Appsec Security Engineer positions focus on delivering results in their domain. This page aggregates open Appsec Security Engineer roles and what employers typically expect.
### *Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry.* **Job Description** **Job Family: Cybersecurity Engineering** Reports to: Cybersecurity Engineering Manager Direct Reports: None **POSITION SUMMARY STATEMENT** We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this role, you will embed directly with our Product and Engineering teams to secure both our third-party SaaS applications and our home-grown applications. You will serve as a trusted security consultant and a hands-on engineer. You will review complex API designs, threat model new features, and build custom security tooling. You will play a critical role in defining security development standards from scratch and automating security controls directly into our CI/CD pipelines. We’re seeking someone who is excited to bring an automation-first mindset and who knows how to balance developer needs with risk-informed pragmatism. You will bridge security, development and operation cultures by translating between development who want speed, security teams who want safety, and operation teams who want stability. We value diverse backgrounds, perspectives, and experiences, and we are committed to building a team where everyone feels they belong. We especially encourage candidates from underrepresented communities in cybersecurity and technology to apply. Our interview process focuses on problem-solving ability, practical skills, and collaborative mindset. **DETAILED RESPONSIBILITIES/DUTIES** You will help advance our automation‑first engineering strategy by designing and maintaining the foundational systems that enable secure, reliable, and scalable software delivery across the organization. **Engineering and Development** - **Pipeline Integration:** Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tools into pipelines for home-grown apps. - **Infrastructure as Code:** Develop secure IaC patterns using Terraform, Helm, and Kustomize. - **Build Security Tooling:** Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default - **AI-empowered Review Assistance:** Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products **Architecture & Design Consultation** - **Security Design & Threat Modeling:** Lead security design and threat modeling sessions based on OWASP Top 10 and Mitre & Attack with Product and Engineering teams during early software design phases - **API Security Evaluation:** Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks. - **Cloud & Container Security:** Define and validate security controls for Azure and Kubernetes to mitigate application-layer risks. **Collaboration & Governance** - **Program Maturation:** Define AppSec coverage, tooling, and assessment processes from scratch across our application landscape. Own and evolve our application security program including establishing and maintaining SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production - **Stakeholder Management:** Partner with engineering teams and s…