Lancesoft logo

Application Security Engineer

Lancesoft
  • New York, NY
  • $65
  • Quick Apply
30+ days ago

Job Description

Hybrid in Charlotte, NC & New York, NY
Application Security Engineer


What You’ll Do
  • Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering.
  • Standing up and operating the AppSec tooling stack —SAST, SCA, secrets scanning, and container/IaC scanning —integrated into business unit CI/CD pipelines.
  • Designing and implementing AI-assisted triage workflows on top of AppSec tooling so that finding volume does not overwhelm developers and false positives are filtered before reaching engineering teams.
  • Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process.
  • Partnering with business unit development leaders to build the relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.
  • Contributing to AI security strategy —evaluating emerging tools (AI code review assistants, agentic security testing, automated security requirement generation) and recommending what to operationalize and what to defer.
  • Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction.
Required Qualifications
  • 7+ years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.
  • Hands-on experience deploying and operating modern AppSec tooling (e.G., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security).
  • Working code-level proficiency in at least three commonly-used languages (e.G., Python, JavaScript/TypeScript, Java, C#, Go) sufficient to read, review, and triage findings.
  • Strong scripting and automation skills in Python or equivalent;comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
  • Demonstrated ability to influence engineering organizations without direct authority —negotiating standards, driving adoption, and partnering with development leaders.
  • Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks.
Preferred Qualifications
  • Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).
  • Familiarity with one or more compliance frameworks relevant to our environment (HITRUST, HIPAA, NIST AI RMF, SOC 2).
  • Prior experience working in a regulated or healthcare-adjacent environment.
  • Cloud security depth in at least one major provider (AWS, Azure, GCP).

Numbers & Facts

LocationNew York, NY
IndustryStaffing/Employment Agencies
Salary$65
Company Size2,000 to 2,499 employees
Year Founded2000
Websitehttp://www.lancesoft.com/

About Company

We are a $125 Million, NMSDC-certified Minority & Woman owned Workforce Solutions Company headquartered in the DC metro area with presence across US with global presence - Canada, Mexico, India, UK, Malaysia, Indonasia, Hongkong, Singapore, UAE. We are specialized in providing Workforce Solutions, SOW project delivery, Engineering Solutions, Creative Services. We currently support 100+ Fortune companies globally and across multiple industry segments. We are currently supporting several massive programs across industry segment nationally/globally (Intel, Ally, AMD, QUALCOMM, Morgan Stanley, Kraft/ Mondelez, MNP, Amdocs, Dell, SanDisk, Medtronic, Becton Dickinson, GE, Lockheed Martin, UTC, L-3 Communications, Caterpillar, BMW, Mercedes Benz, National Grid, Dominion, Energy Future Holdings, PSEG, 3M, Fidelity, Aetna, Humana, Johnson & Johnson, Pfizer, Merck etc). 

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender, identity, national origin, disability, or protected veteran status.

Skills

  • Amazon Web Services (AWS)unmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Cloud Computingunmatched
  • Code Reviewsunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • DevOpsunmatched
  • GCP (Good Clinical Practices)unmatched
  • GitHubunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Healthcareunmatched
  • Jenkinsunmatched
  • Machine Toolunmatched
  • Metricsunmatched
  • Microsoft Windows Azureunmatched
  • Negotiation Skillsunmatched
  • Python Programming/Scripting Languageunmatched
  • REST (Representational State Transfer)unmatched
  • Requirements Managementunmatched
  • Risk Managementunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Software Engineeringunmatched
  • Standards Developmentunmatched
  • Strategic Analysisunmatched
  • Supply Chainunmatched
  • Test Automationunmatched
  • Threat Modelingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder