Jobedly Post a Job

Application Security Engineer

Awardco · Lindon, UT
Full-timeIT & Security General$179,000–$241,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Application Security Engineer role

Application Security Engineer positions focus on delivering results in their domain. This page aggregates open Application Security Engineer roles and what employers typically expect.

Awardco is reimagining the workplace to be more rewarding, supportive, and fun for everyone. As one of the fastest-growing companies in the employee experience industry, our mission is to help employees love what they do, love where they work, and get recognized for their efforts—especially our own employees! And as winners of Glassdoor’s Best Places to Work, Best in Brightest in the Nation, and Great Place to Work, we do much more than talk the talk. We’re looking for an Application Security Engineer joining our IT & Security team to build and mature our application security program as we continue to scale our SaaS platform. In this role, you’ll partner closely with product, engineering, and operations teams to design, build, and ship secure features — without slowing down creativity and innovation. You’ll own the secure software development lifecycle, lead security reviews for new capabilities, and help drive a culture where every engineer treats security as part of quality. You’ll also play a key role in enabling developers, building the skills and tooling they need to own security in their code through secure coding guidance, training, and a strong Security Champions program. If you enjoy rolling up your sleeves, solving real-world security problems, and making cloud products safer by design, this role is for you. What you will do: Embed security checkpoints into planning, design, development, testing, and release processes. Partner with engineering leads to ensure new features ship with security built in, not bolted on. Facilitate threat modeling for new services, APIs, and integrations. Recommend secure patterns and architectures for multi-tenant SaaS and cloud-native components. Perform targeted secure code reviews for high‑risk features and components. Configure and tune SAST, DAST, dependency, and container scanning to reduce noise and highlight real risk. Integrate and optimize AI-assisted application security tools (e.g., GitHub Advanced Security, Snyk, Wiz, or similar) within developer workflows to improve signal and remediation speed. Help define and maintain secure coding standards and patterns used across engineering teams. Triage, prioritize, and track remediation of application and API vulnerabilities across the stack. Advise on secure use of authentication, authorization, cryptography, and data protection controls. Help evaluate and integrate third‑party services and SDKs from a security perspective. Provide clear, technical explanations of findings, mitigations, and residual risk. Build and deliver pragmatic secure coding training tailored to our tech stack and common issues. Create playbooks, checklists, and self‑service guidance for developers to help them ship secure code independently. Champion a “secure by default” mindset across product and engineering. Grow and enhance the Security Champions program, mentoring developers to act as local security advocates on their teams. Assist with investigation and remediation for application‑level security incidents. Help improve detection, logging, and alerting for application and API misuse. What you will bring: 6+ years of experience in application security or in software engineering with a strong security focus for web applications or APIs. Hands‑on experience securing cloud‑hosted, multi‑tenant SaaS applications on a major public cloud platform. Strong understanding of web and API security fundamentals (authentication, authorization, session management, data validation, encryption, multi‑tenant isolation, etc.). Deep familiarity with the OWASP Top 10, common vulnerability classes, and practical exploitation/remediation techniques. Experience with one or more modern programming languages (for example: JavaScript/TypeScript, Java, C#, Python, or Go) and the ability to read and reason about production code. Hands‑on experience with application security tooling, such as Static analysis (SAST), Dynamic analysis (DAST), Dependency and container scanning, and API se…

Salary estimate

$179,000 – $241,000/yr
Provided by the employer.

Skills for this role

JavascriptTypescriptPythonJAVAC#GOSecurity

Resume tips for Application Security Engineer applicants

Interview preparation

Prepare concrete STAR-format stories that show Application Security Engineer outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Application Security Engineer problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Awardco

Awardco is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles