Jobs and Careers
AC
Senior Application Security Engineer
AcrisureOklahoma City, United Statesfull_timeVerifiedPosted 6 Nov 2025
About the role
Department: Information SecurityReports to: Senior Director, Information Security
Role Summary
You will be a hands-on technical engineer who embeds security into how software is designed, built, and operated. You’ll create paved-road patterns, wire security controls into CI/CD, and drive remediation through a risk-based lens. Success in this role means making the secure way the easy way, reducing time-to-fix, and measurably lowering product risk without slowing delivery.What You’ll Do (Core Responsibilities)
Build & Automate Secure-by-Default
- Design and maintain paved road templates (reference repos, IaC, CI/CD workflows) that ship with SAST, SCA, secrets scanning, IaC/container scanning, SBOM generation, artifact signing/attestation, and policy gates.
- Integrate and tune AppSec tools in developer workflows (IDE hints, PR annotations, pipeline gates); author custom rules where off-the-shelf signals are noisy.
- Engineer data flows that aggregate/dedupe/correlate findings into a single vulnerability backlog with risk scoring (severity × exploitability × exposure × asset criticality; KEV overrides).
Secure SDLC & Architecture
- Lead threat modeling and design reviews for high-risk features (authn/z boundaries, multi-tenant isolation, API abuse, data protection).
- Write and evolve secure coding standards and language-specific guardrails (PHP/.NET/Node) aligned to Industry best practice..
- Partner with platform teams on supply-chain security (dependency policies, third-party library allow/deny lists).
Validate & Defend
- Stand up DAST/API testing (REST/GraphQL), targeted fuzzing for parsers/critical endpoints, and pre-prod abuse testing (authz under load, rate limiting, broken object/property level auth).
- Coordinate external pen tests and triage bug bounty submissions; drive root-cause fixes and pattern-level remediations.
- Improve runtime protection with WAF/API gateways, and egress controls.
Vulnerability Management & Risk
- Own triage for critical services; set SLAs by severity and exploitability; escalate KEV/autowormable issues as emergency response.
- Create dashboards that separate leading (coverage, scan on PRs, time-to-triage) from lagging (MTTR, open > SLA) and business metrics.
Minimum Qualifications
- 5+ years in AppSec/Software Security/DevSecOps (or strong software engineering background plus 2+ years AppSec).
- Proficiency in at least one major language (e.g., PHP, C#/.NET, JavaScript/TypeScript, Python, or Go) and ability to read others.
- Hands-on with modern AppSec tools and patterns: SAST/SCA/DAST, secrets scanning, SBOM & artifact signing, container/IaC scanning, API testing, WAF/API gateway policy.
- CI/CD integration experience (GitHub Actions/GitLab/Jenkins/Azure DevOps/Harness); policy-as-code mindset.
- Practical understanding of cloud-native architectures (AWS/Azure/GCP), Kubernetes fundamentals, and common identity patterns (OIDC/OAuth2, session mgmt).
- Demonstrated ability to turn noisy scanner output into actionable, prioritized remediation work.
Preferred Qualifications
- Operating knowledge of NIST SSDF, OWASP SAMM/ASVS, and SLSA; experience aligning controls to PCI/SOC2/ISO (as relevant).
- Building/maintaining
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s