Application Security (DevSecOps) Senior Engineer
**NO C2C SUBMISSIONS**Enterprise Application Security ArchitectKey Requirement: Must be highly technical and comfortable reviewing source code, security findings, and GitHub repositories. This is not a policy-only security role.We're seeking an Application Security (DevSecOps) Senior Engineer to lead application security strategy, architecture governance, and secure software development practices across the enterprise. This individual will partner closely with architecture, engineering, DevOps, and security teams to ensure applications are secure by design from development through deployment.What You'll DoLead enterprise application security architecture and governanceReview and approve application, API, cloud, and integration designsConduct threat modeling and security architecture reviewsEstablish and govern Secure SDLC (SSDLC) and DevSecOps practicesDrive GitHub and source code security standards, including CodeQL, secret scanning, dependency management, and branch protectionsReview source code vulnerabilities and provide remediation guidanceDefine standards for SAST, DAST, SCA, API security, container security, and CI/CD securityPartner with engineering teams to embed security throughout the development lifecycleSupport cloud security initiatives across Azure, AWS, and SaaS platformsEnsure compliance with frameworks such as NIST, ISO 27001, SOC 2, and related security standardsRequired Experience8+ years in Application Security, Security Architecture, Software Engineering, or DevSecOpsStrong background in application security architecture and secure software developmentHands-on experience reviewing code repositories and application security findingsDeep knowledge of OWASP, threat modeling, API security, secure coding, and DevSecOpsExperience with GitHub Enterprise, GitHub Advanced Security, Azure DevOps, CI/CD pipelines, and cloud securityStrong understanding of Zero Trust, IAM, Entra ID, and modern application security practicesPreferred CertificationsCISSP, CSSLP, CCSP, TOGAF, Azure Security, AWS Security, GWEB, GWAPT, or DevSecOps certifications.Ideal Background: Former software engineer, application architect, or DevSecOps leader who moved into security architecture and still enjoys digging into code.