Application Security Engineer

ObjectWin Technology Inc
  • Philadelphia, PA
    3 days ago

    Job Description

    Application Security Engineer

    PHILADELPHIA, PA 19103

    6 Months - Contract to Hire

    What You'll Do

    • Inventory and assess the environment by cataloging applications, development pipelines, source repositories, and existing AppSec tooling across the decentralized engineering organization, so standardization starts from an accurate picture rather than an assumption.
    • Create an application risk-tiering model that focuses limited application security effort on the applications carrying the most risk, so time is spent where it changes outcomes.
    • Define a minimum AppSec baseline that every development team is expected to meet, regardless of their tooling or SDLC, and socialize it with engineering leadership as the common standard.
    • Build and lead a Security Champions program across the decentralized product engineering teams.
    • Lead threat modeling for modernization and migration including the new trust boundaries and attack surfaces introduced by monolith-to-microservices re-architecture containerization, and re-platforming.
    • Provide secure-by-design guidance on migration decisions so security tradeoffs are understood before architecture is locked.
    • Own application inventory, risk-tiering, and coverage metrics, alongside vulnerability and remediation metrics, so leadership can see reach and gaps across the portfolio.
    • Triage and validate vulnerabilities surfaced through tooling, penetration tests, bug bounty submissions, and detection alerts, and drive remediation with the responsible engineering teams.
    • Partner with Security Operations and incident response on application-layer incidents, providing technical depth on attack paths, exploit feasibility, and remediation validation.

    Qualifications/Certifications

    What You Bring

    • 4+ years in software engineering, cloud engineering, or application security, including hands-on security work.
    • Experience wit hthreat modeling (STRIDE, PASTA, or equivalent), or a strong demonstrated ability to translate findings into engineering action.
    • Strong software or cloud engineering ability paired with real, load-bearing security instincts.
    • Enough application security depth to define what good looks like, including OWASP Top 10, OWASP ASVS, CWE Top 25, and modern attack patterns against web applications, APIs, and cloud-native services.
    • Experience integrating security tooling into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or equivalent).
    • Working knowledge of authentication and authorization patterns, including OAuth 2.0, OIDC, SAML, and modern session management.
    • Ability to communicate risk and remediation guidance to engineering audiences in language they will accept and act on.
    • Familiarity with containerization and cloud-native design (Docker, Kubernetes, etc.) and their security considerations.
    • Ability to win credibility with engineers and communicate risk in language they will act on.
    • Bachelor's degree in computer science, information security, or a related field, or equivalent practical experience.

    Nice to Have

    • Experience working with code scanner platforms such as Fortify, Veracode, or Wiz Code
    • Cloud security experience in Azure and AWS, including hands-on time with CSPM and CNAPP tooling such as Wiz.
    • Exposure to API security testing, runtime application protection, and modern WAF tuning.
    • Industry certifications such as OSCP, OSWE, GWAPT, GPEN, or CISSP.
    • Experience with software supply chain security frameworks (SLSA, S2C2F, OpenSSF Scorecard).
    • Prior work in a distributed, multi-tenant, or franchise-like operational environment.

    Numbers & Facts

    LocationPhiladelphia, PA

    Skills

    • Amazon Web Services (AWS)unmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Authenticationunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • DevOpsunmatched
    • Dockerunmatched
    • Engineeringunmatched
    • GitHubunmatched
    • Incident Responseunmatched
    • Information/Data Security (InfoSec)unmatched
    • Jenkinsunmatched
    • Leadershipunmatched
    • Machine Toolunmatched
    • Microservicesunmatched
    • Microsoft Windows Azureunmatched
    • OAuthunmatched
    • Penetration Testingunmatched
    • Product Engineeringunmatched
    • Riskunmatched
    • Scorecardingunmatched
    • Security Assertion Markup Language (SAML)unmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Supply Chainunmatched
    • Threat Modelingunmatched
    • Time Managementunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder