Position: Application Security Engineer (Senior AppSec)
Location: Remote
Duration: 6-12+ Months Contract
Role Overview
We are seeking experienced Senior Application Security Engineers to join our team and play a critical role in validating AI‑generated vulnerability findings and translating them into actionable technical remediation. This position requires strong expertise in application and product security, combined with a deep understanding of how vulnerabilities map to code and how developers remediate them in production environments. The ideal candidate will have a background as a software engineer who transitioned into AppSec, bringing both security insight and practical development knowledge.
Key Responsibilities
Validate AI‑generated vulnerability findings (e.g., from Anthropic’s Mythos) and assess exploitability, severity, and business impact.
Trace vulnerabilities to their technical root cause at the code level.
Collaborate with development teams to design and implement secure remediation strategies.
Conduct secure code reviews, threat modeling, and vulnerability assessments.
Define and enforce secure SDLC practices across product teams.
Provide guidance on API security, OWASP Top 10 risks, and secure design principles.
Partner with product owners and engineering teams to ensure vulnerabilities are remediated effectively and deployed safely.
Document findings, remediation steps, and best practices to strengthen organizational security posture.
Required Skills
Strong background in Application Security / Product Security.
Hands‑on experience with OWASP Top 10, SAST, vulnerability assessment, secure SDLC, threat modeling, code review, API security.
Ability to validate findings, assess severity, and trace vulnerabilities to root cause.
Experience working directly with developers to remediate vulnerabilities.
Strong communication skills to bridge security and engineering teams.
Ideal Profile
A software engineer turned AppSec professional — someone who understands both the security problem and how developers actually fix it.
Proven ability to work across multiple product teams, enabling secure development practices.
Experience with modern CI/CD pipelines and integrating security tooling into developer workflows.
By continuing you agree to our Terms & Privacy Policy.