×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Application Security Engineer

Job in Reston, Fairfax County, Virginia, 20190, USA
Listing for: VeriSign
Full Time position
Listed on 2026-10-09
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Verisign helps enable the security, stability, and resiliency of the internet. We are a trusted provider of internet infrastructure services for the networked world and deliver unmatched performance in domain name system (DNS) services. We are a mission focused, values driven company where each individual can contribute to building a stronger, more secure internet.  We offer a dynamic and flexible work environment with competitive benefits and the ability to grow your career.

The Senior Application Security Engineer will play a lead role in securing all software built and/or used by Verisign. The engineer will work with application development teams as well as 3rd party organizations to ensure that security, privacy, and compliance are built into applications from design through production. The engineer should be a technical leader helping determine the future of the application security program and actively participating in a broad spectrum of activities by leading assessments, following security research and best practices, and helping set the standards of the program.

The individual should possess strong interpersonal skills, be highly motivated, results oriented, have excellent communication and presentation skills, and be a strong team player.

Responsibilities:

Serve as the application security subject matter expert for development teams during requirement, design, and architecture phases, including application threat modeling for new and significantly changed applications

Perform and lead deep dive manual and automated application vulnerability assessments, documenting findings, and provide clear remediation guidance to the responsible engineering teams

Own the application security vulnerability management lifecycle across the security toolchain, including software composition analysis, static and dynamic testing, interactive testing, secrets scanning

Review and provide remediation guidance for submissions from Verisign’s public Bug Bounty program

Track open issues against defined SLAs, follow up with development teams, and escalate overdue items to engineering and Info Sec leadership

Provide guidance to support integration of security testing into CI/CD pipelines

Review third party and vendor supplied applications against internal security requirements

Mentor junior engineers and analysts, review peer work, and provide constructive feedback

Contribute to Information Security standards, secure coding guidance, and be an active participant in the broader Verisign technical communityAI and Application Security:

Assess applications that embed large language models or other AI services for risks such as prompt injection, sensitive data exposure, insecure output handling, and over permissioned agents and integrations

Develop and maintain internal guidance for developers using AI coding assistants, including expectations for review, testing, and scanning of AI generated code Evaluate and pilot AI assisted capabilities within the application security workflow such as finding triage, false positive reduction, and remediation guidance

Track developments in AI security guidance and standards and translate them into practical internal requirements and guidance

Key skills and experience:10+ years’ experience in Information Technology, including hands on application development experience6+ years’ experience conducting application security assessments using COTS and open-source tooling (Burp Suite, Fortify, or equivalent)
Hands-on experience with software composition analysis, dynamic application security testing, and secrets scanning platforms

Experience running a vulnerability management program through ticketing and workflow systems, including SLA definition and executive level reporting

Strong working knowledge of the OWASP Testing Framework and OWASP Top 10

Proficiency in currently accepted software development life cycles and associated standards and procedures

Knowledge of current application architectures (Single Page Application, 3 tier, microservices, containerized workloads)
Practical familiarity with AI and LLM application security risks and current industry guidance in that area Methodical and organized, able to manage multiple opportunities, projects, and partners concurrently

Able to multitask and work independently with minimum supervision to meet firm deadlines

Excellent communication, presentation, and leadership skills, including the ability to present to senior technical and non-technical audiences

Preferred skills and…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary