Wilson, Elser, Moskowitz, Edelman & Dicker

Senior Application Security Engineer

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years experience in Application Security, Product Security, DevSecOps, or Software Engineering
  • Hands-on experience securing CI/CD pipelines and modern development workflows
  • Experience with secure coding principles and OWASP Top 10
  • Strong understanding of secure SDLC practices and vulnerability management
  • Proficient with several technologies including Azure DevOps and Snyk
  • Experience integrating security tooling into CI/CD pipelines
  • Excellent communication and collaboration skills

Responsibilities

  • Lead and mature the secure software development lifecycle (SSDLC) program
  • Partner with developers to embed secure-by-design principles into workflows
  • Perform application security reviews and threat modeling
  • Review source code to identify and remediate vulnerabilities
  • Integrate security tooling within Azure DevOps pipelines
  • Manage and improve security scanning processes
  • Establish a Security Champions program and deliver training for developers

Benefits

  • Outstanding benefits package, including 401k match and generous PTO plan
  • Ample opportunities for professional development and advancement
  • Access to corporate discount plans and other perks
Full Job Description
The Position

We are seeking a highly skilled Senior Application Security Engineer to help establish and mature our secure software development and DevSecOps program. This role will serve as the bridge between Information Security and Application Development, partnering closely with engineering leadership to embed security into the software development lifecycle without slowing innovation or delivery.

This individual will work across internally developed applications, cloud-native platforms, CI/CD pipelines, integrations, low-code/no-code platforms, and Azure-hosted services. The ideal candidate combines hands-on application security expertise with practical development experience and strong collaboration skills.

This position will report to the Information Security team with a strong dotted-line partnership into Application Development and Engineering leadership.

Key Responsibilities

Application Security & Secure Development Lifecycle (SDL)
  • Lead and mature the organization's secure software development lifecycle (SSDLC) program
  • Partner with developers and engineering leadership to embed secure-by-design principles into development workflows
  • Perform application security reviews, threat modeling, and secure architecture assessments
  • Review source code and assist development teams in identifying and remediating vulnerabilities
  • Establish secure development standards, policies, and reusable secure coding templates
  • Build and maintain "paved road" secure development patterns for common technologies and frameworks

DevSecOps & CI/CD Security
  • Integrate and optimize security tooling within Azure DevOps pipelines
  • Manage and improve SAST, DAST, SCA, API scanning, and IaC scanning processes
  • Enhance automated security testing within CI/CD workflows
  • Develop processes for vulnerability ingestion, triage, prioritization, remediation tracking, and reporting
  • Build dashboards and metrics around application security posture and remediation SLAs
  • Create or customize scripts and integrations to normalize findings across multiple security tools

Security Tooling & Vulnerability Management
  • Administer and optimize tools such as:
    • Snyk
    • SonarQube
    • Azure DevOps
    • PowerShell scanning tools
    • Additional open source or commercial AppSec tooling as needed
  • Evaluate gaps in existing security tooling coverage and recommend improvements
  • Tune scanners, suppress false positives appropriately, and create custom detection rules where necessary
  • Partner with development teams to manage security exceptions and remediation timelines

Cloud & Platform Security
  • Collaborate with cloud and infrastructure teams to secure Azure-hosted applications and services
  • Support security reviews involving:
    • Azure PaaS services
    • Containers
    • Databricks
    • MongoDB
    • Data Lake environments
    • Azure Data Factory
    • Power Platform / Power Apps
  • Assist with securing low-code/no-code platforms and related governance processes

Security Culture & Developer Enablement
  • Establish and support a Security Champions program within engineering teams
  • Deliver developer-focused training, workshops, lunch-and-learns, and secure coding guidance
  • Serve as a trusted advisor and mentor to developers on secure coding and DevSecOps practices
  • Promote a collaborative, enablement-focused security culture

Qualifications
  • 5+ years of experience in Application Security, Product Security, DevSecOps, or Software Engineering
  • Hands-on experience securing CI/CD pipelines and modern development workflows
  • Experience working directly with development teams in agile environments
  • Strong understanding of:
    • Secure coding principles
    • OWASP Top 10
    • Secure SDLC practices
    • Threat modeling
    • Vulnerability management
  • Experience with at least several of the following technologies:
    • Azure DevOps
    • Azure cloud services
    • Snyk
    • SonarQube
    • Containers/Kubernetes
    • PowerShell
    • Python
    • .NET
    • JavaScript
    • React
    • PHP
  • Experience integrating security tooling into CI/CD pipelines
  • Ability to analyze scanner results and distinguish meaningful risk from low-value findings
  • Strong scripting and automation skills
  • Excellent communication and collaboration skills


Wilson Elser offers a competitive salary and benefits package designed to support our attorneys both professionally and personally.

A variety of factors are considered in making compensation decisions, including but not limited to experience, education, licensure and/or certifications, geographic location, market demands, other business and organizational needs, and other factors permitted by law. Final salary wages offered may be outside of this range based on other reasons and individual circumstances. This position is considered full-time and therefore qualifies for benefits including 401(k) retirement savings plan, medical, dental, vision, disability, and life insurance. Details of participation in these benefit plans will be provided if an employee receives an offer of employment.

Salary Range:

$150,000-$180,000 USD

Why Should You Apply?
  • Benefits: Outstanding benefits package, including 401k match and generous PTO plan
  • Career Growth: Ample opportunities for professional development and advancement
  • Employee Perks: Access to corporate discount plans and other benefits

Wilson Elser welcomes submissions of candidates for our open positions exclusively from recruitment agencies with an active, signed fee agreement who have been granted access to a position through our dedicated Recruitment Agency Portal. We are unable to consider submissions from recruitment agencies without a current (dated as of 7/1/2024) agreement in place. We appreciate your understanding. For collaboration inquiries or to establish an agreement, please contact us at [redacted].

About Wilson, Elser, Moskowitz, Edelman & Dicker

Wilson Elser is a full-service law firm with clients in the United States, Latin America, Europe and Asia. Founded in 1978, it has grown to become one of the largest law firms in the United States. The firm provides legal services in a wide range of practice areas, including aviation, construction, cybersecurity, data privacy, employment, environmental, insurance coverage, intellectual property, product liability, professional liability, real estate, and transportation. Wilson Elser has more than 800 attorneys and 38 offices in the United States and abroad. The firm is headquartered in New York City.
Learn more about Wilson, Elser, Moskowitz, Edelman & Dicker
Industry
Founded
1978

Similar Jobs

More Jobs at Wilson, Elser, Moskowitz, Edelman & Dicker

More Information Technology Jobs

Find similar Senior Application Security Engineer jobs: