Jobs and Careers
AC

Senior Application Security Engineer

Acrisure
Oklahoma City, United Statesfull_timeVerifiedPosted 6 Nov 2025

About the role

Department: Information SecurityReports to: Senior Director, Information Security

Role Summary

You will be a hands-on technical engineer who embeds security into how software is designed, built, and operated. You’ll create paved-road patterns, wire security controls into CI/CD, and drive remediation through a risk-based lens. Success in this role means making the secure way the easy way, reducing time-to-fix, and measurably lowering product risk without slowing delivery.

What You’ll Do (Core Responsibilities)

Build & Automate Secure-by-Default

  • Design and maintain paved road templates (reference repos, IaC, CI/CD workflows) that ship with SAST, SCA, secrets scanning, IaC/container scanning, SBOM generation, artifact signing/attestation, and policy gates.
  • Integrate and tune AppSec tools in developer workflows (IDE hints, PR annotations, pipeline gates); author custom rules where off-the-shelf signals are noisy.
  • Engineer data flows that aggregate/dedupe/correlate findings into a single vulnerability backlog with risk scoring (severity × exploitability × exposure × asset criticality; KEV overrides).

Secure SDLC & Architecture

  • Lead threat modeling and design reviews for high-risk features (authn/z boundaries, multi-tenant isolation, API abuse, data protection).
  • Write and evolve secure coding standards and language-specific guardrails (PHP/.NET/Node) aligned to Industry best practice..
  • Partner with platform teams on supply-chain security (dependency policies, third-party library allow/deny lists).

Validate & Defend

  • Stand up DAST/API testing (REST/GraphQL), targeted fuzzing for parsers/critical endpoints, and pre-prod abuse testing (authz under load, rate limiting, broken object/property level auth).
  • Coordinate external pen tests and triage bug bounty submissions; drive root-cause fixes and pattern-level remediations.
  • Improve runtime protection with WAF/API gateways, and egress controls.

Vulnerability Management & Risk

  • Own triage for critical services; set SLAs by severity and exploitability; escalate KEV/autowormable issues as emergency response.
  • Create dashboards that separate leading (coverage, scan on PRs, time-to-triage) from lagging (MTTR, open > SLA) and business metrics.

Minimum Qualifications

  • 5+ years in AppSec/Software Security/DevSecOps (or strong software engineering background plus 2+ years AppSec).
  • Proficiency in at least one major language (e.g., PHP, C#/.NET, JavaScript/TypeScript, Python, or Go) and ability to read others.
  • Hands-on with modern AppSec tools and patterns: SAST/SCA/DAST, secrets scanningSBOM & artifact signing, container/IaC scanning, API testing, WAF/API gateway policy.
  • CI/CD integration experience (GitHub Actions/GitLab/Jenkins/Azure DevOps/Harness); policy-as-code mindset.
  • Practical understanding of cloud-native architectures (AWS/Azure/GCP), Kubernetes fundamentals, and common identity patterns (OIDC/OAuth2, session mgmt).
  • Demonstrated ability to turn noisy scanner output into actionable, prioritized remediation work.

Preferred Qualifications

  • Operating knowledge of NIST SSDFOWASP SAMM/ASVS, and SLSA; experience aligning controls to PCI/SOC2/ISO (as relevant).
  • Building/maintaining 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Acrisure

View company profile →