Talent.com
Senior Application Security Engineer (Hybrid - US)

Senior Application Security Engineer (Hybrid - US)

Energy Solutions - USAOakland, CA, United States
2 days ago
Job type
  • Full-time
Job description

Summary

We are seeking a Senior Application Security Engineer who will work with our development team to manage security and risk on our internally developed applications. The engineer will make risk-based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms. This role is primarily focused on execution and consulting but should be familiar with roadmap and strategy and contribute where appropriate. Must have the ability to read, review, and make recommendations on secure Django / Python patterns.

Responsibilities

  • Contribute to the application security roadmap for our internal applications—prioritize risks and sequence work across codebases, application layer, and DevOps.
  • Consult with engineers to communicate requirements, create actionable tickets / acceptance criteria, and drive adoption.
  • Conduct pull request reviews focused on security, provide guidance on refactors, and approve / deny with clear rationale.
  • Serve as a steward for SAST / scanning : review static code scan results, triage findings, eliminate noise, and drive remediation with owners.
  • Build reference implementations in Django / Python (i.e. authentication patterns, input validation, secrets handling, rate limiting, geo-based access) without direct responsibility for production feature development.
  • Map SOC 2 / NIST to engineering work : translate requirements into stories, controls, and automated evidence in CI / CD.
  • Threat modeling & architecture : navigate libraries / architectures and document secure patterns (ADRs / RFCs) that teams follow.
  • Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.
  • Collaborate with software developers and code base leads.
  • Act as a liaison between technical requirements from the business (i.e. security, privacy, compliance) and development teams.
  • Participate as a subject matter expert in security architecture, including new designs and design reviews.
  • Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.
  • Review architecture and compliance-related code changes for security impact.
  • Ensure compliance with all company security policies and standards.
  • Manage and maintain all security related tickets, including recommendations, testing, and validation.

Qualifications

  • Minimum of 5 years' experience in application security experience.
  • Practice and implementation with Django / Python with a clear application-security focus (production experience and impact, not theory).
  • Engineering background (software or DevOps / SRE) with the ability to read / modify code, review PRs, and build PoCs.
  • Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
  • Experience embedding secure SDLC into Git-based workflows and CI / CD (pre-commit, pipeline gates, policy-as-code).
  • Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.
  • Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging / monitoring).
  • Clear, persuasive communication (verbal and written) and prioritization.
  • Excellent time management skills with a proven ability to meet deadlines.
  • Excellent interpersonal and negotiation skills.
  • Preferred Qualifications

  • Bachelors degree in Computer Science or equivalent work experience preferred.
  • CISSP, GIAC, Security+, AWS Security and other related security certifications.
  • Prior experience reporting to or partnering with a security architect, or being the app-sec lead in a smaller org.
  • Strong organizational skills and attention to detail.
  • Strong analytical and problem-solving skills.
  • Ability to prioritize tasks according to severity
  • Ability to adapt to the needs of the organization
  • Proficient in AWS Security services (I.E. Cloud watch, Guard Duty)
  • The salary range for this role is $119,100 - $147,400 / annually, with a target compensation of $119,000 to $131,600 based on experience and qualifications.

    #J-18808-Ljbffr

    Create a job alert for this search

    Application Security Engineer • Oakland, CA, United States

    Related jobs
    • Promoted
    Associate Application Security Engineer

    Associate Application Security Engineer

    PG ForstaEmeryville, CA, United States
    Full-time
    PG Forsta is the leading experience measurement, data analytics, and insights provider for complex industries-a status we earned over decades of deep partnership with clients to help them understan...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Cloudflare IncSan Francisco, CA, United States
    Full-time
    At Cloudflare, we are on a mission to help build a better Internet.Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for cust...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer, Application Security

    Security Engineer, Application Security

    OpenAISan Francisco, CA, United States
    Full-time
    Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products.We are...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    KubeltSan Francisco, CA, United States
    Full-time
    World is a network of real humans, built on privacy-preserving proof-of-human technology, and powered by a globally inclusive financial network that enables the free flow of digital assets for all....Show moreLast updated: 30+ days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Cloudflare, Inc.San Francisco, CA, United States
    Full-time
    At Cloudflare, we are on a mission to help build a better Internet.Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for cust...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Security GRC Engineer

    Senior Security GRC Engineer

    Hill Physicians Medical GroupSan Ramon, CA, US
    Full-time
    At PriMed, your uniqueness is valued, celebrated, encouraged, supported, and embraced.Whatever your relationship with Hill Physicians, we welcome ALL that you are. We value and respect your race, et...Show moreLast updated: 16 hours ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    ImprintSan Francisco, CA, United States
    Full-time
    Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Rakuten, Booking.H-E-B, Fetch, and Brooks Bro...Show moreLast updated: 23 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    AltruistSan Francisco, CA, United States
    Full-time
    Altruist is transforming the multi-trillion dollar wealth management industry by building an AI platform for wealth professionals. We partner with financial advisors nationwide, empowering them to g...Show moreLast updated: 4 days ago
    • Promoted
    Security Engineer, Application and Product

    Security Engineer, Application and Product

    Modular ServicesLos Altos, CA, United States
    Full-time
    At Modular, we're on a mission to revolutionize AI infrastructure by systematically rebuilding the AI software stack from the ground up. Our team, made up of industry leaders and experts, is buildin...Show moreLast updated: 2 days ago
    • Promoted
    Sr. Application Security Engineer

    Sr. Application Security Engineer

    OpenGovSan Francisco, CA, United States
    Full-time
    OpenGov is the leader in AI and ERP solutions for local and state governments in the U.More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov ...Show moreLast updated: 1 day ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Brex Inc.San Francisco, CA, United States
    Full-time
    Senior Application Security Engineer#### San Francisco, California, United StatesSenior Application Security Engineer • •Why join us • •Brex is the AI-powered spend platform. We help companies spend wit...Show moreLast updated: 4 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    FastlySan Francisco, CA, United States
    Full-time
    Fastly helps people stay better connected with the things they love.Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing,...Show moreLast updated: 2 days ago
    • Promoted
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry.ioSan Francisco, CA, United States
    Full-time
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...Show moreLast updated: 18 days ago
    • Promoted
    Senior / Staff Application Security Engineer

    Senior / Staff Application Security Engineer

    AbridgeSan Francisco, CA, United States
    Full-time
    Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation eff...Show moreLast updated: 2 days ago
    • Promoted
    Senior Security System Project Engineer

    Senior Security System Project Engineer

    PinkertonSan Jose, California, United States
    Full-time
    At Pinkerton, the mission is to protect our clients.To do this, we provide enterprise risk management services and programs specifically designed for each client. Pinkerton employees are one of our ...Show moreLast updated: 3 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    AirwallexSan Francisco, CA, United States
    Full-time
    Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000 businesses ...Show moreLast updated: 23 days ago
    • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    BrexSan Francisco, CA, United States
    Full-time
    Brex is the AI-powered spend platform.We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses.Tens of ...Show moreLast updated: 4 days ago
    • Promoted
    Remote Senior Application Security Engineer - Zetachain

    Remote Senior Application Security Engineer - Zetachain

    ZetachainSan Francisco, CA, United States
    Remote
    Full-time
    Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program. The ideal candidate will be responsibl...Show moreLast updated: 30+ days ago