{"schemaVersion":"jobsearcher.job.v1","id":"a0413bd6ada36dbe8e416e36","url":"https://jobsearcher.com/jobs/a0413bd6ada36dbe8e416e36","canonicalUrl":"https://jobsearcher.com/jobs/a0413bd6ada36dbe8e416e36","title":"Application Security Engineer","description":"Application Security EngineerThe Application Security Engineer will be responsible for analyzing software code repositories, code designs, processes, and implementation from a security perspective, and work with software development and infrastructure teams to identify and resolve security issues. You will include the appropriate security analysis, defenses and countermeasures at each phase of the software development lifecycle, to result in secure, robust and reliable software. An ideal candidate is someone that has experience in software development and information security, technical knowledge of the broad aspects of application and information security, and the soft skills to build a DevSecOps culture within an existing environment.Advanced knowledge and understanding of AppSec tools: SourceClear, BlackDuck, Threadfix, SonarQube and CheckmarxExperience with manual penetration testing as well as dynamic web application vulnerability scanning tools and servicesA strong desire to learn new and upcoming technologies Preferred Experience Candidate should meet several of the following qualifications:5-7 years experience developing software applications3-5 years experience implementing tools in support of and using CI/CD pipelines; experience integrating security tools into the pipeline and developer workflow3-5 years of experience with Amazon Web Services (AWS), either as an administrator or software developer2-3 years of experience working with code analysis tools to analyze static, dynamic, and open source code2-3 years of experience deploying Infrastructure as Code via Terraform, able to interpret CloudFormation templatesExperience and knowledge of how to work in an Agile/Scrum driven environmentIn depth comprehension of OWASP Top 10 / SANS 25 and application security frameworksIn-depth knowledge of application security concepts, best practices, and architectures for API, Microservices, networking and data DevOps tools, containerization and orchestration platforms (Docker, ECS, Fargate), code scanning tools and workflowsExpertise in working with Product, Application Development, QA, and DevOps teams to mitigate and address application threat vectorsIndustry related certifications a plus (CISSP, CISM, GIAC, OSCP, etc.)Education Bachelors degree in Information Security, Computer Science, or similar degree preferredEssential Duties And Responsibilities:Develop, operate and maintain processes and tools to identify, analyze, and remediate vulnerabilities and configurations that could negatively impact business, clients, and information.Work with software engineers to build secure architectures and patterns that can be implemented with minimal disruptionPartner with Product, Engineering, QA, and Infrastructure teams to ensure security is part of the design process and proactively built into the clients productsAnalyze security concerns and follow through with issues until resolutionLead application security testing; participate in penetration testing, vulnerability management, and other assessments as directedParticipate in additional team functions and rotating on-call schedule to support broader security tools and capabilities, including email, endpoint, perimeter, and cloudRespond to incidents and manage incident response as assignedDevelop training, documentation and guidance for internal teamsWork alongside other team members supporting the business by identifying and removing risks, threats, and anomalies in the environmentOther security-related projects that may be assignedRequired Skills:Strong oral and written communication skills; ability to present findings and recommendations to leadership while diving deep into code with developersStrong interpersonal skills, with the ability to enable fellow staff through training, communication and mentorshipProblem solving skills, with the ability to identify symptoms, root causes and possible solutions to challenges, identifying and creating plans to implement the most effective solutions","company":"Central Business Solutions","rawCompany":"central business solutions","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-11T12:39:32.190Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer","description":"Application Security EngineerThe Application Security Engineer will be responsible for analyzing software code repositories, code designs, processes, and implementation from a security perspective, and work with software development and infrastructure teams to identify and resolve security issues. You will include the appropriate security analysis, defenses and countermeasures at each phase of the software development lifecycle, to result in secure, robust and reliable software. An ideal candidate is someone that has experience in software development and information security, technical knowledge of the broad aspects of application and information security, and the soft skills to build a DevSecOps culture within an existing environment.Advanced knowledge and understanding of AppSec tools: SourceClear, BlackDuck, Threadfix, SonarQube and CheckmarxExperience with manual penetration testing as well as dynamic web application vulnerability scanning tools and servicesA strong desire to learn new and upcoming technologies Preferred Experience Candidate should meet several of the following qualifications:5-7 years experience developing software applications3-5 years experience implementing tools in support of and using CI/CD pipelines; experience integrating security tools into the pipeline and developer workflow3-5 years of experience with Amazon Web Services (AWS), either as an administrator or software developer2-3 years of experience working with code analysis tools to analyze static, dynamic, and open source code2-3 years of experience deploying Infrastructure as Code via Terraform, able to interpret CloudFormation templatesExperience and knowledge of how to work in an Agile/Scrum driven environmentIn depth comprehension of OWASP Top 10 / SANS 25 and application security frameworksIn-depth knowledge of application security concepts, best practices, and architectures for API, Microservices, networking and data DevOps tools, containerization and orchestration platforms (Docker, ECS, Fargate), code scanning tools and workflowsExpertise in working with Product, Application Development, QA, and DevOps teams to mitigate and address application threat vectorsIndustry related certifications a plus (CISSP, CISM, GIAC, OSCP, etc.)Education Bachelors degree in Information Security, Computer Science, or similar degree preferredEssential Duties And Responsibilities:Develop, operate and maintain processes and tools to identify, analyze, and remediate vulnerabilities and configurations that could negatively impact business, clients, and information.Work with software engineers to build secure architectures and patterns that can be implemented with minimal disruptionPartner with Product, Engineering, QA, and Infrastructure teams to ensure security is part of the design process and proactively built into the clients productsAnalyze security concerns and follow through with issues until resolutionLead application security testing; participate in penetration testing, vulnerability management, and other assessments as directedParticipate in additional team functions and rotating on-call schedule to support broader security tools and capabilities, including email, endpoint, perimeter, and cloudRespond to incidents and manage incident response as assignedDevelop training, documentation and guidance for internal teamsWork alongside other team members supporting the business by identifying and removing risks, threats, and anomalies in the environmentOther security-related projects that may be assignedRequired Skills:Strong oral and written communication skills; ability to present findings and recommendations to leadership while diving deep into code with developersStrong interpersonal skills, with the ability to enable fellow staff through training, communication and mentorshipProblem solving skills, with the ability to identify symptoms, root causes and possible solutions to challenges, identifying and creating plans to implement the most effective solutions","datePosted":"2026-09-11T12:39:32.190Z","dateModified":"2026-09-11T12:39:32.190Z","hiringOrganization":{"@type":"Organization","name":"Central Business Solutions","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a0413bd6ada36dbe8e416e36"},"url":"https://jobsearcher.com/jobs/a0413bd6ada36dbe8e416e36"}}