** Due to client requirements, applicants must be able to work on a w2 basis
** Onsite is required Application Security Engineer Job Overview We are seeking an experienced Application Security Engineer to provide security leadership for a growing internal application development environment, including emerging AI-enabled solutions. This is a newly created role with an immediate need for someone who can embed practical security controls into the development lifecycle while partnering closely with engineering, data, security, and technology stakeholders.
To secure an interview, candidates should bring hands-on Application Security and Secure SDLC experience, understand modern development practices beyond checklist-based risk reviews, and be comfortable evaluating applications, architecture, vulnerabilities, third-party components, and emerging AI security risks.
Must Haves - Approximately 3-5 years of relevant technology or security experience, including practical exposure to Application Security, secure coding, or Secure SDLC activities.
- Strong understanding of how modern applications are designed, developed, tested, deployed, and secured throughout the Software Development Life Cycle (SDLC).
- Demonstrated ability to perform substantive application risk assessments and identify meaningful technical security concerns rather than relying solely on compliance checklists.
- Working knowledge of Secure SDLC, CI/CD security, release controls, vulnerability remediation, and application security testing.
- Familiarity with security testing approaches such as SAST, DAST, IAST, SCA, API security testing, infrastructure-as-code scanning, container scanning, and secrets detection.
- Experience reviewing vulnerability or source-code scanning results using platforms such as SonarQube, Checkmarx, Fortify, Veracode, GitHub security capabilities, or comparable tools.
- Ability to collaborate effectively with developers, architects, security professionals, and technology stakeholders while navigating competing priorities and technical disagreements.
- Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Security, or a related discipline; equivalent relevant professional experience may be considered.
What the Client Needs You to Do You will serve as a hands-on security partner for teams building new applications and AI-enabled capabilities. Your primary objective is to integrate security into development from design through release, ensuring new functionality receives appropriate technical review without unnecessarily slowing delivery.
You will evaluate proposed solutions, review architecture, establish secure development expectations, analyze scanning results, validate vulnerability remediation, assess third-party technology, and determine the security implications of new functionality before deployment.
The successful candidate must be comfortable challenging technical decisions constructively. This position requires someone who understands how software is actually built and can translate security requirements into practical guidance developers can implement.
Key Responsibilities - Embed Application Security practices throughout design, development, testing, deployment, and ongoing enhancement activities.
- Review new application features and releases to confirm appropriate security requirements and development controls have been addressed.
- Establish practical secure coding expectations, technical guardrails, and development security standards in partnership with engineering stakeholders.
- Analyze application security scanning results, distinguish meaningful vulnerabilities from lower-priority findings, and validate appropriate remediation.
- Evaluate application architectures, integrations, APIs, infrastructure components, and technical design decisions for potential security weaknesses.
- Assess third-party software, libraries, services, and other external components introduced into application environments.
- Partner with developers and technology teams to incorporate security testing and controls into CI/CD and release processes.
- Evaluate AI-enabled applications for risks involving data exposure, source integrity, prompt injection, unauthorized disclosure, model misuse, and other emerging attack patterns.
- Test internally developed solutions prior to release and provide actionable recommendations when security concerns are identified.
- Collaborate across security and technology functions to resolve vulnerabilities, address technical risks, and strengthen secure development practices.
Additional Information The technical environment includes a mixture of modern application development technologies. Experience with Python is particularly valuable, while exposure to Java, .NET, or comparable enterprise development frameworks is beneficial. Candidates do not need to specialize in one programming language; broader understanding of sound development and application security principles is more important.
Experience with Azure, Azure DevOps, GitHub Enterprise, GitHub Advanced Security, or comparable cloud-based development and DevSecOps platforms is preferred.
Candidates with knowledge of AI security will have an advantage. Relevant areas include the OWASP Top 10 for Large Language Model Applications, NIST AI Risk Management Framework, responsible AI concepts, prompt injection, sensitive-data leakage, hallucination risk, model misuse, AI agents, and prompt security.
This position is best suited for a technically curious security professional who can operate beyond policy and compliance activities. A software developer or engineer who has transitioned into Application Security may be particularly well aligned.
Strong interpersonal judgment is essential. You will work with stakeholders who may have different levels of security maturity and occasionally challenge security recommendations. The successful candidate can explain technical risk clearly, establish credibility with developers, resolve reasonable disagreements, and determine when a material security concern requires escalation.
W2 employees of Overture Partners who work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), 401(k) starting on day one, a variety of voluntary benefits including life and disability insurance, and sick time if required by law in the worked-in state/locality.
#25572