Senior Application Security Engineer – Vulnerability Operations
Job in
Jersey City, Hudson County, New Jersey, 07390, USA
Listed on 2026-08-06
Listing for:
Veriipro
Full Time
position Listed on 2026-08-06
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Roles and Responsibilities
1. Strategic App Sec Leadership
- Drive enterprise-wide implementation of Application Security controls across CI/CD pipelines.
- Partner with App Sec Champions to embed secure development practices and improve security adoption.
- Define and manage tiered security control strategy (Tier 1–3) with quarterly migration goals.
- Enable decentralized security ownership across engineering teams.
2. Vulnerability & Threat Management
- Lead triage, analysis, and remediation of complex and high-risk vulnerabilities.
- Serve as SME for modern threat classes including cloud-native risks, APIs, supply chain, containers, serverless, and emerging OWASP categories.
- Perform threat modeling and security design reviews for critical applications.
- Provide escalation support for advanced App Sec issues.
3. CI/CD Security & Automation
- Architect and enhance CI/CD security integrations (SAST, DAST, SCA, secrets, IaC scanning).
- Implement policy-as-code and automated security gating (merge/build prevention).
- Develop reusable security automation frameworks and pipeline modules.
4. Governance & Reporting
- Build dashboards, KPIs, and risk scorecards using tools like Power BI or Grafana.
- Lead vulnerability governance forums and executive reporting on security posture and trends.
- Manage risk registers, remediation tracking, and quarterly program alignment.
5. Enablement & Continuous Improvement
- Mentor App Sec engineers and support security champion enablement programs.
- Evaluate scanning outputs, reduce false positives, and improve detection quality.
- Continuously enhance App Sec processes, tools, and onboarding workflows.
- Stay current with emerging threats and security trends.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or related field.
- 7+ years of experience in Application Security, Vulnerability Management, or Secure SDLC.
- Strong expertise in secure design, threat modeling, exploit analysis, and remediation strategies.
- Hands-on experience with CI/CD security tooling (SAST, DAST, SCA, secrets, IaC scanning).
- Proven experience working with engineering teams to drive App Sec adoption and governance.
- Ability to analyze vulnerability trends and emerging/zero-day threats.
- Cloud security experience across AWS, Azure, or GCP.
- Certifications such as CISSP, CSSLP, OSCP, OSWE, GWAPT, or equivalent.
- Experience with policy enforcement tools (OPA/Gatekeeper).
- Knowledge of software supply chain security (SLSA, SBOM).
- Experience building App Sec Champion or federated security models.
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×