Senior Application Security Engineer

About the role

We're looking for a Senior Application Security Engineer. You own security in the software development lifecycle (SDLC) — end to end, hands-on, and independently. You report to the CISO. The CISO sets direction, risk appetite, and handles executive escalation; you run application security day to day without needing constant support. You'll partner with engineering teams to find, fix, and prevent vulnerabilities in a platform built primarily on .NET and hosted in Azure, while helping us secure the next generation of AI-powered features. This is a hands-on role for someone who wants to make secure development the path of least resistance for our engineers.

What you’ll do

· Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs. Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.

· Security tooling in CI/CD. Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets.

· Azure security. Secure our cloud estate across identity and access management (Entra ID, Auth0), network configuration, secrets management, and workload protection, working with Defender for Cloud policy and posture.

· Threat modeling and reviews. Conduct threat models, design reviews, and code reviews for new and existing services — with a threat model in place before any new service reaches production.

· AI feature security. Evaluate security and privacy implications of our AI functionality, including LLM-specific risks such as prompt injection, data leakage, and model misuse, and define controls for them.

· Standards and enablement. Define and uphold secure coding standards, train engineers, and build a security champion in each product team so risk assessment becomes self-service rather than a security-team bottleneck.

· Pen tests and scans. Coordinate penetration tests and application vulnerability scanning, review the findings, identify fixes, and implement them hands-on when needed.

· Incident response. Support security incident investigation and response as the application subject-matter expert, working with our 24/7 managed detection and response partner.

What you’ll bring

· 8+ years of experience in application security, or in software engineering with a strong security focus.

· Experience integrating and operating security tooling within CI/CD pipelines.

· Strong .NET (C#) working knowledge; ability to read and reason about Python is a plus.

· Fluency in common vulnerability classes (OWASP Top 10, API security risks) and how they manifest in real code — not just in scanner output.

· Hands-on Azure experience: creating resources, securing applications, Azure networking, and secrets management.

· Hands-on experience with Auth0 in production environments.

· Strong communication skills and the ability to influence engineers without owning their backlog.

· A pragmatic, risk-based mindset that balances security with delivery — you know which findings matter and which are noise

Ready to apply? 📬

We’d love to hear from you. If you’re curious but not 100% sure, we still encourage you to apply. We’re happy to explore the fit together!

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available