{"schemaVersion":"jobsearcher.job.v1","id":"f789d37fd63bbe6d8d79edf6","url":"https://jobsearcher.com/jobs/f789d37fd63bbe6d8d79edf6","canonicalUrl":"https://jobsearcher.com/jobs/f789d37fd63bbe6d8d79edf6","title":"Application Security Engineer","description":"Experience: Mid Level\nSalary: $50 - $80 per hour\n\nJob Details\n-\n\nRESPONSIBILITIES\n\nPerform application security assessments including manual code review, SAST, DAST, SCA, and targeted penetration testing.\nLead threat modeling sessions for new features, architectural changes, and AI/LLM-backed workflows with customer product and engineering teams.\nIntegrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) with minimal developer friction.\nTriage, track, and drive remediation of findings across web, mOur Clientle, and API surfaces with developer-friendly workflows and SLAs.\nDesign and maintain secure coding standards, authentication and authorization patterns (OAuth 2.0, SAML, JWT), and training materials for customer development teams.\nEvaluate third-party libraries, vendor integrations, and open-source dependencies for supply chain and security risk.\nSupport incident response activities and contribute to post-incident analysis with a focus on application-layer root cause.\nWrite and maintain documentation, runbooks, and architecture decision records (ADRs) for AppSec tooling, coding standards, and remediation playbooks.\n\nQUALIFICATIONS\n\n3 to 5 years of experience in application security, penetration testing, or secure software development.\nStrong knowledge of OWASP Top 10, CWE, and common web and API vulnerability classes.\nHands-on experience with at least two of the following: SAST, DAST, SCA, or IAST tools in real CI/CD environments.\nProficiency in one or more programming languages (Python, Go, JavaScript/TypeScript, or Java) for automation, tooling, and integration work.\nFamiliarity with modern development workflows including Git, CI/CD pipelines, and containerized environments.\nSolid understanding of authentication and authorization frameworks (OAuth 2.0, SAML, JWT).\nExcellent communication skills with the ability to translate security findings into actionable engineering tasks.\nMust be located in the SF Bay Area or willing to travel to our San Francisco office on a regular cadence.\n\nNICE TO HAVE\n\nRelevant certifications such as OSCP, GWAPT, CEH, or CSSLP.\nExperience with bug bounty programs or responsible disclosure processes.\nFamiliarity with cloud-native security (AWS, GCP, or Azure) and cloud-native workload protection.\nPrior contributions to open-source security tooling.\n\nA bit about us:\n-\n\nWe are a Software Consulting firm working with enterprise and start companies that are AI driven and we are developing some of the most cutting edge software/security solutions platforms in the world\n\nWhy join us?\n-\n\nCompetitive Compensation\nWork on incredible projects that are fun and challenging\nFull Benefits (Medical, Vision, Dental)\n401k\nLong term Contract to Hire opportunity\n\n#techservices #ci-cd #api #remediation #root-cause #owasp #vulnerability #sast #dast #sca #security-tooling #ai-llm #tier3","company":"Leoforce","rawCompany":"leoforce","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-27T13:54:36.391Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer","description":"Experience: Mid Level\nSalary: $50 - $80 per hour\n\nJob Details\n-\n\nRESPONSIBILITIES\n\nPerform application security assessments including manual code review, SAST, DAST, SCA, and targeted penetration testing.\nLead threat modeling sessions for new features, architectural changes, and AI/LLM-backed workflows with customer product and engineering teams.\nIntegrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) with minimal developer friction.\nTriage, track, and drive remediation of findings across web, mOur Clientle, and API surfaces with developer-friendly workflows and SLAs.\nDesign and maintain secure coding standards, authentication and authorization patterns (OAuth 2.0, SAML, JWT), and training materials for customer development teams.\nEvaluate third-party libraries, vendor integrations, and open-source dependencies for supply chain and security risk.\nSupport incident response activities and contribute to post-incident analysis with a focus on application-layer root cause.\nWrite and maintain documentation, runbooks, and architecture decision records (ADRs) for AppSec tooling, coding standards, and remediation playbooks.\n\nQUALIFICATIONS\n\n3 to 5 years of experience in application security, penetration testing, or secure software development.\nStrong knowledge of OWASP Top 10, CWE, and common web and API vulnerability classes.\nHands-on experience with at least two of the following: SAST, DAST, SCA, or IAST tools in real CI/CD environments.\nProficiency in one or more programming languages (Python, Go, JavaScript/TypeScript, or Java) for automation, tooling, and integration work.\nFamiliarity with modern development workflows including Git, CI/CD pipelines, and containerized environments.\nSolid understanding of authentication and authorization frameworks (OAuth 2.0, SAML, JWT).\nExcellent communication skills with the ability to translate security findings into actionable engineering tasks.\nMust be located in the SF Bay Area or willing to travel to our San Francisco office on a regular cadence.\n\nNICE TO HAVE\n\nRelevant certifications such as OSCP, GWAPT, CEH, or CSSLP.\nExperience with bug bounty programs or responsible disclosure processes.\nFamiliarity with cloud-native security (AWS, GCP, or Azure) and cloud-native workload protection.\nPrior contributions to open-source security tooling.\n\nA bit about us:\n-\n\nWe are a Software Consulting firm working with enterprise and start companies that are AI driven and we are developing some of the most cutting edge software/security solutions platforms in the world\n\nWhy join us?\n-\n\nCompetitive Compensation\nWork on incredible projects that are fun and challenging\nFull Benefits (Medical, Vision, Dental)\n401k\nLong term Contract to Hire opportunity\n\n#techservices #ci-cd #api #remediation #root-cause #owasp #vulnerability #sast #dast #sca #security-tooling #ai-llm #tier3","datePosted":"2026-07-27T13:54:36.391Z","dateModified":"2026-07-27T13:54:36.391Z","hiringOrganization":{"@type":"Organization","name":"Leoforce","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f789d37fd63bbe6d8d79edf6"},"url":"https://jobsearcher.com/jobs/f789d37fd63bbe6d8d79edf6"}}