ArchiveSocial

Application Security Engineer

ArchiveSocial • $80K — $90K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-7 years of experience in application security or related fields.
  • Hands-on experience with SAST, DAST, or IAST tools.
  • Experience with integrating secure design into CI/CD pipelines.
  • Possession of Security+, GSEC, GSSP, or equivalent certification.
  • Bachelor's degree in Computer Science or related field is preferred.
  • Familiarity with secure coding in languages like C#, Java, JavaScript, or Python.
  • Demonstrated ability in leveraging AI tools for improved productivity.

Responsibilities

  • Perform security code reviews and architecture reviews.
  • Collaborate with teams to integrate security into the SDLC.
  • Identify and validate vulnerabilities from security testing.
  • Coordinate external penetration testing of production environments.
  • Lead application security testing for various methodologies.
  • Act as a subject matter expert on application security vulnerabilities.

Benefits

  • Comprehensive health, dental, and vision insurance.
  • Flexible Time Off policy.
  • 401(k) plan offered.
  • Support for continuous learning and development.
Full Job Description
Description

Your Impact

As an Application Security Engineer you will help embed security across CivicPlus's software development lifecycle, leading application security testing and vulnerability remediation to protect the products local governments and residents rely on.

What You'll Do

As an Application Security Engineer, you will:
  • Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC).
  • Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC.
  • Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements.
  • Coordinate external, independent penetration testing of production environments.
  • Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST).
  • Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats.

What We're Looking For

We know that excellent candidates come from diverse backgrounds. Even if you don't meet 100% of the listed requirements, we encourage you to apply!

Preferred Qualifications:
  • 3-7 years of experience in application security, secure development, penetration testing, or a related field.
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST).
  • Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations.
  • Security+, GSEC, GSSP, or equivalent certification.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred).
  • Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments.
  • AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality.
  • Demonstrated ability to effectively use AI tools to enhance productivity and outcomes.

Compensation and Benefits
  • Estimated Salary Grade Range: $70,300 - $101,300
    • Anticipated Hiring Range: $80k - $90k.
    • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience and is based on a 40-hour work week.
  • Benefits: Comprehensive health insurance, dental insurance, vision insurance, Flexible Time Off, 401(k) plan, and more.

Our Hiring Process
  1. Introductory call with Talent Acquisition
  2. Interview with the Hiring Manager
  3. Panel Interview with CivicPlus team members, including an interview project activity
  4. Offer

Note: The process may vary slightly depending on the role.

Additional Information
  • CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US.
  • This position will remain open until October 7, 2026 at 4pm CT. We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team.
  • At CivicPlus, we embrace AI and automation as tools that help people work smarter, move faster, and focus on higher-value work that strengthens communities. We encourage thoughtful, responsible use of technology to improve efficiency, support innovation, and enhance the employee and customer experience-while keeping human judgment, collaboration, and accountability at the center of what we do.

About ArchiveSocial

ArchiveSocial is a social media archiving company that provides solutions for archiving and managing social media content. The company's platform is designed to help organizations comply with regulations related to social media content, and to provide insights into social media activity. ArchiveSocial's technology is used by companies in various industries, including government, healthcare, and education. The company was founded in 2011 and is headquartered in Durham, North Carolina.
Learn more about ArchiveSocial
Size
50 employees
Industry
Founded
2011

Similar Jobs

More Jobs at ArchiveSocial

More Information Technology Jobs

Find similar Application Security Engineer jobs: