Application Security Engineer

Omnissa

$111K — $186K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience in application security or software engineering with a focus on security.
  • Solid knowledge of common application security vulnerabilities and mitigation techniques.
  • Hands-on experience with manual secure code review and application security testing, focusing on reading source code.
  • Proficiency in a programming language such as Java or C++ to analyze production code.
  • Ability to independently own well-scoped security work and deliver it reliably.
  • Strong problem-solving skills and attention to detail, capable of root cause analysis.
  • Good communication skills for effective collaboration within a team.

Responsibilities

  • Lead threat modeling for features and components, collaborating with senior engineers on complex architectures.
  • Independently perform secure code reviews and manual application security testing on assigned components.
  • Triage and validate reported vulnerabilities, assessing severity and driving fixes with engineering teams.
  • Build and maintain automation and tooling to enhance security processes.
  • Identify recurring security issues and recommend improvements for tools or processes.
  • Document findings clearly and collaborate with developers to improve secure development practices.

Benefits

  • Employee ownership.
  • Health insurance coverage.
  • 401k plan with matching contributions.
  • Disability insurance.
  • Paid time off for work-life balance.
  • Growth opportunities for career advancement.
Full Job Description
Job Description:

What is the opportunity?:

This is a hands-on application security role for an engineer who can own well-scoped work and deliver it independently. You'll contribute across multiple areas of the security program - from secure code reviews and application security testing to triaging vulnerabilities and building automation - collaborating with senior and staff engineers on the harder, more ambiguous problems. Omnissa's portfolio spans six major product families and roughly a hundred products, so you'll focus on assigned areas while steadily broadening your expertise and growing your scope and impact over time. This role is about the security of the code we write - reading it, reviewing it, and helping engineers find, fix, and prevent vulnerabilities in our own software - not CVE tracking, dependency patching, or third-party vulnerability management. It is deep, manual work: reasoning about source code to find issues that automated scanners miss, not operating SAST/DAST tools and forwarding their output.

If you have an analytical mind, a passion for software security, and thrive on solving problems, this role is for you. A successful candidate is dependable, communicates clearly, manages their time well, and can identify and understand root causes.

Key Responsibilities:
  • Lead threat modeling for the features and components in your area, and partner with senior engineers on threat models spanning complex or cross-cutting architectures.
  • Independently perform secure code reviews, manual application security testing, and penetration testing across assigned components, partnering with senior engineers on complex or distributed architectures.
  • Triage and validate reported vulnerabilities in our products, assess severity and impact, and drive fixes to closure with engineering teams.
  • Build and maintain automation and tooling that improve the security process.
  • Identify recurring issues in your areas and recommend improvements to tooling or process.
  • Document findings and guidance clearly, and collaborate with developers to strengthen secure development practices across the portfolio.

What success looks like:
  • First 3 months: Ramp up on the products in your assigned area - their architecture, development toolchain, and release process - within Omnissa's broader portfolio of six product families, and begin delivering security reviews and triage.
  • First 6 months: Independently own routine security work end to end, handle vulnerability triage with sound judgment, and contribute automation or process improvements that help the team.
  • 12 months: Reliably own a defined area with minimal oversight, take on progressively more complex problems, and be a consistent, trusted contributor to the security program.

Leadership and team culture:
  • Report to the Director of Product Security and take direction from the Manager of Application Security.
  • Work closely with a committed team of security engineers, product managers, and developers focused on innovation and getting things done.
  • Build trust among team members and stakeholders, committing to customer success.
  • Operate in a transparent, communicative environment that emphasizes work-life balance and having fun at work.

What will you bring to Omnissa?

Required:
  • 4+ years of experience in application security, or in software engineering with a demonstrated focus on security.
  • Solid working knowledge of common application security vulnerabilities and mitigation techniques.
  • Hands-on experience with manual secure code review and application security testing - reading source code to find vulnerabilities, not just running and triaging scanner output. Candidates whose experience is primarily operating SAST/DAST scanners are not a fit.
  • Proficiency in a programming language such as Java or C++, with the ability to read and reason about production code.
  • Ability to own well-scoped security work independently and deliver it reliably.
  • Strong problem-solving skills and attention to detail.
  • Good documentation and communication skills, and the ability to collaborate within a team.

Preferred:
  • Exposure to security across multiple domains - application, system, cloud, or mobile.
  • Experience writing automation or scripts to improve a technical process.
  • Familiarity with AI tooling and interest in testing agentic AI systems.
  • Prior experience in the software industry or multi-tenant SaaS.

Location: Atlanta, Mountain View

Location Type: HYBRID - 3 days per week in our Atlanta office; remaining days remote. Candidates must reside within a reasonable commuting distance.

Travel Expectations: Occasional (annual) travel to remote offices

Education: Bachelor's degree in Computer Science or a related field preferred, or equivalent combination of education and relevant professional experience.

Compensation: The typical base salary for this role is between USD $111,637- $186,062 per year and it may be eligible for participation in a corporate bonus program. Actual compensation offer may vary from posted hiring range based upon geographic location, work experience, education, skill level, or other relevant factors. In addition to competitive compensation, Omnissa offers a variety of benefits such as employee ownership, health insurance, 401k with matching contributions, disability insurance, paid-time off, growth opportunities, and more.

Similar Jobs

More Jobs at Omnissa

More Information Technology Jobs

Find similar Application Security Engineer jobs: