Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
CivicPlus

Application Security Engineer

CivicPlus

. Perform security code reviews, threat modeling, and architecture reviews across development projects as part of a secure SDLC .

Posted 9/24/2026full-timeRemote • United StatesMid-LevelSenior💰 $70,300 - $101,300 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security, including security code reviews, threat modeling, and vulnerability management. Proficient in integrating secure design principles and leveraging AI tools to enhance security practices and productivity.

Highest-signal resume keywords
Application Security TestingSAST, DAST, IASTSecure Development OperationsSecurity+ CertificationVulnerability Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityThreat ModelingSecurity Code ReviewVulnerability TrackingSecure Coding PracticesPenetration TestingCI/CD IntegrationCloud-Native EnvironmentsProgramming Languages (C#, Go, Java, JavaScript, Python)AI Tools Utilization
Certifications & Qualifications
Security+GSECGSSP
Industry Keywords
OWASP Top 10Secure SDLCCompliance TimelineSaaS ApplicationsChange Management

Tech Stack

Tools & technologies
CloudCyber SecurityJavaJavaScriptPythonSDLCGo

About the role

Key responsibilities & impact
  • Perform security code reviews, threat modeling, and architecture reviews across development projects as part of a secure SDLC
  • Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC
  • Identify, track, and validate vulnerabilities and security defects from security testing and scanning
  • Partner with development teams to prioritize remediation within compliance timeline requirements
  • Coordinate external, independent penetration testing of production environments
  • Lead application security testing, including SAST, DAST, and IAST
  • Serve as a subject matter expert on application security vulnerabilities, including the OWASP Top 10, and emerging threats

Requirements

What you’ll need
  • 3–7 years of experience in application security, secure development, penetration testing, or a related field
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST)
  • Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations
  • Security+, GSEC, GSSP, or equivalent certification
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred)
  • Familiarity with secure coding practices across multiple languages, such as C#, Go, Java, JavaScript, or Python
  • Knowledge of cloud-native and SaaS application environments
  • AI-forward mindset with demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality
  • Demonstrated ability to effectively use AI tools to enhance productivity and outcomes
  • Applicants must be authorized to work in the US
  • CivicPlus is currently unable to provide visa sponsorship for this position now or in the future

Benefits

Comp & perks
  • Comprehensive health insurance
  • Dental insurance
  • Vision insurance
  • Flexible Time Off
  • 401(k) plan