Senior Appsec Engineer positions focus on delivering results in their domain. This page aggregates open Senior Appsec Engineer roles and what employers typically expect.
**At Arctic Wolf, you won’t just watch the cybersecurity industry evolve – you'll help lead the change. Our global Pack is made up of people who thrive on solving hard problems, moving fast, and building technology that protects organizations around the world. We’re proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights and IDC MarketScape – but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our Aurora Platform.** **If you’re looking for meaningful work, smart teammates and the chance to make a real impact in a high-growth company that’s redefining security operations, Arctic Wolf is the right place for you!** **Our mission is simple: End Cyber Risk. We’re looking for a Senior AppSec Engineer to be part of making this happen.** **Position Overview and Objective** At Arctic Wolf, we are transforming our Application Security function to be AI-first, fundamentally changing how security work is executed and scaled across the organization. We are seeking a Senior Application Security Engineer to help scale secure-by-design practices across our cloud, SaaS, and AI-enabled platforms. In this role, you will partner closely with engineering teams to identify, assess, and reduce application security risk throughout the software development lifecycle. You will independently execute threat modeling activities, perform security assessments, triage vulnerabilities, and provide actionable remediation guidance to development teams. You will also contribute to improving AppSec processes, tooling, and standards while helping strengthen the organization’s overall security posture. **Responsibilities** You will excel in this role if you are: - Conduct threat modeling exercises for applications, APIs, microservices, and AI/LLM-enabled capabilities - Perform application security reviews and vulnerability assessments across the SDLC - Triage and validate findings from SAST, DAST, SCA, IaC, container, and other AppSec security tools - Partner with engineering teams to provide clear, actionable remediation guidance and support risk-based decision making - Support secure development practices by identifying opportunities for process, tooling, and workflow improvements - Contribute to the refinement of security standards, SOPs, playbooks, and reusable security guidance - Help drive adoption and optimization of AppSec tooling and automation across engineering teams - Collaborate with developers, product managers, architects, and Security Champions to improve security awareness and maturity - Mentor junior engineers, interns, or peers and contribute to a culture of continuous learning - Stay current on emerging application security risks, attack techniques, vulnerabilities, and industry best practices **Experience and Requirements** - 5+ years of experience in application security, secure software development, or related security engineering roles - Strong understanding of application security fundamentals including OWASP Top 10, secure coding principles, and common attack patterns - Experience conducting threat modelling and security architecture reviews - Hands-on experience with AppSec tooling such as SAST, DAST, SCA and vulnerability management platforms - Experience validating and triaging security findings and working directly with engineering teams on remediation - Familiarity with cloud-native application architectures and modern development practices - Ability to communicate technical security risks and recommendations clearly to developers, product managers, and leadership audiences - Strong analytical and problem-solving skills with the ability to identify root causes and propose practical solutions - Ability to independently manage multiple priorities and drive deliverables to completion **Preferred Qualifications** - Experience securing cloud environments in AWS, Azure, or GCP - Familiarity with AI/GenAI application security concepts and frameworks su…