Skip to content

Clear Capital | CubiCasa | restb.ai

Senior Application Security Engineer

Compensation
$111K–$144.4K / yr
From job posting
Location
Remote - US, US
Arrangement
Remote
Employment type
Full-time
Level
Senior
Posted
6 July 2026 (about 2 months ago)

Checked 15 days agoApplications go to the employer, never to RoleSprint

About this role

The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused. This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege.

What You Will Work On • Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices.

• Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes.

• Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics.

• Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain.

• Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning.

• Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks.

• Fully define and follow a security review process to ensure an automated and repeatable process is managed.

• Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing.

• Train developers and junior application security engineers on weaknesses to avoid.

• Perform other duties as assigned.

Who We Are Looking For • 4+ years of related experience required.

• Bachelor’s Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience.

• Highly technical and analytical, with a background in software development, and scripting (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP).

• Expertise in application security testing, including hands-on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools.

• Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments.

• Relevant certifications such as C|ASE, CSSLP, GWAPT, OSCP, or equivalent.

• Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2.

What You Can Expect • Compensation: The base salary for this position ranges from $111,000 to $144,400 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit-sharing bonus program, communication stipends, and referral bonuses.

• Inclusive benefits package offering:

• Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&D insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources.

• Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team.

• Career and skill development resources to help advance your career and personal growth.

• A mission-driven environment where your work makes a measurable impact on the real estate industry.

What We Value • Wherever it Leads, Whatever it Takes® - No matter how remote, complex, or unexpected. Our commitment never wavers.

• Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit.

• Lift others up - We lead with empathy and strive to improve the lives of those around us.

• Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact.

• Raise the bar - We don’t settle for industry standards, we redefine them.

Work location

  • Reno, NV, US

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Clearcapital, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 6 July 2026, last checked 15 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free