Talent.com
Sr. Application Security Engineer
Sr. Application Security EngineerOpenGov • San Francisco, CA, United States
Sr. Application Security Engineer

Sr. Application Security Engineer

OpenGov • San Francisco, CA, United States
6 days ago
Job type
  • Full-time
Job description

OpenGov is the leader in AI and ERP solutions for local and state governments in the U.S. More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov Public Service Platform to operate efficiently, adapt to change, and strengthen the public trust. Category-leading products include enterprise asset management, procurement and contract management, accounting and budgeting, billing and revenue management, permitting and licensing, and transparency and open data. These solutions come together in the OpenGov ERP, allowing public sector organizations to focus on priorities and deliver maximum ROI with every dollar and decision in sync. Learn about OpenGov's mission to power more effective and accountable government and the vision of high-performance government for every community at OpenGov.com.

Summary

The Senior Application Security Engineer is a technical leader responsible for ensuring the security, integrity, and resilience of our cloud-native SaaS applications. This role partners closely with Software Engineering, Product, DevOps, and Security Operations to embed security into every phase of the SDLC. The ideal candidate is hands-on, highly collaborative, and capable of scaling AppSec processes that align with best practices, regulatory requirements, and the needs of a rapidly growing technology organization.

Key Responsibilities

Embed security into CI / CD pipelines through scalable guardrails, automated security checks, and continuous improvements to developer workflows.

Drive adoption of secure coding best practices across engineering teams through tooling, guidance, and direct partnership.

Lead threat modeling exercises for high-risk features and new architecture patterns.

Own, maintain, and tune AppSec tooling including SAST, DAST, SCA, secrets scanning, container scanning, and dependency management.

Partner with DevOps to ensure automated testing integrates into build, test, and deploy workflows with high signal-to-noise and minimal developer friction.

Evaluate emerging technologies and automation opportunities to strengthen AppSec capabilities.

Lead triage, prioritization, and root-cause analysis for application vulnerabilities discovered through internal testing, bug bounty programs, pentests, and external researchers.

Ensure timely remediation through strong cross-functional partnership, driving the right balance of risk, velocity, and operational maturity.

Support security reviews, pen test scoping, and remediation programs tied to GovRAMP, SOC 2, and customer requirements.

Conduct manual reviews of critical code paths, APIs, backend services, and cloud components to identify security defects that automation may miss.

Advise on secure design patterns for microservices, cloud-native architectures, authentication / authorization mechanisms, secrets management, and data protection.

Collaborate with Security Operations during active incidents involving application or product vulnerabilities.

Perform deep-dive analysis of new vulnerabilities, exploit techniques, frameworks, and supply-chain risks affecting our tech stack.

Mentor engineering teams on secure design, secure coding, and modern AppSec patterns.

Lead internal workshops, brown bags, and knowledge-sharing sessions.

Contribute to internal AppSec documentation, policies, and secure development standards.

Qualifications Required

6+ years of application security, secure development, or software engineering experience (or equivalent real-world experience).

Strong knowledge of modern application architectures : microservices, REST / GQL APIs, React / Node / Java / Kotlin / Go, containerized workloads, Kubernetes.

Hands-on experience with SAST, DAST, SCA, secrets scanning, container scanning, and CI / CD integration.

Expertise in OWASP Top 10, ASVS, SANS CWE Top 25, and secure coding principles.

Ability to perform threat modeling, code review, and architecture analysis.

Experience partnering with Engineering to drive remediation and long-term maturity improvements.

Preferred

Experience in SaaS, multi-tenant systems, or high-scale cloud environments (AWS preferred).

Familiarity with SOC 2, GovRAMP, & TX-RAMP.

Prior background in DevOps, software engineering, or cloud security.

Compensation :

Boston, MA : $140,000 - $167,500

On target ranges above include base plus a portion of variable compensation that is earned based on company and individual performance.

The final compensation will be determined by a number of factors such as qualifications, expertise, and the candidate's geographical location.

Why OpenGov?

A Mission That Matters.

At OpenGov, public service is personal. We are passionate about our mission to power more effective and accountable government. Government that operates efficiently, adapts to change, and strengthens public trust. Some people say this is boring. We think it's the core of our democracy.

Opportunity to Innovate

The next great wave of innovation is unfolding with AI, and it will impact everything-from the way we work to the way governments interact with their residents. Join a trusted team with the passion, technology, and expertise to drive innovation and bring AI to local government. We've touched 2,000 communities so far, and we're just getting started.

A Team of Passionate, Driven People

This isn't your typical 9-to-5 job; we operate in a fast-paced, results-driven environment where impact matters more than simply clocking in and out. Our global team of 800+ employees is united in our commitment to challenge the status quo. OpenGov is headquartered in San Francisco and has offices in Atlanta, Boston, Buenos Aires, Chicago, Dubuque, Plano, and Pune.

A Place to Make Your Mark

We pride ourselves on our performance-based culture, where every employee is encouraged to jump in head-first and take action to help us improve. If you have a great idea, we want to hear it. Excellent performance is recognized and rewarded, and we love to promote from within.

Compensation Range : $140K - $167.5K

Create a job alert for this search

Application Security Engineer • San Francisco, CA, United States

Related jobs
Application Security Engineer

Application Security Engineer

Cloudflare • San Francisco, California, USA
Full-time
At Cloudflare we are on a mission to help build a better Internet.Today the company runs one of the worlds largest networks that powers millions of websites and other Internet properties for custom...Show more
Last updated: 30+ days ago • Promoted
Staff Application Security Engineer

Staff Application Security Engineer

Sunrun • San Francisco, CA, United States
Full-time
Ever since we started in 2007, Sunrun has been at the forefront of connecting people to the cleanest energy on Earth.It's why we've become the #1 home solar and battery company in America.Today, we...Show more
Last updated: 10 days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Brex Inc. • San Francisco, CA, United States
Full-time
Senior Application Security Engineer#### San Francisco, California, United StatesSenior Application Security Engineer • •Why join us • •Brex is the AI-powered spend platform. We help companies spend wit...Show more
Last updated: 13 days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Altruist • San Francisco, CA, United States
Full-time
Altruist is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals. We partner with financial advisors nationwide, empowering them to g...Show more
Last updated: 10 days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Cloudflare Inc • San Francisco, CA, United States
Full-time
At Cloudflare, we are on a mission to help build a better Internet.Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for cust...Show more
Last updated: 9 days ago • Promoted
Senior Security Engineer, Application Security

Senior Security Engineer, Application Security

Postman • San Francisco, CA, United States
Full-time
Postman is the world's leading API platform, used by more than 40 million developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals acro...Show more
Last updated: 30+ days ago • Promoted
Application Security Engineer

Application Security Engineer

AtoB • San Francisco, CA, United States
Full-time
The trucking and logistics industry provides the backbone of the economy.But the payments infrastructure on which it runs is broken. For the hard-working men and women of this sector, the existing s...Show more
Last updated: 10 days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Airwallex • San Francisco, CA, United States
Full-time
Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000 businesses ...Show more
Last updated: 30+ days ago • Promoted
Application Security Engineer II (AI Security)

Application Security Engineer II (AI Security)

Amplitude • San Francisco, CA, United States
Full-time
Amplitude is the leading Amplitude is the leading digital analytics platform, helping over 4,300 customers-including Atlassian, Burger King, NBCUniversal, Square, and Under Armour-build better prod...Show more
Last updated: 10 days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Roblox • San Mateo, CA, United States
Full-time
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers...Show more
Last updated: 9 days ago • Promoted
Sr. Application Security Engineer

Sr. Application Security Engineer

Bridge Technologies and Solutions • San Francisco, CA, United States
Full-time
We need a resource who has experience working within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience. Experience with commercial applic...Show more
Last updated: 30+ days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

Imprint • San Francisco, CA, United States
Full-time
Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Rakuten, Booking.H-E-B, Fetch, and Brooks Bro...Show more
Last updated: 29 days ago • Promoted
Senior Application Security Engineer - Hybrid / Remote Impact

Senior Application Security Engineer - Hybrid / Remote Impact

OpenAI • San Francisco, CA, United States
Remote
Full-time
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security.The role involves identifying and mitigating security vulnerabilities, conducting assessments, an...Show more
Last updated: 1 day ago • Promoted
Senior Security Engineer, Application & Platform Security

Senior Security Engineer, Application & Platform Security

Sentry • San Francisco, CA, United States
Full-time
Bad software is everywhere, and we're tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...Show more
Last updated: 30+ days ago • Promoted
Senior / Staff Application Security Engineer

Senior / Staff Application Security Engineer

Abridge • San Francisco, CA, United States
Full-time
Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation eff...Show more
Last updated: 7 days ago • Promoted
Senior Application Security Engineer

Senior Application Security Engineer

ZIP • San Francisco, CA, United States
Full-time
The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally...Show more
Last updated: 7 days ago • Promoted
Senior Security Engineer, Application & Platform Security

Senior Security Engineer, Application & Platform Security

Sentry.io • San Francisco, CA, US
Full-time
About Sentry Bad software is everywhere, and we're tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology.With more than $217 m...Show more
Last updated: 10 days ago • Promoted
Application Security Engineer

Application Security Engineer

Benchling • San Francisco, California, USA
Full-time
Biotechnology is rewriting life as we know it from the medicines we take to the crops we grow the materials we wear and the household goods that we rely on every day. But moving at the new speed of ...Show more
Last updated: 1 day ago • Promoted