Application Security Engineer [Remote-US]
Quanata, LLCAbout the role
About Us
Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer centered team with a passion for creating innovative technologies, digital products, and brands. We blend some of the best Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer, State Farm.
Learn more about us and our work at quanata.com Our Team From data scientists and actuaries to engineers, designers and marketers, we’re a world class team of tech-minded professionals from some of the best companies in Silicon Valley, and around the world. We’ve come together to create the context-based insurance solutions and experiences of the future. We know that the key to our success isn't just about nailing the technology—it’s hiring the talented people who will help us continue to make a quantifiable impact.The role
We are seeking an Application Security Engineer to join the Product Security team within the greater Security & Privacy team. This role is pivotal in ensuring the security and integrity of our applications and services and shared solutions within our B2B/E product suite. You will be responsible for implementing application security measures across various projects, with a focus on identifying and mitigating risks within our development lifecycle.
As an Application Security Engineer, you will be playing an essential role in maintaining the overall security posture of the company. You'll work closely with the entire Security & Privacy team. Our application environment is a hybrid of containers, managing most of our production microservices, and a public cloud-driven services layer based on popular open-source components.
We’re looking for a candidate who thrives in a team setting, collaborates effectively with colleagues across multiple departments, and contributes positively to a dynamic team environment. The ideal individual should be skilled in leveraging the strengths of diverse team members, fostering a culture of open communication, and driving joint initiatives towards successful outcomes.
Your day-to-day
Collaborate with development and product teams to integrate security solutions into business-critical applications.Assist in creating and refining product security threat models, focusing on security measures tailored to the unique challenges of the insurance sector.Participate in secure code reviews and product security testing to identify vulnerabilities.Implement application security best practices throughout the software development lifecycle.Respond to vulnerabilities identified through internal security testing, prioritizing according to business impact.Support initiatives to enhance security awareness and practices within the application development teams.Work closely with compliance teams to ensure that applications adhere to industry-specific regulations and standards.Document security procedures, best practices, and team initiatives using repeatable patterns.
About you
- Experience:
- Bachelor’s degree or equivalent, relevant experience and;
- 3 - 5 years of experience in information security, with at least 2 years of experience in application security engineering.
- Experience in working with software development teams to integrate security into complex application ecosystems.
- Technical Skills:
- Familiarity with security-by-design principles and a solid understanding of application security frameworks and standards.
- Familiarity with cloud-based hosting providers like AWS, Google Cloud or Microsoft Azure.
- Knowledge of OWASP and relevant standards like the Top 10, ASVS and MASVS.
- Proficiency in at least one programming language and relevant security tools.
- Familiarity with threat modeling paradigms such as STRIDE or STRIPED.
- People Skills:
- Strong communication skills, with the ability to collaborate effectively with development teams and other stakeholders.
- Ability to work in a fast-paced environment, managing multiple tasks and priorities.
Bonus points
- Certifications in security architecture or application security (e.g., CSSLP, GWEB, OSWE).
- Familiarity with the insurance industry or a similarly regulated sector and its im
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s