Application Security Engineer Bright Vision Technologies
Overview
Lead security integration across software development lifecycles for a remote full-time role at Bright Vision Technologies. Own security practices while collaborating with engineering teams to build resilient applications. Drive measurable risk reduction through proactive threat mitigation and secure coding standards.
What You'll Do14
- 1Conduct threat modeling and security architecture reviews for new and existing applications and services
- 2Perform manual code reviews secure design consultations pair with engineering teams on hardening critical components
- 3Operate and tune SAST DAST IAST SCA and secret-scanning tools across CI/CD pipelines
- 4Drive vulnerability management workflows including triage prioritization owner assignment and SLA tracking
- 5Build paved-road libraries and frameworks that make secure patterns the default for engineering teams
- 6Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses
- 7Implement and operate runtime protections including WAF RASP bot protection and abuse-detection mechanisms
- 8Design and enforce secure authentication authorization session management and cryptographic patterns
- 9Partner with infrastructure and platform teams to harden container Kubernetes and cloud environments
- 10Develop and deliver application security training lunch-and-learns and onboarding content for engineering staff
- 11Respond to security incidents involving application vulnerabilities or active exploitation
- 12Track and apply emerging threats and CVEs that may affect the application portfolio
- 13Maintain comprehensive current technical documentation including architecture diagrams design decisions configuration references runbooks and operational procedures
- 14Stay current with application security research and emerging defensive tooling
Requirements13
- 15+ years building ETL pipelines with Spark and Airflow
- 210+ years application security or security engineering experience
- 3Strong understanding of OWASP Top 10 common vulnerability classes and modern exploit patterns
- 4Hands-on experience performing code review across at least two major languages
- 5Deep familiarity with SAST DAST SCA and CI/CD-integrated security tooling
- 6Strong understanding of authentication authorization and cryptographic primitives
- 7Experience with cloud security and modern infrastructure controls
- 8Proficiency in at least one programming language for tooling and automation
- 9Experience working closely with engineering teams in an Agile environment
- 10Industry certifications such as OSCP OSCE GWAPT or CISSP
- 11Offensive security tooling experience red-team operations bug bounty participation public CVEs or open-source security contributions
- 12Familiarity with AI/LLM application security considerations
- 13Exposure to regulated industries with strict compliance requirements
Salary Insight
$100 - $160k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Motion Recruitment Partners, LLC
VerifiedPrincipal Application Security Engineer
You will own application security for a major financial services firm with over 150 years of market presence, hardening Java and .NET applications across a global portfolio. You will lead security reviews, threat modeling, and code analysis while partnering with DevOps to embed security into CI/CD pipelines. This hybrid role in Charlotte, NC offers direct impact on high-velocity releases and access to cutting-edge cloud infrastructure.

DMS Vision Inc.
VerifiedApplication Security Engineer DMS Vision Inc.
Lead ownership of application security initiatives scaling across hybrid environments. Drive security posture through innovative solutions. Shape future direction of security practices. Differentiate by delivering cutting edge protection strategies.
David Joseph & Company
VerifiedSenior Staff Security Engineer
Lead the end-to-end security posture of an AI coworker product for enterprise IT teams. Own application cloud network and agent security while defining a novel category. Drive secure design reviews build security primitives and manage incident response. This is a full-time role in San Francisco with equity compensation.

Prudent Technologies and Consulting
VerifiedCybersecurity Engineer, Vulnerability Management & SAST
You will own the vulnerability identification and triage process across the product portfolio at a scale of 10,000+ assets. Your stack includes SAST, DAST, and SCA tools like AppScan, Fortify, and Checkmarx, alongside Burp and Snyk. Working with the security engineering team, you will reduce false positives and prioritize real risk. This role stands out by focusing on the intelligence layer between scanning and remediation, using ASPM tools like Vulcan and Brinqa.
greenlight
VerifiedStaff Product Security Engineer, AI & Cloud Security
You will own end-to-end security for consumer products, a digital platform, and an emerging hardware line at Greenlight, a fintech serving 6.5 million family members. You will drive threat modeling, lead penetration testing, manage PSIRT operations, and champion secure AI adoption across the company. Collaborating with architects, product managers, and engineering, you will define security guardrails for AI-powered products and development workflows. This role offers a rare blend of hands-on technical work and strategic influence in a highly regulated financial environment.
Bright Vision Technologies
VerifiedStaff Software Engineer - Remote Bright Vision Technologies
Own scalable cloud AI data solutions at scale. Lead cross-functional teams to deliver high-impact products. Drive innovation in Kubernetes AWS React environments. Shape technology landscape for remote teams.