← Back to jobs

AppSec Security Engineer

Location
New York, NY
Work type
Full Time · On-site
Posted
2026-09-03

Job description

What You'll Do:

Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tooling into CI/CD pipelines for home-grown applications
Lead security design and threat modeling sessions with Product and Engineering teams based on OWASP Top 10 and MITRE ATT&CK
Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks
Define AppSec coverage, tooling, and assessment processes from scratch across the application landscape
Develop secure Infrastructure as Code patterns and validate security controls for Azure and Kubernetes

What Gets You the Job:

Significant hands-on application security experience, including expert knowledge of OWASP Top 10, API Security Top 10, and OWASP LLM Top 10 and how common vulnerability classes manifest in production
Proficiency integrating SAST/SCA/DAST, container/IaC scanners, and secret scanning into one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins)
Proficiency in Terraform/IaC, Kubernetes, and cloud provider security, with Azure preferred
Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch
Experience building security tooling or automation; policy gates with OPA/Gatekeeper or Kyverno a plus

Original source