Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Application Security Engineer image - Rise Careers
Job details

Application Security Engineer

Andesite is on a mission to build innovative security products that enhance human and AI collaboration in cybersecurity. They are looking for an Application Security Engineer to safeguard their software applications and cloud environments.

Skills

  • Proficient in a programming language
  • Strong knowledge of secure coding practices
  • Experience with SAST, DAST, and SCA tools
  • In-depth experience with cloud security controls
  • Familiarity with compliance standards and frameworks

Responsibilities

  • Proactively identify and mitigate security weaknesses in software applications.
  • Conduct application threat modeling and secure design reviews.
  • Manage SAST, DAST, and SCA tooling for scalable application security testing.
  • Perform manual and automated code reviews to ensure secure coding standards.
  • Develop custom scripts to automate security tasks and support DevSecOps initiatives.
  • Monitor computer systems and networks for vulnerabilities and security threats.
  • Provide training and guidance to developers to promote secure development practices.

Education

  • Bachelor's degree in Computer Science, Cybersecurity, or related field
  • Equivalent practical experience may be considered

Benefits

  • Competitive salary, bonus, and equity package
  • 100% employer-paid health insurance for you and your family
  • Unlimited PTO with manager’s approval
  • Flexible work environment
  • 14 weeks of fully-paid parental leave
To read the complete job description, please click on the ‘Apply’ button

Average salary estimate

$112500 / YEARLY (est.)
min
max
$100000K
$125000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Application Security Engineer, Andesite

Join our incredible team at Andesite as an Application Security Engineer, where you will play a pivotal role in shaping the future of cybersecurity! With a mission to build innovative security products that elevate human and AI collaboration against cyber threats, you’ll find yourself surrounded by a diverse group of passionate technologists and seasoned experts from prominent organizations in cybersecurity and tech. In this fully remote role, you will ensure the security of our software applications and cloud environments by identifying and mitigating vulnerabilities throughout the development lifecycle. Your responsibilities will involve application threat modeling, code reviews, and managing SAST, DAST, and SCA tools, ensuring that security best practices are top of mind. You will have the chance to work closely with various teams in a fast-paced environment, educating and empowering them to adopt secure development practices. Additionally, you will be responsible for delivering real-time threat response and facilitating vulnerability assessments to maintain the integrity, confidentiality, and availability of our systems. If you have over 4 years of experience in application security or secure software development and a passion for fostering a strong security culture, you will thrive in this role at Andesite. Let’s reshape the world of cybersecurity together!

Frequently Asked Questions (FAQs) for Application Security Engineer Role at Andesite
What are the responsibilities of an Application Security Engineer at Andesite?

As an Application Security Engineer at Andesite, your primary responsibilities include securing software applications and cloud environments by identifying and mitigating vulnerabilities throughout the development lifecycle. You'll conduct application threat modeling, perform code reviews, and manage security tools such as SAST, DAST, and SCA. Additionally, you'll educate engineering teams on secure practices and work closely with various departments to ensure compliance with relevant regulations.

Join Rise to see the full answer
What qualifications are required for the Application Security Engineer position at Andesite?

To qualify for the Application Security Engineer position at Andesite, candidates should have over 4 years of experience in application security or secure software development, along with hands-on experience securing cloud-native applications. A strong understanding of secure design principles, threat modeling, and software risk assessment is also essential, along with proficiency in at least one programming language and familiarity with security standards like OWASP Top 10.

Join Rise to see the full answer
How does Andesite support the professional development of its Application Security Engineers?

Andesite is committed to the professional development of its Application Security Engineers by encouraging participation in continuous learning opportunities. You can expect to stay updated with industry developments through training, conferences, and hands-on experiences that enhance your knowledge and skills, helping you grow in your career and stay abreast of best practices in the cybersecurity domain.

Join Rise to see the full answer
What can a candidate expect during the interview process for the Application Security Engineer role at Andesite?

During the interview process for the Application Security Engineer role at Andesite, candidates can anticipate a series of structured interviews focusing on technical skills and cultural fit. The process may include technical assessments, problem-solving scenarios related to application security, and discussions highlighting past experiences. Expect a friendly environment where the team values your input and strives to understand how you can contribute to the mission and objectives of Andesite.

Join Rise to see the full answer
What benefits are offered to Application Security Engineers at Andesite?

Andesite offers a comprehensive benefits package to its Application Security Engineers, including a competitive salary alongside bonus and equity options. Employees enjoy employer-paid health insurance covering medical, dental, and vision for themselves and their families, unlimited PTO, a flexible remote work environment, and 14 weeks of fully-paid parental leave, all fostering a healthy work-life balance.

Join Rise to see the full answer
Common Interview Questions for Application Security Engineer
Can you describe your experience with application threat modeling?

In answering this question, consider elaborating on specific projects where you successfully identified potential threats and vulnerabilities during the design phase. Explain how you utilized tools or frameworks for threat modeling and the impact this had on enhancing application security. Being specific about your methodologies and outcomes will demonstrate your expertise effectively.

Join Rise to see the full answer
What security tools have you used to manage application security?

Speak about the specific SAST, DAST, and SCA tools you are familiar with, including examples of how you configured or tuned these tools in previous roles. Highlight your achievements while using these tools, such as improved detection rates or faster remediation times, to illustrate your hands-on experience and technical proficiency.

Join Rise to see the full answer
How do you ensure secure coding practices are followed by developers?

Outline your approach to promoting secure coding practices, including conducting training sessions, providing detailed documentation, and performing code reviews. Share examples of how you've successfully guided teams towards adopting these practices, along with any metrics that demonstrate the effectiveness of these efforts.

Join Rise to see the full answer
What is your experience with cloud-native security?

Discuss the cloud platforms (like AWS, Azure, or GCP) you have worked with, emphasizing your hands-on experience in implementing security controls. Detail how you have managed identity and access controls and enforced secure configurations across cloud services, reinforcing your understanding of cloud security concepts and practices.

Join Rise to see the full answer
Can you provide an example of a challenging security vulnerability you identified and remediated?

When responding to this question, narrate a specific instance where you discovered a vulnerability, detailing your investigative process. Explain how you communicated the findings to stakeholders and the strategies you utilized to remediate the issue, emphasizing your analytical skills and solution-oriented mindset.

Join Rise to see the full answer
How do you prioritize vulnerabilities when managing an application security program?

Highlight your method for assessing the severity and potential impact of vulnerabilities by referencing frameworks like CVSS or OWASP. Demonstrate your ability to balance urgency against business needs while considering factors like exploitability, potential damage, and compliance requirements.

Join Rise to see the full answer
What steps do you take to educate developers about application security?

Describe your strategies for instilling a security-first mindset among developers, such as rolling out training programs, providing security-focused onboarding, and facilitating workshops. Share how you measure engagement and knowledge retention over time to ensure lasting impacts on security culture within the organization.

Join Rise to see the full answer
What role does automation play in your application security strategy?

Explain the automated processes and tools you have employed to enhance security throughout the development lifecycle. Discuss specific examples where automation helped streamline security tasks, reduce human error, or increase efficiency in managing security assessments.

Join Rise to see the full answer
How familiar are you with the OWASP Top 10, and how do you apply it to your work?

Demonstrate your depth of knowledge regarding the OWASP Top 10 vulnerabilities and how you incorporate these guidelines into your application security practices. Provide examples of how recognizing these risks have influenced your threat modeling or code review processes in past projects.

Join Rise to see the full answer
What would you consider the most critical aspect of an Application Security Engineer's role?

Discuss your views on the importance of collaboration and communication within the role of an Application Security Engineer. Emphasize how a strong partnership with development and operations teams can lead to more effective security practices and lower risks in deployed applications.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 12 days ago

As a Senior Cloud Architect at Agile Defense, you will play a critical role in providing cloud solutions for DOD customers.

Photo of the Rise User
Johnson Controls Hybrid US, Saginaw County, MI; Michigan, Saginaw, MI
Posted 6 days ago

Join our team as a Journeymen Chiller Mechanic and leverage your expertise in chillers to provide top-notch service to our clients.

Photo of the Rise User

Join Reliable Robotics as an A&P Mechanic and help shape the future of aviation safety through innovative technology.

Join GE Aerospace as an Additive Materials Application Engineer to advance cutting-edge additive manufacturing technologies.

Amazon Stores Hybrid US, Minnehaha County, SD; South Dakota, Sioux Falls, SD
Posted 10 days ago

Join Amazon as a Mechatronics & Robotics Technician and support our Operations Maintenance team in optimizing our automation systems.

Photo of the Rise User
Auria Hybrid No location specified
Posted 13 days ago

Auria is in search of an experienced Systems Architect to support critical defense initiatives across a range of complex systems.

Photo of the Rise User
Posted 6 days ago

Join Sandisk as a Mechanical Design Engineer and contribute to cutting-edge SSD development in a collaborative and innovative environment.

Photo of the Rise User
Techo-Bloc Hybrid Boyertown, PA, USA
Posted 4 days ago

Techo-Bloc is on the lookout for an experienced electro-mechanic to enhance their team, where innovation meets excellence in industrial maintenance.

MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
SALARY RANGE
$100,000/yr - $125,000/yr
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 20, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Success Manager, US SLED at Dataminr
Photo of the Rise User
Someone from OH, Greenville just viewed Systems Engineer (Linux & Shell or Python scripting) at Visa
Photo of the Rise User
Someone from OH, Greenville just viewed Help Desk Technician - Youngstown at R.I.T.A.
Photo of the Rise User
Someone from OH, Mount Orab just viewed Backend Developer at G2i Inc.
Photo of the Rise User
7 people applied to Technology Intern at SABIC
Photo of the Rise User
Someone from OH, Cincinnati just viewed Product Marketing Manager at Cast & Crew
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Manager at Cast & Crew
o
Someone from OH, Cincinnati just viewed Administrative Assistant at osu
A
Someone from OH, Cincinnati just viewed Data Entry Clerk at Alphabe Insight Inc
Photo of the Rise User
Someone from OH, Cincinnati just viewed Machine Learning Engineer at Allstate
Photo of the Rise User
Someone from OH, Twinsburg just viewed Data Analyst/Power BI Developer at Datadog
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed Small Fleet Underwriter at HDVI
Photo of the Rise User
18 people applied to HVAC Apprentice at DuPont
Photo of the Rise User
Someone from OH, Dublin just viewed Product Designer, Entry Level at Govini