Jobs and Careers
TR

Application Security Engineer II - Penetration Testing

Travelers
United Statesfull_timeVerifiedPosted 8 Jul 2025
💰 $203,000/yr($123,000/yr$203,000/yr)

About the role

Who Are We?

Taking care of our customers, our communities and each other. That’s the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 160 years. Join us to discover a culture that is rooted in innovation and thrives on collaboration. Imagine loving what you do and where you do it.

Job Category

Technology

Compensation Overview

The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards.

Salary Range

$123,000.00 - $203,000.00

Target Openings

1

What Is the Opportunity?

Travelers is seeking an Application Security Engineer II to join our organization as we grow and transform our Technology landscape. Individual will complete advanced end to end security engineering tasks for specific system including security research, application security testing, interpretation of vulnerability scan results, threat modeling code reviews, and will provide defensive coding techniques consulting. Works with circle leads in a Value Stream on security and performs Application Security testing for Value Stream. Provides guidance and support to junior team members. Performs application architecture security reviews. Partners with Cybersecurity and Enterprise Security Engineering on testing and remediation of vulnerabilities and implementation of Cybersecurity patterns.

What Will You Do?

  • Contribute to the creation of an application penetration testing framework.
  • Conduct thorough penetration testing on web, mobile, and cloud-based applications to identify security vulnerabilities.
  • Develop and execute test plans, scripts, and methodologies for application security assessments.
  • Document and report findings, including detailed descriptions of vulnerabilities, potential impact, and recommended remediation steps.
  • Perform security research, application security testing, interpretation of vulnerability scan results, threat modeling code reviews and advise on defensive coding techniques with a high degree of accuracy and speed, operating as an individual contributor to team goals.
  • Work independently to tackle well-scoped and loosely scoped problems.
  • Seek opportunities to expand technical knowledge and capabilities.
  • Provide technical guidance and mentorship to less experienced employees.
  • Perform other duties as assigned.

What Will Our Ideal Candidate Have?

  • Four years of application security experience and/or certifications such as OSCP, OSWA, or GWAPT.
  • Proficiency using penetration testing tools such as Burp Suite
  • Strong knowledge of common application vulnerabilities (e.g., OWASP Top Ten)
  • Experience reviewing reported application vulnerabilities from outside testers and researchers for impact and likelihood to Travelers.
  • Experience with DAST tooling and supporting a scalable and integrated strategy to test applications.
  • Familiarity with threat modeling methodologies.
  • Delivery - Intermediate delivery skills including the ability to estimate accurate timelines for tasks and deliver work at a steady, predictable pace to achieve commitments, contribute to the software design strategy and methodologies used to best meet the system requirements, consider and build for many different use cases, avoid over engineering, and ensure automation, deliver complete solutions but release them in small batches, and identify important tradeoffs and negotiate them.
  • Domain Expertise - Demonstrated track record of domain expertise including understanding technical concepts necessary to do the job effectively and aware of industry trends, demonstrate willingness, cooperation, and concern for business issues and priorities, and possess in depth knowledge of immediate systems worked on and some knowledge of adjacent systems.
  • Problem Solving - Strong problem solver who ensures solutions are built for the long term, is able to resolve new issues, recognizes mistakes using them as learning and teaching opportunities and consistently breaks down large problems into smaller, more manageable ones.
  • Communication - Strong communicator who possesses the ability to articulate information clearly and concisely with the business, document work in a clear, easy to follow manner, co

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Travelers

View company profile →