Senior Application Security Engineer
World Wide TechnologyAbout the role
Required Qualifications
- Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related field — or equivalent hands-on experience.
- Minimum 8 years of experience in roles related to application security, information security, software engineering, SecDevOps.
- A demonstrable track record of independently owning AppSec domains and delivering remediation without close supervision.
- Hands-on experience operating application security scanning tooling (SAST, SCA, secrets, IaC) and integrating it into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or equivalent).
- Experience securing cloud-native and container/Kubernetes-based applications (AWS, Azure, GCP; Docker, Kubernetes, OpenShift).
- Ability to read and reason about code in one or more modern stacks (Java, JavaScript/TypeScript, Python, Go, or C#) well enough to perform and review secure code, trace data flows, and identify vulnerabilities in source code.
- Scripting and automation in Python, Bash, or PowerShell.
- Design-level understanding of authentication, authorization, and identity — session management, SSO and federation, and OAuth2/OIDC as architectural patterns.
- Working knowledge of applied cryptography — TLS, certificates and PKI, secrets and key management, hashing versus encryption.
- Strong command of HTTP and web API internals — request/response semantics, auth flows (OAuth2/OIDC, JWT, session management), and the authZ failures, injection, and business-logic flaws common to REST and GraphQL APIs.
- Solid understanding of the secure software development lifecycle and where security testing, gates, and controls fit within it.
- Strong working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and CWE.
- Working knowledge of NIST SSDF (SP 800-218), NIST 800-53, NIST 800-171, ISO 27001, SOC 2, and CMMC as they apply to secure software development.
- Hands-on threat modeling experience (STRIDE, PASTA, or equivalent).
- Excellent interpersonal, written, and verbal communication — able to explain and document security risk and remediation credibly to both engineers and non-technical stakeholders.
- Self-starter, team player, and enthusiasm for learning.
- Applicants must be authorized to work in the United States without sponsorship. We are unable to provide sponsorship now or in the future for this position.
Preferred Qualifications
- Direct, hands-on experience with one or more leading application security platforms (e.g., Wiz, Snyk, Apiiro, OX Security, Cycode, Checkmarx, Veracode, or GitHub Advanced Security).
- Hands-on experience securing AI/LLM-enabled and agentic applications; familiarity with OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic AI, MITRE ATLAS, NIST AI RMF, and Model Context Protocol (MCP) security implications.
- Hands-on penetration testing or offensive security experience across web, API, infrastructure, or AI systems (including prompt injection, jailbreaks, and agent abuse).
- Industry certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP, OSWE, or AWS/Azure/GCP security certifications.
Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $116,000 to $145,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the base pay.
The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
- Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
- Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
- Paid Time
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s