Application Security Engineer

Arlington, VA | |

up to $180,000

Job Summary

AppSec Engineer III

Our client, a leading organization in the technology and financial services sector, is seeking an experienced Application Security Engineer III to join their dynamic team. This role offers an opportunity to lead advanced security initiatives, influence strategic security practices, and shape the future of application security across cloud-native and AI-powered systems. The successful candidate will serve as a technical expert, collaborating closely with engineering, DevOps, and vendor teams to enhance security posture and automate security controls.

Key Responsibilities:

  • Design and implement scalable security architectures for large-scale, cloud-native applications, including microservices and container environments.
  • Conduct comprehensive risk assessments, including penetration testing and secure code reviews.
  • Integrate security measures seamlessly into the software development lifecycle (SDLC), fostering a DevSecOps culture.
  • Drive security efforts for AI/ML features by assessing vulnerabilities, establishing secure architectures, and implementing robust testing and controls for AI models and related systems.
  • Evaluate and recommend third-party security tools and vendor solutions, ensuring alignment with organizational security standards.
  • Develop, improve, and scale automation tools integrated within CI/CD pipelines and cloud environments to enhance security operations.
  • Provide guidance and mentorship to junior engineers and cross-functional teams on application security best practices.
  • Participate in incident response activities, contributing to investigations and strategic security improvements.
  • Stay current with industry trends, emerging threats, and advancements in AI security to proactively refine security strategies.

Required Skills:

  • Extensive expertise in application security, secure software design, and risk management frameworks such as OWASP ASVS, OWASP Top 10, and NIST 800-53.
  • Proven experience conducting complex security assessments, including penetration testing and automated security controls.
  • Proficiency in programming languages such as Python, Java, and JavaScript.
  • Hands-on experience with security tools including SAST, DAST, SCA, Infrastructure as Code (IaC), and container security.
  • Strong understanding of modern architectures, including cloud-native environments, microservices, Kubernetes, serverless computing, and DevSecOps processes.
  • Deep knowledge of AI/ML security, including vulnerability assessments, AI threat modeling, and secure deployment practices, aligned with NIST AI RMF and OWASP Top 10 tailored for LLMs.
  • 5-7 years of relevant experience in application security, cloud security, or software engineering.

Nice to Have Skills:

  • Relevant certifications such as AWS Certified Security – Specialty, Certified Secure Software Lifecycle Professional (CSSLP), CISSP, or equivalent.
  • Bachelor’s degree in Computer Science, Information Security, or related fields, or equivalent practical experience.

Share This Job

I want more
jobs like this
in my inbox
weekly.

ABOUT US

Our High Trail Verified members include elite Technical and Solutions Architects, Developers, Engineers, Administrators, Business Analysts, Project Managers and Leaders, with a proven track record of delivering solutions to complex problems.

If you are ready to Elevate Your Work, you’ve come to the right place. Contact us to schedule a consultation.

Other Jobs you might like…