FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Engineer
Purposebrands. Embed application security practices into all phases of the software development lifecycle, from design through deployment and maintenance .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security practices throughout the software development lifecycle, with a strong focus on secure coding, vulnerability management, and cloud security in AWS and Azure environments. Proficient in integrating security tools into CI/CD pipelines and communicating security risks effectively to diverse stakeholders.
Highest-signal resume keywords
Application Security AssessmentStatic Code Analysis (SAST)Dynamic Testing (DAST)Secure Coding PracticesAWS and Azure Security
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecurityCode ReviewVulnerability RemediationThreat ModelingSecurity Automation
Soft Skills
Analytical SkillsCommunication Skills
Tools & Technologies
GitHub Advanced SecurityQualysSyftClairCI/CD Pipelines
Certifications & Qualifications
Security+CSSLPGWAPTGWEBCEH
Industry Keywords
OWASP Top 10NIST CSFCIS BenchmarksDevSecOpsGovernance, Risk Management, and Compliance
Tech Stack
Tools & technologiesAWSAzureCloud
About the role
Key responsibilities & impact- Embed application security practices into all phases of the software development lifecycle, from design through deployment and maintenance
- Perform application security assessments including static code analysis (SAST), dynamic testing (DAST), and software composition analysis (SCA)
- Develop and maintain threat models for critical systems and applications
- Promote secure coding practices and contribute to secure development standards aligned with OWASP and industry best practices
- Integrate security tooling into CI/CD pipelines to enable automated and repeatable security testing
- Analyze and manage vulnerability findings from GitHub Advanced Security, Syft, Clair, Qualys, and similar tools
- Tune security tooling to reduce false positives and improve signal quality
- Support security automation across application environments
- Assist in securing applications deployed across AWS and Azure, including IaaS, PaaS, and container-based platforms
- Identify risks to application data confidentiality, integrity, and availability in cloud environments
- Collaborate with cloud and platform security engineers to align application security controls with cloud security architecture
- Own and curate security controls aligned with NIST CSF, CIS Benchmarks, and CSA CCM
- Triage, prioritize, and track application vulnerability remediation based on risk and business impact
- Assist with security investigations involving application vulnerabilities or security events
- Participate in periodic application security control reviews
- Provide security guidance, education, and actionable recommendations to engineering teams
- Improve application security processes, standards, and metrics
- Support governance, risk management, and compliance initiatives related to application security
- Report to the Staff Security Engineer
Requirements
What you’ll need- Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related field
- 3–5 years of experience in application security, security engineering, or software engineering with a strong security focus
- Hands-on experience performing code reviews and application security testing across modern languages, frameworks, and APIs
- Experience working with application security tools such as SAST, DAST, and dependency scanning (e.g., GitHub Dependabot or similar)
- Strong understanding of OWASP Top 10, secure coding principles, authentication/authorization, and API security
- Practical experience supporting applications running in AWS and/or Azure cloud environments
- Familiarity with CI/CD pipelines, DevOps workflows, and DevSecOps concepts
- Ability to communicate security risks and remediation guidance clearly to developers and non-security stakeholders
- Strong analytical skills with the ability to balance security risk with delivery velocity
- Preferred certifications include: Security+, CSSLP, GWAPT, GWEB, CEH, GPEN or other application security–focused certifications
Benefits
Comp & perks- Medical, Dental and Vision Coverage
- Hybrid Work Environment
- Life and Disability Insurance
- Unlimited Time off + Paid Holidays
- Flexible Friday's between Memorial Day and Labor Day
- 401(K) Savings Plan Matching at 4%
- 10 Coaching and Therapy sessions
- Mental Health Benefits
- Brand Discounts & Reimbursements
- In-house workout facilities
- Professional Development Opportunities
- Team Building, Employee Engagement Activities & so much more