About the role

We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across engineering teams. This person deploys and tunes SAST, DAST, and IAST tools, conducts threat modeling, and integrates security controls into CI/CD pipelines. Comfort working across Python, JavaScript, or Java and cloud infrastructure such as AWS is essential.

What you will do

  • Be a part of a bleeding-edge security organization that enables the agile development of secure and reliable applications and products.
  • Deploy and tune code scanning solutions such as SAST, DAST, and IAST.
  • Interpret code scanning results to ensure the team is focused on remediation of the highest-risk vulnerabilities.
  • Perform threat modeling of applications to identify potential threat vectors in the technology stack that could be used by attackers and cause disruption or a potential data breach.
  • Collaborate with technology stakeholders to establish metrics that demonstrate application security proficiency across all engineering teams.
  • Steer the development of tools to improve the security of applications through automation and other means, allowing for faster and easier security gains by teams.
  • Ensure processes associated with key systems are documented, maintained, and archived.

Must haves

  • Strong hands-on Application Security experience in a modern software-development environment of at least 4 years.
  • Software engineering foundation with the ability to read, understand, and discuss code in Python, JavaScript, Java, or similar languages.
  • Deep experience deploying, tuning, and interpreting SAST and DAST tools; IAST experience is a plus.
  • Demonstrated experience conducting threat modeling and translating findings into practical security requirements.
  • Experience integrating security testing and controls into CI/CD pipelines and developer workflows.
  • Working knowledge of AWS/cloud application security, APIs, authentication/authorization, secrets management, and common web-application vulnerabilities.
  • Experience with infrastructure-as-code and automation tools such as Terraform, CloudFormation, Ansible, Puppet, Chef, or Salt.
  • Ability to prioritize true security risk, reduce scanner noise, and drive timely remediation of meaningful vulnerabilities.
  • Strong communication and influence skills: able to explain complex security issues clearly to engineers, engineering leaders, and nontechnical stakeholders.
  • Collaborative, solutions-oriented approach; must be able to build trust with development teams and improve security without unnecessarily slowing product delivery.
  • Upper-intermediate English level.

Nice to haves

  • Familiarity with security tools such as Nessus, Burp, and web application firewalls.
  • Experience with Static/Dynamic Application Security Testing methodologies and tools.
  • Experience with automation tools such as Terraform, Puppet, Chef, Salt, Ansible, or CloudFormation.
  • Experience conducting a detailed threat model exercise.
  • Experience with CI/CD pipelines and how to assess them from a security perspective, including the integration of security tools with the pipeline.
  • Experience working with cloud-based infrastructure and technologies, preferably AWS.
  • A collaborator who will partner across the engineering organization to drive the establishment of a security posture.
  • Results oriented and believes in steady continuous improvement.
  • Curious and always goes beyond what is happening to discover why.
  • An effective communicator with a solution-oriented mindset.
  • A strategic thinker who focuses on integrating current initiatives and ideating on ways to improve while still meeting the needs of the business.

Perks

  • Growth without limits: build your skills through mentorship, internal TechTalks, challenging projects, and a dedicated annual learning budget
  • Competitive compensation: get recognition that reflects your skills and impact, with regular performance and compensation reviews
  • Flexibility: work 100% remotely with flexible hours that support focus, autonomy, and a healthy work rhythm
  • Meaningful, modern projects: build impactful products using modern technologies alongside global teams and leading brands
  • Collaborative culture: join a supportive environment with zero micromanagement where ideas are welcomed and contributions are recognized
  • Well-being & support: access local well-being programs and people-focused support tailored to your location

Didn’t find the perfect fit?

Subscribe to get notified about new roles that match your skills and interests.

Get role alerts

Hiring process timeline

We designed our hiring process to be fast, transparent, and convenient — so you always know what to expect and can move through the steps without unnecessary delays.

lightning-iconA quick note

After applying, keep an eye on your inbox — including your spam folder. Occasionally, emails from our hiring platform, LaunchPod, may land there.

1

Tell us about yourself

Submit a short application form.

2

Pass a quick test

Pass a 30’- 60’ test.

3

Record a short video

Introduce yourself on video to fast-track your application process.

4

Meet our team

Once you pass the video review, grab a spot on our calendar for a technical interview.

5

Get an offer

Welcome to AgileEngine!

FAQ

Have any questions?

What is the work format and schedule?

We are a remote-first company, so all our positions are remote. Schedules are flexible, but the main requirement is to have an overlap with your client’s schedule to ensure smooth collaboration. Specific details depend on the project and are discussed during the interview process.

What level of English is required?

We look for Upper-Intermediate (B2) proficiency or higher. Since you will be collaborating with international teams and global clients (including Fortune 500 companies), English is a part of your daily work.

Does AgileEngine provide work equipment?

It depends on your location. We provide equipment in Ukraine, Poland, Argentina, Colombia, Mexico, Brazil, Guatemala, Portugal, Spain, and India. In the USA, equipment is usually provided by the client; otherwise, you will be expected to use your own setup.

What opportunities for professional growth do you offer?

We support continuous growth through personalized development paths tailored to each expert. Also, you can expect:

  • An annual learning and development budget
  • Internal workshops, tech talks, and mentorship programs
  • Opportunities to switch projects or grow into new roles over time

What does a typical team look like, and what tools do you use?

Teams vary by project, but you’ll usually work with a mix of experts across different fields, along with a delivery or project manager who supports collaboration and onboarding.

For day-to-day work, teams commonly use tools like Jira and Google Workspace, along with communication platforms such as Google Chat. Depending on the client, you may also work with Slack, Confluence, Notion, or similar tools.

Need help?

Want more details? See full FAQ

If something doesn’t work or you have questions regarding your application process, drop us a line.

    Scroll to Top