Senior Security Engineer, Application
Job Description
Own application security across physical datacenter and cloud environments, driving vulnerability management, threat modeling, and security tooling automation.
Responsibilities
- Manage and support application vulnerability scanning technologies, AST platforms, and cloud security tooling
- Partner with business stakeholders to design secure applications and test for security weaknesses
- Collaborate on remediation of identified issues and respond to information security concerns
- Coordinate orchestration, automation, and day-to-day management of security technologies and platforms
- Support life cycle management activities including threat assessment, threat modeling, and risk avoidance
- Produce actionable reporting that shows direct impact to the organization’s security posture
- Define and implement security effectiveness measures using Key Risk Indicators (KRIs) and security scorecards
- Serve as a subject-matter-expert for Application Security and a key contact for critical issues and security risk assessments
- Triage and support CI/CD security issues with internal partners and stakeholders
- Evaluate business and technical needs to select tools, processes, and technologies that improve security across environments
- Continuously improve compliance processes
Requirements
- 5+ years of experience
- Computer Science or a similar degree
- Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling
- Formal experience with threat modeling
- Ability to assess and prioritize risk with an attacker mindset to inform threat models
- Cloud experience: AWS, Azure, or GCP
- Understanding of Infrastructure as Code (IaaC) and Policy as Code (PaC) concepts
- Experience implementing secure Software Development Lifecycle programs
- Familiarity with technical security controls, guidelines, and frameworks including SOC2, ISO 27001, and NIST 800-53
- Experience with project delivery through direct and indirect leadership
- Ability to automate repetitive tasks and build code solutions
- Scripting or programming experience: Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash
- Penetration testing and web application assessment experience
- Experience assessing software compliance with HIPAA, PHI, PII, and PCI regulations
Technologies
- AWS, Azure, GCP
- Infrastructure as Code (IaaC), Policy as Code (PaC)
- Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript
- PowerShell, Bash
- SOC2, ISO 27001, NIST 800-53
- HIPAA, PCI
- CI/CD
Compensation
- USD 96,700 - 145,000 per year (national range)
- Eligible for a bonus incentive plan
Benefits
- Competitive Compensation & Total Rewards Incentives
- Comprehensive Healthcare Coverage
- Multiple 401(k) Savings Plan Options
- Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded)
- Generous Paid Time Off, including 12 paid holidays, Volunteer Time Off, and Paid Family Leave
- Disability, Life, and Long Term Care Insurance
- Tuition Reimbursement, Student Loan Repayment, and Training & Certification Support
- Wellness support including gym membership reimbursement and Employee Assistance Program resources
- Caregiver and Mental Health Support Services
Location & Schedule
- Richmond, VA (Hybrid)
- Hybrid schedule requires Remote and In-Office days
- In-office days: Tuesday, Wednesday, and Thursday
- Working hours target: 9am-5pm EST
Additional Location Information
- In-office applicants: Richmond or Lynchburg, Virginia
Disclaimer
- Role aligned to a national market-based pay range; actual compensation varies by geography, experience, skills, and other job-related factors
- Bonus incentive plan eligibility depends on individual and company performance and is not guaranteed