JOBSEARCHER

Senior Application Security Engineer

Senior Security Engineer – Secure Code Review📍 San Francisco, California🏢 On-site | Full-TimeMy client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development background and deep experience performing secure code reviews, analysing CVEs, and working with SAST and SCA tools in real production environments.ResponsibilitiesPerform manual and tool-assisted secure code reviews across Java and C#/.NET applicationsAnalyse and triage vulnerabilities in open-source libraries and frameworks (CVE analysis)Assess applications against OWASP Top 10 and identify exploitable security issuesProvide developers with actionable remediation guidance and architectural recommendationsUse AI-assisted code analysis tools to accelerate vulnerability detection and validate findingsSupport vulnerability management, risk assessments, and compensating controls such as WAF rulesResearch emerging open-source vulnerabilities and produce mitigation guidanceMust-Have Skills5+ years in software development, application security, or bothHands-on experience with SAST and/or SCA tools (e.g. Checkmarx, SonarQube, Black Duck)Real-world experience performing CVE analysis and exploitability triageStrong Java proficiency (JDK 8–21, Spring, Maven/Gradle)Ability to review and understand complex codebases written by othersSolid understanding of OWASP Top 10 and secure coding principlesPreferred SkillsC#/.NET and ASP.NET Core experienceDAST tools such as Burp Suite or OWASP ZAPExperience writing or validating WAF rulesSecure SDLC, threat modelling, or security champion programmesConsulting or professional services backgroundCloud application security experience (AWS, Azure, or GCP)Certifications such as CSSLP, GWEB, GPEN, or OSCP