Application Security Engineer
Location: Remote
Compensation: To Be Discussed
Reviewed: Tue, Aug 11, 2026
This job expires in: 26 days
Job Summary
To enhance application security, the full-time remote Application Security Engineer will triage security findings, conduct code reviews, and perform penetration testing on web applications and APIs.
Key responsibilities
- Triage, validate, and prioritize security findings from various scanning tools, assessing risks and tracking issues to remediation
- Conduct manual and tool-assisted code reviews to identify security vulnerabilities and logic flaws before production deployment
- Perform hands-on penetration testing of web applications, microservices, and APIs, focusing on core application security risks
Required qualifications
- 2-4 years of experience in Application Security, Product Security, or Penetration Testing
- Hands-on experience with tools such as Semgrep, Gitleaks, Trivy, and Burp Suite
- Deep understanding of OWASP Top 10 vulnerabilities and OWASP API Security Top 10
- Knowledge of identity protocols and access control mechanics, including OAuth 2.0 and JWT
- Intermediate level of English (spoken and written)
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 47,198 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee