Application Security Engineer
Job Title: Application Security EngineerLocation: RemoteReports to: Information Security Director or Information Security ManagerDepartment: Information SecurityPosition Summary:The Application Security Engineer is responsible for strengthening Trulieve application security by embedding secure architecture, secure design, secure coding practices, and risk-based security review into the software development lifecycle.This role partners with application developers, architects, product owners, infrastructure teams, and Information Security leadership to identify application risks early, translate security principles into practical engineering requirements, and help teams deliver secure, resilient, and compliant applications.The Application Security Engineer is expected to demonstrate hands-on development or engineering experience, a practical understanding of OWASP guidance, and the ability to show how security principles were applied in current or prior roles through design reviews, threat modeling, code review, remediation guidance, or security control implementation.Key Responsibilities:Lead application security reviews for internally developed, configured, and integrated applications, including design review, threat modeling, code review coordination, and risk-based remediation guidance.Partner with software developers, architects, DevOps, infrastructure, and business teams to design secure, highly available application environments that align with Trulieve security standards and business requirements.Translate security principles into practical design requirements, secure coding patterns, reusable guidance, and engineering recommendations that development teams can adopt within delivery timelines.Assess application architecture, authentication, authorization, session management, input validation, data protection, API security, error handling, logging, and configuration patterns for security risk.Apply OWASP Top 10, OWASP Application Security Verification Standard (ASVS), OWASP API Security guidance, and secure design principles to identify, explain, prioritize, and remediate application vulnerabilities.Review application changes, third-party integrations, APIs, cloud services, and identity / access patterns to identify security gaps before production release.Collaborate with vulnerability management and security operations teams to validate findings, reduce false positives, prioritize remediation, and ensure application vulnerabilities are tracked through closure.Support secure SDLC activities such as security requirements definition, developer education, security acceptance criteria, application risk assessments, and release readiness reviews.Evaluate and help operationalize application security tooling such as SAST, DAST, SCA, secret scanning, container security, API testing, and CI/CD security controls.Document application security current state, gaps, decisions, exceptions, compensating controls, target state recommendations, and remediation plans in an audit-defensible manner.Communicate application security risks clearly to technical and non-technical stakeholders, including the business impact, likelihood drivers, remediation options, and practical implementation considerations.Use prior development or engineering experience to mentor developers and junior security team members on secure coding, secure design tradeoffs, and practical vulnerability prevention.Maintain working knowledge of current and emerging application threats, secure architecture patterns, cloud-native development practices, identity and access controls, and regulatory expectations affecting application data protection.Establish and maintain productive working relationships with development teams, applications owners, business stakeholders, vendors, and Information Security leadership.Incorporate company strategic goals, risk appetite, compliance obligations, and operational priorities into application security recommendations and continuous improvement initiatives.Core Capability Areas: Secure Architecture & Design: Ability to evaluate application architecture, identity flows, API boundaries, data handling, and trust zones.Development & Engineering Background: Hands-on experience with software development, scripting, API development, CI/CD pipelines, or engineering delivery.OWASP & Application Risk: Practical knowledge of OWASP Top 10, ASVS, API security risks, and common vulnerability classes.Secure SDLC Enablement: Experience embedding security requirements, testing, and remediation into delivery workflows.Communication & Influence: Ability to explain application risk in business terms and guide teams toward practical remediation.Qualifications:Bachelor's Degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or related discipline preferred; equivalent hands-on experience may be considered.5+ years of experience in application security, software engineering, cybersecurity engineering, secure architecture, or a closely related role.Demonstrated development or engineering experience with one or more modern programming or scripting languages, application frameworks, APIs, CI/CD workflows, or cloud-native services.Strong understanding of application security principles, secure design, secure coding, authentication, authorization, data protection, cryptography, logging, input validation, and error handling.Practical knowledge of OWASP Top 10, OWASP ASVS, API Security risks, common vulnerability classes, and how those risks are prevented or remediated in application design and code.Experience reviewing security findings from SAST, DAST, SCA, container security, cloud security, secret scanning, penetration testing, code review, or vulnerability management tools.Ability to explain how security principles have been applied in current or previous roles through concrete examples such as secure design decisions, remediation plans, threat models, code changes, or developer guidance.Ability to work effectively with development teams, architects, product owners, infrastructure, operations, vendors, auditors, and Information Security leadership.Self-motivated, organized, and capable of managing multiple priorities in a dynamic environment with limited supervision.Strong written and verbal communication skills with the ability to translate technical risk into business-relevant language.Experience assessing cloud-hosted application environments for security risk, including identity access controls, encryption, logging, network exposure, workload configuration, secrets management, and secure deployment patterns.Experience identifying and helping mitigate ecommerce fraud and abuse risks, including account takeover, credential stuffing, bot activity, payment abuse, promo/discount abuse, transaction anomalies, and related monitoring or control requirements.Preferred certifications include CSSLP, GWAPT, GWEB, GSSP, CISSP, CCSP, Security+, or equivalent application security / software security certifications.Preferred / Differentiating Experience:Experience building or operating secure SDLC processes, application security standards, developer security training, or application security intake / review workflows.Experience with cloud application security, containerized workloads, serverless applications, API gateways, identity federation, secrets management, and CI/CD security controls.Experience supporting regulated environments where application controls support privacy, financial reporting, payment security, health information protection, or audit readiness.Experience using risk-based prioritization to balance security requirements, business delivery timelines, compensating controls, and operational constraints.Experience mentoring developers or cross-functional teams on practical secure coding, vulnerability prevention, and secure design improvements.Work Schedule:40+ hours weekly with flexible hours depending on department needs.Equal Opportunity Employer / Trulieve Supports a Drug-Free Workplace