ONE

Helping people save and grow their money.

AppSec Engineer

EngineerEngineerFull TimeRemoteTeam 201-500H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

31 days ago

Salary

$170K - $210K / year

Bachelor Degree4 yrs expEnglishAWSDockerEC2KubernetesPython

Job Description

• Architect and implement secure AWS configurations (IAM roles/policies, encryption keys, VPC segmentation) • Embed security into CI/CD pipelines and repos using policy-as-code tools (pre-commit hooks, SAST/SCA, IDE tool integrations) • Secure container and orchestration environments (EKS, Kubernetes, Docker) per best practices • Conduct threat modeling sessions and risk‑driven design reviews early in development • Perform secure code reviews and static/dynamic analysis; oversee remediation with dev teams • Automate repetitive security tasks—vulnerability triage, code scanning, tool orchestration • Build and extend in-house AppSec automation frameworks or pentest tooling • Partner with security architecture and detection teams (SIEM tuning, logging, telemetry alignment) • Develop and enforce AppSec standards and patterns across product teams; iterate through feedback loops • Support regulatory or compliance assessments (PCI, CCPA, GLBA) as needed

Job Requirements

  • 4+ years’ experience in application security engineering, DevSecOps, or security platform engineering
  • Deep familiarity with CVSS, MITRE ATT&CK frameworks, OWASP Top 10 and CWE taxonomy
  • Proven experience with AWS core services: IAM, KMS, VPC, EC2, RDS, EKS
  • Hands-on expertise in securing IaC and CI/CD pipelines; strong knowledge of policy-as-code tooling
  • Container security experience: Docker, Kubernetes, EKS-related threat surfaces
  • Solid threat modeling and secure code review skills; SAST/SCA tool proficiency
  • Experience scripting automation (e.g. Python, Bash, PowerShell) to streamline AppSec tasks
  • Capability to lead in-house AppSec frameworks or tooling development
  • Strong communicator, able to translate technical findings to non-technical stakeholders
  • Track record of defining and institutionalizing security architecture patterns

Benefits

  • Competitive base salary, stock options, and health benefits from Day 1
  • 401(k) plan with company match
  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth
  • A high-growth, mission-driven, inclusive culture where your work has real impact

Related Categories

Related Job Pages

More Engineer Jobs

Systematics Engineer

Kunai

20% of fortune 500 fintech trust Kunai for engineering talent.

Engineer31 days ago
Full TimeRemoteTeam 51-200Since 2001H1B Sponsor

Systematics Engineer developing software solutions for fintech at Kunai

United States

Lead Zuora Engineer

Toast

We empower the restaurant community to delight guests, do what they love, and thrive.

Engineer31 days ago
Full TimeRemoteTeam 1,001-5,000Since 2013H1B Sponsor

Lead Zuora Engineer designing and expanding subscription billing solutions at Toast

United States
$168K - $269K / year

DevTooling Engineer

Parity Healthcare Analytics

Creating innovative healthcare solutions from the frontlines for the frontlines

Engineer32 days ago
Full TimeRemoteTeam 1-10Since 2020H1B No Sponsor

DevTooling Engineer driving ecosystem growth for blockchain at Parity

Web3
United States

Senior Instrumentation Engineer

Switzerland Global Enterprise

We support Swiss SMEs in their international business and help innovative foreign companies to establish in Switzerland.

Engineer33 days ago
Full TimeRemoteTeam 51-200Since 1927H1B No Sponsor

Senior Instrumentation Engineer guiding nuclear instrumentation design and application for GE Vernova

North Carolina
$111.2K - $213.2K / year