{"schemaVersion":"jobsearcher.job.v1","id":"e3c4e84e8a7879e0f6a8cb84","url":"https://jobsearcher.com/jobs/e3c4e84e8a7879e0f6a8cb84","canonicalUrl":"https://jobsearcher.com/jobs/e3c4e84e8a7879e0f6a8cb84","title":"Application Security Engineer","description":"Job Summary:\nWe are seeking a highly skilled and motivated Application Security Engineer to join our Information Security Team. The candidate will have a deep understanding of application security principle, practices, and technologies. You will be responsible for ensuring the security of our software applications by identifying and mitigating potential security risk, implementing best practices, and collaborating with cross-functional teams to integrate security into the software development lifecycle. They will navigate the complexities of modern technologies, fortify our systems against evolving threats, and uphold the integrity of our data and operations with precision and foresight.\nKey Responsibilities:\nSecurity Assessments: Conduct comprehensive security assessments of applications/API/mobile applications, including code reviews, vulnerability assessments, and penetration testing. Perform security testing (SAST, DAST, pen test) and vulnerability assessments to identify security strengths and weaknesses.\nThreat Modeling: Develop and implement threat models to identify potential security issues early in the development process\nSecure Development: Provide guidance and support to development teams on secure coding practices, security architecture, and the use of security tools\nIncident Response: Investigate and respond to security incidents related to application vulnerabilities and provide remediation recommendations\nCompliance and Standards: Ensure compliance with industry standards, regulations, and best practices (e.g. OWASP, NIST, ISO/IEC 27001)\nTraining and Awareness: Develop and deliver security training programs for developers and other stakeholders to promote security awareness and best practices.\nSecurity Tooling: Implement and manage security tools and technologies to automate security testing and monitoring. Support Web Application Firewall Operation and new service onboarding.\nCollaboration: Work closely with development, QA, and operations teams to integrate security into the continuous integration/continuous development (CI/CID) pipeline.\nDocumentation: Maintain detailed documentation of security assessments, incidents, and remediation activities. Prepare KPI and KRI for AppSec services.\nQualifications:\n· Minimum 5 years of security engineering experience with a passion for information security; technical certifications such as CEH, CSSLP, or OSCP are required for this role\n· Technical Skill:\nProficiency in programming languages such as Java, C#, Python, or JavaScript\nExperience with security assessment tools such as OWASP ZAP, Burp Suite, AppSpider, Veracode, Semgrep, Data Theorem, Github advanced security, Snyk, Signal Science, Imperva, Cloud based WAF, etc.\nStrong understanding of application security vulnerabilities (e.g., SQL Injection, XSS, CSRF) and mitigation techniques\nFamiliarity with cloud security (e.g. AWS, Azure) and container security (e.g., Docker, Kubernetes)\n· Soft Skills:\nExcellent problem-solving and analytical skills\nStrong communication and collaboration abilities\nAbility to work independently and as part of a team in a fast-paced environment\nPreferred Qualifications:\nExperience with DevSecOps practices and tools\nKnowledge of microservices architecture and security implications\nUnderstanding of identity and access management (IAM) principles\nJob Type: Full-time\nPay: $90,000.00 - $110,000.00 per year\nBenefits:\nDental insurance\nHealth insurance\nPaid time off\nVision insurance\nSchedule:\n8 hour shift\nExperience:\nLinux: 5 years (Preferred)\nCybersecurity: 5 years (Required)\nInformation security: 5 years (Required)\nAbility to Commute:\nSan Marino, CA (Required)\nAbility to Relocate:\nSan Marino, CA: Relocate before starting work (Required)\nWork Location: In person","company":"Lexiglobal","rawCompany":"lexiglobal","city":"San Marino","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-04-12T20:39:53.173Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer","description":"Job Summary:\nWe are seeking a highly skilled and motivated Application Security Engineer to join our Information Security Team. The candidate will have a deep understanding of application security principle, practices, and technologies. You will be responsible for ensuring the security of our software applications by identifying and mitigating potential security risk, implementing best practices, and collaborating with cross-functional teams to integrate security into the software development lifecycle. They will navigate the complexities of modern technologies, fortify our systems against evolving threats, and uphold the integrity of our data and operations with precision and foresight.\nKey Responsibilities:\nSecurity Assessments: Conduct comprehensive security assessments of applications/API/mobile applications, including code reviews, vulnerability assessments, and penetration testing. Perform security testing (SAST, DAST, pen test) and vulnerability assessments to identify security strengths and weaknesses.\nThreat Modeling: Develop and implement threat models to identify potential security issues early in the development process\nSecure Development: Provide guidance and support to development teams on secure coding practices, security architecture, and the use of security tools\nIncident Response: Investigate and respond to security incidents related to application vulnerabilities and provide remediation recommendations\nCompliance and Standards: Ensure compliance with industry standards, regulations, and best practices (e.g. OWASP, NIST, ISO/IEC 27001)\nTraining and Awareness: Develop and deliver security training programs for developers and other stakeholders to promote security awareness and best practices.\nSecurity Tooling: Implement and manage security tools and technologies to automate security testing and monitoring. Support Web Application Firewall Operation and new service onboarding.\nCollaboration: Work closely with development, QA, and operations teams to integrate security into the continuous integration/continuous development (CI/CID) pipeline.\nDocumentation: Maintain detailed documentation of security assessments, incidents, and remediation activities. Prepare KPI and KRI for AppSec services.\nQualifications:\n· Minimum 5 years of security engineering experience with a passion for information security; technical certifications such as CEH, CSSLP, or OSCP are required for this role\n· Technical Skill:\nProficiency in programming languages such as Java, C#, Python, or JavaScript\nExperience with security assessment tools such as OWASP ZAP, Burp Suite, AppSpider, Veracode, Semgrep, Data Theorem, Github advanced security, Snyk, Signal Science, Imperva, Cloud based WAF, etc.\nStrong understanding of application security vulnerabilities (e.g., SQL Injection, XSS, CSRF) and mitigation techniques\nFamiliarity with cloud security (e.g. AWS, Azure) and container security (e.g., Docker, Kubernetes)\n· Soft Skills:\nExcellent problem-solving and analytical skills\nStrong communication and collaboration abilities\nAbility to work independently and as part of a team in a fast-paced environment\nPreferred Qualifications:\nExperience with DevSecOps practices and tools\nKnowledge of microservices architecture and security implications\nUnderstanding of identity and access management (IAM) principles\nJob Type: Full-time\nPay: $90,000.00 - $110,000.00 per year\nBenefits:\nDental insurance\nHealth insurance\nPaid time off\nVision insurance\nSchedule:\n8 hour shift\nExperience:\nLinux: 5 years (Preferred)\nCybersecurity: 5 years (Required)\nInformation security: 5 years (Required)\nAbility to Commute:\nSan Marino, CA (Required)\nAbility to Relocate:\nSan Marino, CA: Relocate before starting work (Required)\nWork Location: In person","datePosted":"2026-04-12T20:39:53.173Z","dateModified":"2026-04-12T20:39:53.173Z","hiringOrganization":{"@type":"Organization","name":"Lexiglobal","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Marino","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"e3c4e84e8a7879e0f6a8cb84"},"url":"https://jobsearcher.com/jobs/e3c4e84e8a7879e0f6a8cb84"}}