Application Security Engineer positions focus on delivering results in their domain. This page aggregates open Application Security Engineer roles and what employers typically expect.
## Company Description *We were early to the fight against Ubiquitous Technical Surveillance, and we’ve been pushing the edge ever since.* *Our mission is to help government and enterprise organizations understand and manage commercial data risks, shape their digital signatures, and operate with confidence in an increasingly complex information landscape. We build and integrate advanced, tech-forward solutions to problems our customers often don’t know they have – until it matters most.* *We move fast, think critically, and deliver where it counts.* *What’s in it for you?* *We work hard and do fun things.* *You’ll work on high-impact, technically challenging problems alongside a team that values teamwork over competition. Veilant offers a solid work-life balance and flexible remote work options. At Veilant, you’ll work with the most talented software developers, systems engineers, and subject matter experts, building tools and systems that make a real difference.* ## Job Description Veilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure, and continuously improve software developed by internal and partner engineering teams. This role is ideal for someone who combines a software engineering foundation with an attacker mindset. You will review major and minor software releases before deployment, identify and validate vulnerabilities, create proof-of-concept demonstrations where appropriate, and provide practical remediation guidance that developers can act on. You will not simply file security tickets and move on. You will work closely with engineering teams to understand application architecture, business logic, user workflows, data sensitivity, and production environments so that your findings are accurate, contextualized, and useful. You will work collaboratively across Veilant’s software, DevSecOps, and infrastructure teams. **In this role, you will:** - Audit software releases across major and minor cycles to intercept and remediate security flaws before deployment. - Analyze source code to identify, isolate, validate, and contextualize vulnerabilities in complex application codebases. - Build safe proof-of-concept examples to demonstrate exploitation paths and verify the real-world impact of discovered risks. - Contextualize findings based on application business logic, user workflows, data sensitivity, and production use cases. - Author clear remediation guidance and partner with development teams to implement effective patches, controls, or architectural mitigations. - Intercept and analyze application-layer network traffic using tools such as Burp Suite or similar intercepting proxies to inspect encrypted payloads, API calls, and authentication flows. - Assess and help secure core architectures across REST APIs, SQL databases, PostgreSQL, JWT/OAuth, identity providers, and token-based authentication mechanisms. - Perform threat modeling for web applications based on use cases, data flows, user roles, trust boundaries, and production environments. - Improve DevSecOps pipelines by integrating, tuning, and operationalizing SAST, DAST, SCA, IaC scanning, secrets detection, and container security tooling. - Support container runtime security efforts using monitoring and runtime protection tools such as Falco, NeuVector, or similar technologies. - Create standardized security reporting that translates technical findings into clear risk narratives for both engineering teams and executive stakeholders. **What You Will Accomplish in Your First Six Months** Within your first six months, success in this role will look like: **Building a repeatable AppSec review process** for major and minor software releases, helping engineering teams identify and resolve security issues before deployment. **Integrating and improving SAST, DAST, and SCA checks in CI/CD pipelines** so that security testing becomes a reliable part of the development lifecycle rather than a late-stage blocker. **Est…