Security Engineer, Application Security
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.
About the job
Responsibilities
Application Security
- Embed security into every phase of the software development lifecycle.
- Champion security requirements for the responsible and secure integration of generative AI and agentic AI tools within the product stack.
- Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes.
- Perform secure code reviews and provide clear, actionable findings with remediation guidance.
- Partner with architecture and platform teams to establish secure REST and GraphQL API patterns.
- Maintain secure coding guidelines, API security standards, and security architectural patterns as paved roads for engineering teams.
- Provide code review feedback, write durable documentation, and conduct workshops or lunch-and-learns for engineers.
DevSecOps
- Integrate and maintain security tooling across CI/CD pipelines.
- Enforce security quality gates in delivery pipelines.
- Harden CI/CD platform components, including GitHub Actions and runner environments.
- Identify opportunities to use AI for engineering productivity and agentic security workflows.
- Work with DevOps engineers to ensure AWS cloud infrastructure is securely defined and deployed using infrastructure as code.
- Implement and validate security controls for containerized workloads.
- Support application-layer network security controls, including Web Application Firewalls and CDN security.
Vulnerability and Risk Management
- Operate the application vulnerability management lifecycle.
- Triage and prioritize findings from GHAS, NowSecure, Wiz, BugCrowd, penetration tests, and other sources based on business impact and exploitability.
- Identify systemic risks and facilitate cross-functional initiatives addressing root causes.
- Track security KPIs such as MTTR, vulnerability density, and CI/CD security coverage.
- Translate security metrics and risks into actionable insights for engineering and business leadership.
- Communicate security risk clearly to engineering and business leaders.
- Participate in a weekly on-call rotation.
Requirements
- 3+ years of experience in application security engineering.
- Experience building and operating internal security developer platforms or tooling that reduces developer friction.
- Ability to use AI/ML-driven tools to improve security effectiveness and scalability.
- Experience leading threat-modeling engagements and designing paved roads.
- Proven track record integrating security tooling into CI/CD pipelines.
- Working knowledge of OWASP Top 10 for web, mobile, API, and LLM security.
- Hands-on experience securing AWS deployments with container and Kubernetes security, infrastructure-as-code scanning, and policy-as-code approaches.
- Expertise in security-by-design with TypeScript, Swift, and/or Kotlin.
- Experience implementing secure primitives in iOS and/or Android ecosystems.
Nice-to-Haves
- AWS Certified Security – Specialty, CKS, GWEB, GMOB, or equivalent certification.
Compensation and Benefits
- Target salary range: $120,000–$140,000 USD.
- Total compensation may include incentive compensation, equity, and benefits.
- Unlimited vacation policy.
- Paid volunteer opportunities.
- Technology stipend of $4,000 every two years after start.
- Annual WFH stipend of $500.
- Monthly physical, mental, wellness, and learning stipend.
- Monthly lifestyle stipend.
- Medical, dental, vision, prescription, FSA, HRA, HSA, and family/dependent coverage.
- Traditional and Roth 401(k) plans with immediate company match.
- Basic, supplemental, and dependent life insurance.
- Short-term and long-term disability leave.
- Company-paid parental leave of up to 20 weeks for birthing parents and 12 weeks for non-birthing parents.
- Family-building benefits.
- Teammate discount for DICK'S Sporting Goods and its family of brands.
Skills
AWS, Kubernetes, Terraform, GitHub Actions, TypeScript, Swift, Kotlin, iOS, Android, REST APIs, GraphQL, Owasp Top 10, Web Application Firewalls, CI/CD, Policy As Code
Similar jobs
Security Engineering jobsThe Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Develops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.