Senior Application Security Engineer

🏒 Clear Capital · all Clear Capital jobs
πŸ“ United States
πŸ’° USD 111,000 - 144,400 / annual
πŸ“… Posted 2026-07-14 Β· via Himalayas
🏷 Security-Engineer,Enterprise-Information-Security,Technology,Application-Security-Engineering,Cybersecurity,Secure-Software-Development,Senior-Application-Security-Engineer,Application-Security-Engineer,Lead-Application-Security-Engineer,Senior-Information-Security-Engineer,Application-Security-Lead,Senior-Principal-Security-Engineer,Senior-Security-Engineering-Manager,Senior-Cybersecurity-Engineer
Apply on original site β†—

The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.

This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege.
What You Will Work On

- Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices.

- Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes.

- Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics.

- Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain.

- Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning.

- Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks.

- Fully define and follow a security review process to ensure an automated and repeatable process is managed.

- Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing.

- Train developers and junior application security engineers on weaknesses to avoid.

- Perform other duties as assigned.

Who We Are Looking For

- 4+ years of related experience required.

- Bachelor’s Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience.

- Highly technical and analytical, with a background in software development, and scripting (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP).

- Expertise in application security testing, including hands-on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools.

- Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.

- Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.

- Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.

What You Can Expect

- Compensation: The base salary for this position ranges from $111,000 to $144,400 annually, depending on your location, experience, and qualificati

← All remote jobs