Senior Application Security Engineer
Lead application security assessments and vulnerability management in Azure Cloud and DevOps environments. Perform SAST, DAST, SCA, penetration testing, and API security testing while advising development teams on secure coding practices. Requires +10 years experience, fluency in English, and expertise in OWASP Top 10, Azure Security, and security automation.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
For our international customer, we are looking for a full remote Senior Application Security Engineer with +10 years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines in a Azure Cloud and Azure DevOps environment.
We are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management and DevSecOps advisory services. The successful candidate will lead security assessments, support vulnerability remediation efforts, advise development teams on secure software development practices, and contribute to application security governance, risk and compliance initiatives.
Candidates need to be flexible to work across time zones, including alignment with US Eastern Time where required. Candidates need to be fluent in English.
Tasks and responsibilities:
- Perform and support application security assessments, including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews;
- Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques;
- Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness;
- Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components;
- Lead vulnerability management activities, including identification, prioritization, remediation tracking, and reporting.
- Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria.
- Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation.
- Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices;
- Support application security policies, standards, risk assessments, threat modeling, and secure design reviews;
- Assist with security compliance and audit-related activities;
- Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage.
- Communicate security risks and remediation priorities to technical and non-technical stakeholders;
Looking to advance your Cyber Security career with relocation support? Explore Cyber Security Jobs with Relocation Packages that include comprehensive packages to help you move and settle in your new role.
Profile:
- Bachelor or Master degree;
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience;
- +10 years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines;
- Strong hands-on experience with: SAST, DAST, SCA, Penetration Testing, API Security Testing, Manual Security Assessments, ...;
- Extensive experience using Burp Suite for web and API security testing;
- Hands-on experience with tools such as: Burp Suite, HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools), ...
- Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization;
- Experience collaborating with development teams to drive remediation and improve security maturity;
- Strong written, verbal, and stakeholder communication skills;
- Experience with Azure Cloud and Azure DevOps;
- Experience with ServiceNow for vulnerability or incident management workflows;
- Experience creating security dashboards and reports using Power BI;
- Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices;
- Experience with AI-assisted security solutions, security automation, or agentic AI technologies;
- Fluent in English;
Discover our full range of relocation jobs with comprehensive support packages to help you relocate and settle in your new location.
Preferred Certifications
CISSP
CSSLP
GWAPT
GWEB
OSCP / OSWE
Security+
SSCP
Microsoft Azure Security Certifications (AZ-500 or equivalent)
Similar Jobs
Explore other opportunities that match your interests