Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Purposebrands

Application Security Engineer

Purposebrands

. Embed application security practices into all phases of the software development lifecycle, from design through deployment and maintenance .

Posted 10/7/2026full-timeUnited StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security practices throughout the software development lifecycle, with a strong focus on secure coding, vulnerability management, and cloud security in AWS and Azure environments. Proficient in integrating security tools into CI/CD pipelines and communicating security risks effectively to diverse stakeholders.

Highest-signal resume keywords
Application Security AssessmentStatic Code Analysis (SAST)Dynamic Testing (DAST)Secure Coding PracticesAWS and Azure Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityCode ReviewVulnerability RemediationThreat ModelingSecurity Automation
Soft Skills
Analytical SkillsCommunication Skills
Tools & Technologies
GitHub Advanced SecurityQualysSyftClairCI/CD Pipelines
Certifications & Qualifications
Security+CSSLPGWAPTGWEBCEH
Industry Keywords
OWASP Top 10NIST CSFCIS BenchmarksDevSecOpsGovernance, Risk Management, and Compliance

Tech Stack

Tools & technologies
AWSAzureCloud

About the role

Key responsibilities & impact
  • Embed application security practices into all phases of the software development lifecycle, from design through deployment and maintenance
  • Perform application security assessments including static code analysis (SAST), dynamic testing (DAST), and software composition analysis (SCA)
  • Develop and maintain threat models for critical systems and applications
  • Promote secure coding practices and contribute to secure development standards aligned with OWASP and industry best practices
  • Integrate security tooling into CI/CD pipelines to enable automated and repeatable security testing
  • Analyze and manage vulnerability findings from GitHub Advanced Security, Syft, Clair, Qualys, and similar tools
  • Tune security tooling to reduce false positives and improve signal quality
  • Support security automation across application environments
  • Assist in securing applications deployed across AWS and Azure, including IaaS, PaaS, and container-based platforms
  • Identify risks to application data confidentiality, integrity, and availability in cloud environments
  • Collaborate with cloud and platform security engineers to align application security controls with cloud security architecture
  • Own and curate security controls aligned with NIST CSF, CIS Benchmarks, and CSA CCM
  • Triage, prioritize, and track application vulnerability remediation based on risk and business impact
  • Assist with security investigations involving application vulnerabilities or security events
  • Participate in periodic application security control reviews
  • Provide security guidance, education, and actionable recommendations to engineering teams
  • Improve application security processes, standards, and metrics
  • Support governance, risk management, and compliance initiatives related to application security
  • Report to the Staff Security Engineer

Requirements

What you’ll need
  • Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related field
  • 3–5 years of experience in application security, security engineering, or software engineering with a strong security focus
  • Hands-on experience performing code reviews and application security testing across modern languages, frameworks, and APIs
  • Experience working with application security tools such as SAST, DAST, and dependency scanning (e.g., GitHub Dependabot or similar)
  • Strong understanding of OWASP Top 10, secure coding principles, authentication/authorization, and API security
  • Practical experience supporting applications running in AWS and/or Azure cloud environments
  • Familiarity with CI/CD pipelines, DevOps workflows, and DevSecOps concepts
  • Ability to communicate security risks and remediation guidance clearly to developers and non-security stakeholders
  • Strong analytical skills with the ability to balance security risk with delivery velocity
  • Preferred certifications include: Security+, CSSLP, GWAPT, GWEB, CEH, GPEN or other application security–focused certifications

Benefits

Comp & perks
  • Medical, Dental and Vision Coverage
  • Hybrid Work Environment
  • Life and Disability Insurance
  • Unlimited Time off + Paid Holidays
  • Flexible Friday's between Memorial Day and Labor Day
  • 401(K) Savings Plan Matching at 4%
  • 10 Coaching and Therapy sessions
  • Mental Health Benefits
  • Brand Discounts & Reimbursements
  • In-house workout facilities
  • Professional Development Opportunities
  • Team Building, Employee Engagement Activities & so much more