Application Security Engineer

Overture Partners

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in technology or security, especially in Application Security and Secure SDLC.
  • Strong grasp of modern application design, development, testing, and security processes.
  • Proven ability to conduct thorough application risk assessments beyond compliance checklists.
  • Knowledge of Secure SDLC, CI/CD processes, and vulnerability remediation techniques.
  • Familiarity with various security testing methods like SAST, DAST, and API testing.
  • Experience with tools such as SonarQube, Checkmarx, and Veracode for vulnerability assessments.
  • Collaborative mindset to work effectively with technical teams and navigate complex discussions.
  • Bachelor's degree in a related field, or equivalent professional experience.

Responsibilities

  • Embed security practices throughout the application lifecycle from design to deployment.
  • Review application features for adherence to security standards and requirements.
  • Establish secure coding guidelines in collaboration with engineering teams.
  • Analyze security scan results to prioritize vulnerabilities and verify remediation steps.
  • Evaluate app architectures and integrations for security weaknesses.
  • Assess third-party components for potential risks.
  • Integrate security controls into CI/CD and release workflows.
  • Evaluate AI applications for emerging security risks associated with model usage.

Benefits

  • Medical insurance with a choice of three plans.
  • 401(k) plan eligibility starting on day one.
  • Access to various voluntary benefits, including life and disability insurance.
  • Sick time offered in accordance with local laws.
Full Job Description
** Due to client requirements, applicants must be able to work on a w2 basis
** Onsite is required


Application Security Engineer

Job Overview

We are seeking an experienced Application Security Engineer to provide security leadership for a growing internal application development environment, including emerging AI-enabled solutions. This is a newly created role with an immediate need for someone who can embed practical security controls into the development lifecycle while partnering closely with engineering, data, security, and technology stakeholders.

To secure an interview, candidates should bring hands-on Application Security and Secure SDLC experience, understand modern development practices beyond checklist-based risk reviews, and be comfortable evaluating applications, architecture, vulnerabilities, third-party components, and emerging AI security risks.

Must Haves
  • Approximately 3-5 years of relevant technology or security experience, including practical exposure to Application Security, secure coding, or Secure SDLC activities.
  • Strong understanding of how modern applications are designed, developed, tested, deployed, and secured throughout the Software Development Life Cycle (SDLC).
  • Demonstrated ability to perform substantive application risk assessments and identify meaningful technical security concerns rather than relying solely on compliance checklists.
  • Working knowledge of Secure SDLC, CI/CD security, release controls, vulnerability remediation, and application security testing.
  • Familiarity with security testing approaches such as SAST, DAST, IAST, SCA, API security testing, infrastructure-as-code scanning, container scanning, and secrets detection.
  • Experience reviewing vulnerability or source-code scanning results using platforms such as SonarQube, Checkmarx, Fortify, Veracode, GitHub security capabilities, or comparable tools.
  • Ability to collaborate effectively with developers, architects, security professionals, and technology stakeholders while navigating competing priorities and technical disagreements.
  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Security, or a related discipline; equivalent relevant professional experience may be considered.

What the Client Needs You to Do

You will serve as a hands-on security partner for teams building new applications and AI-enabled capabilities. Your primary objective is to integrate security into development from design through release, ensuring new functionality receives appropriate technical review without unnecessarily slowing delivery.

You will evaluate proposed solutions, review architecture, establish secure development expectations, analyze scanning results, validate vulnerability remediation, assess third-party technology, and determine the security implications of new functionality before deployment.

The successful candidate must be comfortable challenging technical decisions constructively. This position requires someone who understands how software is actually built and can translate security requirements into practical guidance developers can implement.

Key Responsibilities
  • Embed Application Security practices throughout design, development, testing, deployment, and ongoing enhancement activities.
  • Review new application features and releases to confirm appropriate security requirements and development controls have been addressed.
  • Establish practical secure coding expectations, technical guardrails, and development security standards in partnership with engineering stakeholders.
  • Analyze application security scanning results, distinguish meaningful vulnerabilities from lower-priority findings, and validate appropriate remediation.
  • Evaluate application architectures, integrations, APIs, infrastructure components, and technical design decisions for potential security weaknesses.
  • Assess third-party software, libraries, services, and other external components introduced into application environments.
  • Partner with developers and technology teams to incorporate security testing and controls into CI/CD and release processes.
  • Evaluate AI-enabled applications for risks involving data exposure, source integrity, prompt injection, unauthorized disclosure, model misuse, and other emerging attack patterns.
  • Test internally developed solutions prior to release and provide actionable recommendations when security concerns are identified.
  • Collaborate across security and technology functions to resolve vulnerabilities, address technical risks, and strengthen secure development practices.

Additional Information

The technical environment includes a mixture of modern application development technologies. Experience with Python is particularly valuable, while exposure to Java, .NET, or comparable enterprise development frameworks is beneficial. Candidates do not need to specialize in one programming language; broader understanding of sound development and application security principles is more important.

Experience with Azure, Azure DevOps, GitHub Enterprise, GitHub Advanced Security, or comparable cloud-based development and DevSecOps platforms is preferred.

Candidates with knowledge of AI security will have an advantage. Relevant areas include the OWASP Top 10 for Large Language Model Applications, NIST AI Risk Management Framework, responsible AI concepts, prompt injection, sensitive-data leakage, hallucination risk, model misuse, AI agents, and prompt security.

This position is best suited for a technically curious security professional who can operate beyond policy and compliance activities. A software developer or engineer who has transitioned into Application Security may be particularly well aligned.

Strong interpersonal judgment is essential. You will work with stakeholders who may have different levels of security maturity and occasionally challenge security recommendations. The successful candidate can explain technical risk clearly, establish credibility with developers, resolve reasonable disagreements, and determine when a material security concern requires escalation.

W2 employees of Overture Partners who work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), 401(k) starting on day one, a variety of voluntary benefits including life and disability insurance, and sick time if required by law in the worked-in state/locality.

#25572

Similar Jobs

More Jobs at Overture Partners

  • Application Security Engineer
    $110K — $130K *
    Burlington, MA 01803 (Middlesex County)
    Information Technology
    In-Person
  • Zscaler Security Analyst
    $90K — $110K *
    Boston, MA 02115 (Suffolk County)
    Information Technology
    In-Person
  • Full Stack Java
    $110K — $130K *
    Boston, MA 02115 (Suffolk County)
    Information Technology
    In-Person
  • GRC Lead
    $120K — $145K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • DataBricks Data Engineer
    $125K — $150K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Application Security Engineer jobs: