×
Register Here to Apply for Jobs or Post Jobs. X

Staff Engineer, Application Security

Job in Buffalo, Erie County, New York, 14266, USA
Listing for: BetterCloud
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 110000 - 170000 USD Yearly USD 110000.00 170000.00 YEAR
Job Description & How to Apply Below

Who we are looking for:

ACV is looking for an Application Security Engineer to join our security team and lead the development and maturation of our Application Security (App Sec) program. This is a high-impact role for someone with a proven track record of embedding security into modern software development life cycles in SaaS environments. You’ll work across engineering, product, and Dev Ops to ensure secure design, implementation, and deployment of our applications and services.

This role is ideal for a developer turned security leader who has built or significantly matured an App Sec program from the ground up and is looking to drive impact at scale within a fast-paced, cloud-native, Dev Sec Ops  environment.

What you will do:

Actively and consistently support all efforts to simplify and enhance the customer experience. Design, implement, and scale ACV's Application Security Program, aligning with Secure SDLC best practices and taking a Shift Left by default approach. Serve as the subject matter expert for secure application architecture, code analysis, and application threat modeling. Partner with engineering and security teams to integrate security tools and controls into CI/CD pipelines (e.g., SAST, DAST, SCA, secrets management).

Conduct and oversee escalated code reviews, security assessments, and pen testing of internal and external applications. Lead threat modeling workshops, security training, and awareness initiatives for developers and architects. Develop policies, standards, and automation to support a secure-by-default engineering culture. Drive remediation efforts by working hands‑on with developers to fix critical vulnerabilities. Collaborate with compliance and risk teams to meet security audit and regulatory requirements (SOC2, ISO
27001, etc.). Stay current on emerging threats, vulnerabilities, and secure development trends. Perform additional duties as assigned.

What you will need:

Ability to read, write, speak and understand English. Attention to detail and strong organizational skills Critical thinking and problem‑solving abilities Effective written and verbal English communication skills Demonstrated experience building or leading a successful Application Security Program at a technology‑driven organization Deep technical knowledge of common web and mobile vulnerabilities (e.g., OWASP Top
10), microservices security, and cloud‑native architectures (preferably AWS) Strong proficiency with security testing tools (e.g., Burp Suite, Git Hub Advanced Security, Snyk, Checkmarx, etc.) Familiarity with modern development stacks and languages (e.g., Node.js, Python, Go, React). Hands‑on experience securing CI/CD environments and working with Dev Ops teams Experience conducting code and security reviews of architecture designs, APIs, and infrastructure‑as‑code Strong communication skills with the ability to influence engineers and leadership alike as well as understand that different audiences require different messages Industry certifications a plus (e.g., OSWE, GWAPT, CSSLP, CISSP)

#LI-AM3

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary