Application Security Engineer
Burp SuiteFortifyCheckmarxVeracodeAWSAzureKubernetesPenetration TestingThreat ModelingSecure SDLC
About the Role
We are looking for an Application Security Engineer to strengthen secure software delivery and partner closely with engineering teams in Reading, Pennsylvania. This role focuses on embedding security throughout the software lifecycle, from architecture and development through deployment and ongoing operations. The ideal candidate brings deep application security expertise, a collaborative mindset, and the ability to translate security requirements into practical engineering guidance.
Responsibilities:
• Partner with software engineering and cybersecurity teams to build security into application design, coding practices, release processes, and production support.
• Perform in-depth security evaluations through code analysis, threat modeling, penetration testing, and vulnerability assessments to uncover and prioritize risk.
• Establish and uphold secure development standards, reusable patterns, and technical guidance that improve consistency across teams.
• Administer and enhance security controls within CI/CD workflows, including code scanning, infrastructure-as-code checks, and container security tooling.
• Contribute to architecture assessments for cloud-based systems, microservices, and containerized applications to ensure resilient and secure designs.
• Evaluate application risks and support formal security reviews to guide mitigation planning and informed technical decisions.
• Verify that application security activities align with applicable compliance obligations and recognized industry frameworks.
• Create and deliver training sessions that help developers strengthen secure coding habits and increase security awareness.
• Track emerging attack techniques and threat intelligence, then apply those insights to improve preventive and detective controls.
• Support the monitoring, investigation, and remediation of application security issues, while coordinating effectively with external vendors and consultants as needed.
• At least 5 years of experience in information security, including 3 or more years dedicated to application security, secure software engineering, or DevSecOps.
• Proven success helping build, strengthen, or scale an application security program in a lead or highly influential capacity.
• Strong understanding of common application security risks, secure SDLC practices, and widely recognized vulnerability frameworks and standards.
• Hands-on experience with application security testing platforms such as Burp Suite, Fortify, Checkmarx, Veracode, or similar tools.
• Working knowledge of threat modeling, penetration testing, secure architecture review, and modern software security assessment techniques.
• Practical experience securing cloud environments such as AWS or Azure, along with familiarity with Kubernetes, container hardening, and runtime protection.
• Active passport required, with willingness and ability to travel internationally.
Responsibilities:
• Partner with software engineering and cybersecurity teams to build security into application design, coding practices, release processes, and production support.
• Perform in-depth security evaluations through code analysis, threat modeling, penetration testing, and vulnerability assessments to uncover and prioritize risk.
• Establish and uphold secure development standards, reusable patterns, and technical guidance that improve consistency across teams.
• Administer and enhance security controls within CI/CD workflows, including code scanning, infrastructure-as-code checks, and container security tooling.
• Contribute to architecture assessments for cloud-based systems, microservices, and containerized applications to ensure resilient and secure designs.
• Evaluate application risks and support formal security reviews to guide mitigation planning and informed technical decisions.
• Verify that application security activities align with applicable compliance obligations and recognized industry frameworks.
• Create and deliver training sessions that help developers strengthen secure coding habits and increase security awareness.
• Track emerging attack techniques and threat intelligence, then apply those insights to improve preventive and detective controls.
• Support the monitoring, investigation, and remediation of application security issues, while coordinating effectively with external vendors and consultants as needed.
Requirements
• Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or another related technical discipline.• At least 5 years of experience in information security, including 3 or more years dedicated to application security, secure software engineering, or DevSecOps.
• Proven success helping build, strengthen, or scale an application security program in a lead or highly influential capacity.
• Strong understanding of common application security risks, secure SDLC practices, and widely recognized vulnerability frameworks and standards.
• Hands-on experience with application security testing platforms such as Burp Suite, Fortify, Checkmarx, Veracode, or similar tools.
• Working knowledge of threat modeling, penetration testing, secure architecture review, and modern software security assessment techniques.
• Practical experience securing cloud environments such as AWS or Azure, along with familiarity with Kubernetes, container hardening, and runtime protection.
• Active passport required, with willingness and ability to travel internationally.
You'll be redirected to Robert Half's application page
Job Details
Salary
$117K–$147K
Location
United States - Reading PA
Job type
Full-time
Category
Application Security
Experience
5+ years
Posted
2w ago
Job Highlights
- $117K–$147K salary
- 5+ years level role
- 100% Remote — open to candidates in United States
About Robert Half
This job is hosted by Robert Half. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.