppSec)

Application Security Engineer (AppSec)

ACL Digital • Westford, MA, United States
Full-time
Titile : Application Security Engineer.We are seeking a skilled Application Security Engineer (AppSec) with expertise in Secure Software Development Life Cycle (SSDLC) and DevSecOps practices to joi...Show more
Last updated: 23 days ago • Promoted
Sr. Security Operations Engineer

Sr. Security Operations Engineer

OpenGov • Boston, MA, United States
Full-time
OpenGov is the leader in AI and ERP solutions for local and state governments in the U.More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov ...Show more
Last updated: 5 days ago • Promoted
Enterprise Security Sr Analyst

Enterprise Security Sr Analyst

Enbridge • Waltham, MA, United States
Full-time
Join Our Enbridge Team as an Enterprise Security Sr Analyst!.Are you ready to play a vital role in shaping and strengthening the security backbone of a dynamic organization? Then look no further as...Show more
Last updated: 1 day ago • Promoted
Product Security Engineer

Product Security Engineer

Omni Inclusive • Danvers, MA, United States
Full-time
Security risk management techniques Regulatory standards and compliance frameworks (e.NIST Cybersecurity Framework,ISO27001, SOC2, HIPAA, GDPR) Pre-market product development activities Medical dev...Show more
Last updated: 2 days ago • Promoted
Application Security Engineer

Application Security Engineer

ISC2 • Boston, MA, United States
Full-time
As the world's leading nonprofit member organization for cybersecurity professionals, our core values - Integrity, Advocacy, Commitment, Inclusion, and Excellence - drive everything we do in suppor...Show more
Last updated: 2 days ago • Promoted
Physical Security Systems Application Specialist

Physical Security Systems Application Specialist

Massachusetts General Hospital • Boston, MA, United States
Full-time
Responsible for providing, designing, developing, testing, implementing and ongoing maintenance of new and existing software applications. The Physical Security Systems Application Specialist is res...Show more
Last updated: 1 day ago • Promoted
Security Engineer

Security Engineer

Zoom Corporation • Boston, MA, United States
Full-time
The Security Engineer is responsible for security design and reviews across our products and services, with a specific focus on Platform services and core infrastructure components.The ideal candid...Show more
Last updated: 3 days ago • Promoted
Senior Application Security Engineer (Hybrid - US)

Senior Application Security Engineer (Hybrid - US)

EnergySolutions • Boston, MA, United States
Full-time
Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus ...Show more
Last updated: 23 days ago • Promoted
Sr. Product Security Engineer II

Sr. Product Security Engineer II

IBM • Lowell, MA, United States
Full-time
A career in IBM Software means you'll be part of a team that transforms our customer's challenges into industry-leading solutions. We are an infinitely curious team, always seeking new possibilities...Show more
Last updated: 6 hours ago • Promoted • New!
Principal SaaS Security Engineer

Principal SaaS Security Engineer

PTC • Boston, MA, United States
Full-time
Principal SaaS Security Engineer - Hybrid - Boston.Onshape is a next-generation, global Software-as-a-Service (SaaS) product development platform. The role focuses on security operations and continu...Show more
Last updated: 9 days ago • Promoted