Application Security Engineer (Senior) ID71672
<div>AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.<br></div><div><br></div><div><b>WHY JOIN US</b><br></div><div>If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!<br></div><div><br></div><div><b>ABOUT THE ROLE</b><br></div><div>We are looking for a <b>Senior Application Security Engineer</b> to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program. You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks. The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus.<br></div><div><br></div><div><b>WHAT YOU WILL DO</b><br></div><div>- Engineer and deploy AI-enabled secure code scanning capabilities and Golden Images to drive secure-from-the-start adoption;<br></div><div>- Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows;<br></div><div>- Architect the integration of continuous security scanning tools into enterprise CI/CD pipelines and tune them to eliminate noise;<br></div><div>- Act as a senior technical SME by reading and reviewing complex application code in Java and Python and providing software engineers with highly specific, code-level remediation guidance.<br></div><div><br></div><div><b>MUST HAVES</b><br></div><div>- 6+ years of software engineering experience with a strong subsequent focus on <b>Application Security</b> and <b>DevSecOps</b>;<br></div><div>- Strong coding and architectural proficiency in <b>Python</b> for security automation and scripting;<br></div><div>- Strong coding and architectural proficiency in <b>Java</b> for reviewing and securing enterprise source code;<br></div><div>- Deep, hands-on expertise deploying and tuning modern application security testing tools, including <b>SAST</b>, <b>DAST</b>, and <b>SCA</b>;<br></div><div>- Experience integrating application security testing tools into complex <b>CI/CD orchestration</b> ecosystems;<br></div><div>- Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks;<br></div><div>- Upper-intermediate English level.<br></div><div><br></div><div><b>NICE TO HAVES</b><br></div><div>- Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation;<br></div><div>- Advanced application threat modeling experience.<br></div><div><br></div><div><b>PERKS AND BENEFITS</b><br></div><div>- <b>Professional growth</b>: Mentorship, TechTalks, and personalized growth roadmaps.<br></div><div>- <b>Competitive compensation</b>: USD-based pay with education, fitness, and team activity budgets.<br></div><div>- <b>Exciting projects</b>: Modern solutions with Fortune 500 and top product companies.<br></div><div>- <b>Flextime</b>: Flexible schedule with remote and office options.<br></div><br>