Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Application Security Engineer II image - Rise Careers
Job details

Application Security Engineer II

Who Are We?

Taking care of our customers, our communities and each other. That’s the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 160 years. Join us to discover a culture that is rooted in innovation and thrives on collaboration. Imagine loving what you do and where you do it.

Job Category

Technology

Compensation Overview

The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards.

Salary Range

$111,600.00 - $184,200.00

Target Openings

1

What Is the Opportunity?

Travelers is seeking an Application Security Engineer II to join our organization as we grow and transform our Technology landscape. Individual will complete advanced end to end security engineering tasks for specific system including security research, application security testing, interpretation of vulnerability scan results, threat modeling code reviews, and will provide defensive coding techniques consulting. Works with circle leads in a Value Stream on security and performs Application Security testing for Value Stream. Provides guidance on testing to Application Security Engineer I. Performs application architecture security reviews. Partners with Cybersecurity and Enterprise Security Engineering on testing and remediation of vulnerabilities and implementation of Cybersecurity patterns.

What Will You Do?

  • Contribute to the creation of an application penetration testing framework.
  • Conduct thorough penetration testing on web, mobile, and cloud-based applications to identify security vulnerabilities.
  • Develop and execute test plans, scripts, and methodologies for application security assessments.
  • Document and report findings, including detailed descriptions of vulnerabilities, potential impact, and recommended remediation steps.
  • Perform security research, application security testing, interpretation of vulnerability scan results, threat modeling code reviews and advise on defensive coding techniques with a high degree of accuracy and speed, operating as an individual contributor to team goals.
  • Work independently to tackle well-scoped and loosely scoped problems.
  • Seek opportunities to expand technical knowledge and capabilities.
  • Provide technical guidance and mentorship to less experienced employees.
  • Perform other duties as assigned.

What Will Our Ideal Candidate Have?

  • Bachelor's degree plus four years of application security experience and/or certifications such as OSCP, OSWA, or GWAPT.
  • Proficiency using penetration testing tools such as Burp Suite
  • Strong knowledge of common application vulnerabilities (e.g., OWASP Top Ten)
  • Experience reviewing reported application vulnerabilities from outside testers and researchers for impact and likelihood to Travelers.
  • Experience with DAST tooling and supporting a scalable and integrated strategy to test applications.
  • Familiarity with threat modeling methodologies.
  • Delivery - Intermediate delivery skills including the ability to estimate accurate timelines for tasks and deliver work at a steady, predictable pace to achieve commitments, contribute to the software design strategy and methodologies used to best meet the system requirements, consider and build for many different use cases, avoid over engineering, and ensure automation, deliver complete solutions but release them in small batches, and identify important tradeoffs and negotiate them.
  • Domain Expertise - Demonstrated track record of domain expertise including understanding technical concepts necessary to do the job effectively and aware of industry trends, demonstrate willingness, cooperation, and concern for business issues and priorities, and possess in depth knowledge of immediate systems worked on and some knowledge of adjacent systems.
  • Problem Solving - Strong problem solver who ensures solutions are built for the long term, is able to resolve new issues, recognizes mistakes using them as learning and teaching opportunities and consistently breaks down large problems into smaller, more manageable ones.
  • Communication - Strong communicator who possesses the ability to articulate information clearly and concisely with the business, document work in a clear, easy to follow manner, collaborate well with team members as both a mentor and mentee, take in vague requirements and ask the right questions to ensure clarification, offer feedback appropriately and effectively, seek out and receives constructive criticism well, listen when others are speaking and make space for colleagues to share their thoughts.
  • Leadership - Intermediate leadership skills with the ability to help create a safe environment for others to learn and grow as engineers and a proven track record of self-motivation in identifying opportunities and tracking team efforts.

What is a Must Have?

  • Three years of system security experience.

What Is in It for You?

  • Health Insurance: Employees and their eligible family members – including spouses, domestic partners, and children – are eligible for coverage from the first day of employment.
  • Retirement: Travelers matches your 401(k) contributions dollar-for-dollar up to your first 5% of eligible pay, subject to an annual maximum. If you have student loan debt, you can enroll in the Paying it Forward Savings Program. When you make a payment toward your student loan, Travelers will make an annual contribution into your 401(k) account. You are also eligible for a Pension Plan that is 100% funded by Travelers.
  • Paid Time Off: Start your career at Travelers with a minimum of 20 days Paid Time Off annually, plus nine paid company Holidays.
  • Wellness Program: The Travelers wellness program is comprised of tools, discounts and resources that empower you to achieve your wellness goals and caregiving needs. In addition, our mental health program provides access to free professional counseling services, health coaching and other resources to support your daily life needs.
  • Volunteer Encouragement: We have a deep commitment to the communities we serve and encourage our employees to get involved. Travelers has a Matching Gift and Volunteer Rewards program that enables you to give back to the charity of your choice.

Employment Practices

Travelers is an equal opportunity employer. We value the unique abilities and talents each individual brings to our organization and recognize that we benefit in numerous ways from our differences. 

In accordance with local law, candidates seeking employment in Colorado are not required to disclose dates of attendance at or graduation from educational institutions.

If you are a candidate and have specific questions regarding the physical requirements of this role, please send us an email so we may assist you.

Travelers reserves the right to fill this position at a level above or below the level included in this posting.

To learn more about our comprehensive benefit programs please visit http://careers.travelers.com/life-at-travelers/benefits/.

Average salary estimate

$147900 / YEARLY (est.)
min
max
$111600K
$184200K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Application Security Engineer II, Travelers

Are you ready to take your skills to the next level? Join Travelers as an Application Security Engineer II in Atlanta, Georgia! We're committed to taking care of our community and each other, and we need someone like you to help us maintain our reputation as a top property casualty insurer. In this role, you'll be diving deep into advanced end-to-end security engineering tasks, including application security testing and vulnerability assessment. Imagine working collaboratively with a talented team to develop and execute comprehensive testing plans while leveraging the latest tools like Burp Suite. You'll be instrumental in creating an application penetration testing framework and advising on defensive coding techniques that can really bolster our security posture. Plus, you'll have the opportunity to guide less experienced engineers, fostering a culture of growth and learning. We’re looking for someone with a solid background in application security, a passion for innovative technology, and the desire to tackle challenges head-on. With a competitive salary ranging from $111,600 to $184,200, along with outstanding benefits, including health insurance from day one, retirement matching, and generous paid time off, you’ll be joining a company that truly values its employees. If you're eager to expand your technical knowledge, contribute to meaningful projects, and work in an environment that inspires and invests in your growth, the Application Security Engineer II position at Travelers is the perfect fit for you!

Frequently Asked Questions (FAQs) for Application Security Engineer II Role at Travelers
What are the key responsibilities of the Application Security Engineer II at Travelers?

As an Application Security Engineer II at Travelers, you'll conduct comprehensive penetration testing on various applications, including web, mobile, and cloud-based systems. You will also develop test plans, document findings, provide recommendations for remediation, and participate in application architecture security reviews. Your role will be crucial in strengthening our security measures and ensuring that vulnerabilities are addressed effectively.

Join Rise to see the full answer
What qualifications are necessary for the Application Security Engineer II position at Travelers?

To qualify for the Application Security Engineer II role at Travelers, you need a Bachelor's degree and at least four years of application security experience. Industry certifications such as OSCP, OSWA, or GWAPT are highly valued. Familiarity with penetration testing tools, knowledge of common application vulnerabilities, and experience with threat modeling will enhance your candidacy.

Join Rise to see the full answer
Which tools should I be proficient in for the Application Security Engineer II role at Travelers?

For the Application Security Engineer II position at Travelers, proficiency in tools like Burp Suite and DAST tooling is essential. Understanding how to leverage these tools effectively for application security testing and vulnerability assessment is key to succeeding in this role.

Join Rise to see the full answer
What kind of work culture can I expect as an Application Security Engineer II at Travelers?

At Travelers, you can expect a culture rooted in innovation and collaboration. The company values professional growth, encouraging employees to expand their skills and knowledge. You'll work alongside dedicated professionals and have the opportunity to mentor others, contributing to a supportive and enriching work environment.

Join Rise to see the full answer
What benefits does Travelers offer for the Application Security Engineer II position?

Travelers offers an excellent benefits package for the Application Security Engineer II role, including health insurance that begins on your first day, a robust 401(k) match, and a pension plan. Additionally, you'll enjoy at least 20 days of Paid Time Off annually, various wellness program resources, and opportunities to engage in community service.

Join Rise to see the full answer
Common Interview Questions for Application Security Engineer II
Can you explain your experience with application penetration testing?

In answering this question, highlight specific projects where you conducted penetration testing. Discuss the methods and tools you used, the kinds of vulnerabilities you found, and how you communicated the results to stakeholders to ensure they understood the importance of remediation.

Join Rise to see the full answer
What application security tools are you most comfortable with?

Provide a list of tools you've used, like Burp Suite, along with brief examples of how you've utilized these tools to identify vulnerabilities and improve security protocols. Highlight any unique techniques or custom scripts you've developed.

Join Rise to see the full answer
Describe a challenging security vulnerability you encountered and how you resolved it.

Choose a real case where you identified a significant vulnerability. Explain the context, the steps you took to remediate it, how you worked with your team or other departments, and the impact of your solution on the overall security posture.

Join Rise to see the full answer
How do you stay up-to-date with the latest application security trends?

Mention specific resources you follow, such as security blogs, forums, or community conferences. Highlight any certifications you're pursuing or professional networks you engage with to stay current on trends in application security.

Join Rise to see the full answer
What methodologies do you follow for threat modeling?

Explain your approach to threat modeling, including specific methodologies such as STRIDE or DREAD. Discuss how you identify threats within an application's architecture and how this shapes your security testing.

Join Rise to see the full answer
How would you prioritize vulnerabilities found in an application?

Discuss your approach to assessing vulnerabilities based on factors like severity, exploitability, and impact on the organization. Explain how you collaborate with development teams to ensure timely remediation.

Join Rise to see the full answer
Can you detail your experience in conducting security reviews of application architecture?

Share your process for architecture reviews, including key areas you focus on and examples of recommendations you've made. Emphasize how your feedback has positively influenced the security design of applications.

Join Rise to see the full answer
What experience do you have with defensive coding techniques?

Discuss specific defensive coding principles you advocate for, such as input validation and proper error handling. Provide examples of how you’ve recommended these practices to development teams to mitigate vulnerabilities.

Join Rise to see the full answer
How would you mentor a less experienced member on your team?

Talk about your mentorship style, focusing on collaboration and hands-on learning. Provide examples of how you’ve previously guided someone through complex problems or encouraged their growth in security practices.

Join Rise to see the full answer
What do you consider the biggest challenge in application security today?

Reflect on current trends, such as the rise of cloud applications or increasing sophistication of attacks. Discuss how these challenges impact your work and strategies you employ to address them effectively.

Join Rise to see the full answer
Similar Jobs
Posted 9 days ago
Photo of the Rise User

Adtalem Global Education is looking for a Mid-Level Business Systems Analyst to enhance registrar systems through technical and process improvements.

Photo of the Rise User
Posted 7 days ago
United States Air Force Hybrid US, Mississippi, Mississippi
Posted 10 days ago
Photo of the Rise User
PosiGen Remote Remote - UT, LA, PA, TX, NY
Posted 12 days ago
Photo of the Rise User
Posted 11 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 2, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
50 people applied to SOC Analyst I at Epsilon
Photo of the Rise User
65 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
Someone from OH, Cincinnati just viewed Newborn/Pediatric Nurse Care Manager at Included Health
T
Someone from OH, Cleveland just viewed Commvault Backup L1/L2 at Talent Worx
Photo of the Rise User
Someone from OH, Cleveland just viewed Special Education PD Designer at GoalBook
Photo of the Rise User
Someone from OH, Fairfield just viewed Materials Associate at Anduril Industries
Photo of the Rise User
Someone from OH, Xenia just viewed Permitting Associate at Flock Safety
Photo of the Rise User
Someone from OH, Lakewood just viewed Analyst-Treasury at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Director, Digital Marketing at UserTesting
Photo of the Rise User
Someone from OH, Cleveland just viewed Product Manager, AI & STEM Specialist at Macmillan Learning
Photo of the Rise User
Someone from OH, Ashland just viewed Prior Authorization Specialist at LifeStance Health
Photo of the Rise User
Someone from OH, Ashland just viewed Prior Authorization Specialist at LifeStance Health
F
Someone from OH, Grove City just viewed Director of Internal Communications at Filevine
Photo of the Rise User
Someone from OH, Amelia just viewed Copy Editor (contract) at Morning Brew Inc.
Photo of the Rise User
Someone from OH, Versailles just viewed Parts Manager at Crown Equipment
Photo of the Rise User
Someone from OH, Cincinnati just viewed Bookkeeper - Franchise Location at H&R Block
Photo of the Rise User
Someone from OH, Dublin just viewed Cashier - Sawmill Road Market District at Giant Eagle