Staff Application Security Engineer at Jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Application Security Engineer based in the United States. This is a senior security engineering opportunity focused on protecting applications, infrastructure, and software systems at scale. You will take ownership of application security programs while partnering closely with engineering and infrastructure teams. The role combines threat detection, vulnerability management, security testing, incident response, and security tooling. You will help build scalable security processes and integrate security practices directly into modern development and delivery workflows. The position offers significant autonomy, requiring strong technical judgment and the ability to navigate complex and ambiguous security challenges. You will also serve as a trusted security advisor and mentor, helping engineering teams strengthen their security practices. This is a remote opportunity within the United States, offering the chance to make a broad impact in a fast-moving, high-ownership environment. Accountabilities: Own and continuously improve the organization's SIEM, including configuration, tuning, monitoring, and development of effective alerts that identify and support response to threats across multiple layers. Conduct security architecture reviews, code reviews, and infrastructure configuration assessments to identify risks and recommend practical remediation strategies. Perform targeted penetration testing of web and mobile applications, manually validating vulnerabilities and investigating their underlying causes. Build, maintain, and optimize vulnerability management processes and CI/CD pipelines across container and application delivery environments. Partner closely with software development and infrastructure teams to promote secure coding practices, prioritize remediation, and resolve complex security issues. Develop and maintain security frameworks, tooling, and engineering standards that make security requirements clear, scalable, and actionable across the organization. Contribute to incident response and forensic investigations, using technical evidence and business context to make sound decisions during high-pressure situations. Monitor emerging threats and security trends and translate them into practical recommendations for engineering teams. Develop and support security awareness and training initiatives that strengthen security knowledge and empower engineers to build more secure systems. Operate independently while maintaining strong communication and alignment with stakeholders across engineering, infrastructure, and security functions. Requirements: Significant professional experience in application security, security engineering, software engineering, or a closely related discipline, with demonstrated ownership of security outcomes. Advanced proficiency in at least one programming language such as Ruby, Java, Python, C#, or Node.js. Strong hands-on experience managing SIEM platforms, developing effective detection and alerting strategies, and reducing unnecessary alert noise. Deep understanding of cloud environments and container technologies, including Docker and Kubernetes, with experience implementing automated container vulnerability management. Extensive experience with application security testing methodologies and tools, including SAST, DAST, and IAST, combined with the ability to manually validate security findings. Strong knowledge of established security principles and frameworks, including the OWASP Top 10, MITRE Top 25, and secure software development practices. Experience conducting security architecture, code, infrastructure, and application reviews, with the ability to identify root causes and recommend effective remediation. Experience with cloud security concepts and compliance frameworks such as SOC 2 and PCI. Strong analytical and problem-solving skills, particularly when working through ambiguous, complex, or high-impact security issues. Excellent communication skills and the ability to build credibility with engineering peers through clear, direct, and pragmatic guidance. A demonstrated ability to mentor others, advocate for security best practices, and influence teams without relying solely on formal authority. Comfort working autonomously in a fast-paced, collaborative, and remote-first environment. Benefits: Base salary range of $182,800–$215,000 USD , depending on factors such as experience, expertise, and location. Equity provided to all employees. Potential eligibility for an annual bonus depending on the role. Competitive compensation designed to reflect the scope and experience required for the position. Remote work opportunities within the United States, with a flexible hybrid-hub approach depending on role and location. Benefits and perks designed to provide employees with the resources and environment needed to succeed. A high-ownership environment where experienced professionals can make meaningful, organization-wide contributions. Opportunities to work on complex security challenges while collaborating with high-caliber engineering and technology teams. Perks and benefits may vary based on employment type, location, and other applicable factors.