Talent.com
Python/Django Senior Application Security Engineer (Hybrid - US)
Python/Django Senior Application Security Engineer (Hybrid - US)Energy Solutions • Oakland, CA, United States
Python / Django Senior Application Security Engineer (Hybrid - US)

Python / Django Senior Application Security Engineer (Hybrid - US)

Energy Solutions • Oakland, CA, United States
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus on the big impacts. And we believe that market-based programs can be a powerful force to deliver large-scale energy, carbon, and water-use savings. Since 1995, we've harnessed that power to offer proven, performance-based solutions for our utility, government, and institutional customers.

Summary :

We are seeking a Senior Application Security Engineer who will work with our development team to manage security and risk on our internally developed applications. The engineer will make risk-based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms. This role is primarily focused on execution and consulting but should be familiar with roadmap and strategy and contribute where appropriate. Must have the ability to read, review, and make recommendations on secure Django / Python patterns.

Responsibilities :

  • Contribute to the application security roadmap for our internal applications-prioritize risks and sequence work across codebases, application layer, and DevOps.
  • Consult with engineers to communicate requirements, create actionable tickets / acceptance criteria, and drive adoption.
  • Conduct pull request reviews focused on security, provide guidance on refactors, and approve / deny with clear rationale.
  • Serve as a steward for SAST / scanning : review static code scan results, triage findings, eliminate noise, and drive remediation with owners.
  • Build reference implementations in Django / Python (i.e. authentication patterns, input validation, secrets handling, rate limiting, geo-based access) without direct responsibility for production feature development.
  • Map SOC 2 / NIST to engineering work : translate requirements into stories, controls, and automated evidence in CI / CD.
  • Threat modeling & architecture : navigate libraries / architectures and document secure patterns (ADRs / RFCs) that teams follow.
  • Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.
  • Collaborate with software developers and code base leads.
  • Act as a liaison between technical requirements from the business (i.e. security, privacy, compliance) and development teams.
  • Participate as a subject matter expert in security architecture, including new designs and design reviews.
  • Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.
  • Review architecture and compliance-related code changes for security impact.
  • Ensure compliance with all company security policies and standards.
  • Manage and maintain all security related tickets, including recommendations, testing, and validation.

Qualifications :

  • Minimum of 5 years' experience in application security experience.
  • Practice and implementation with Django / Python with a clear application-security focus (production experience and impact, not theory).
  • Engineering background (software or DevOps / SRE) with the ability to read / modify code, review PRs, and build PoCs.
  • Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
  • Experience embedding secure SDLC into Git-based workflows and CI / CD (pre-commit, pipeline gates, policy-as-code).
  • Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.
  • Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging / monitoring).
  • Clear, persuasive communication (verbal and written) and prioritization.
  • Excellent time management skills with a proven ability to meet deadlines.
  • Excellent interpersonal and negotiation skills.
  • Preferred Qualifications :

  • Bachelors degree in Computer Science or equivalent work experience preferred.
  • CISSP, GIAC, Security+, AWS Security and other related security certifications.
  • Prior experience reporting to or partnering with a security architect, or being the app-sec lead in a smaller org.
  • Strong organizational skills and attention to detail.
  • Strong analytical and problem-solving skills.
  • Ability to prioritize tasks according to severity
  • Ability to adapt to the needs of the organization
  • Proficient in AWS Security services (I.E. Cloud watch, Guard Duty)
  • The salary range for this role is $119,100 - $147,400 / annually, with a target compensation of $119,000 to $131,600 based on experience and qualifications.

    Compensation is commensurate with experience and includes a generous retirement package. Energy Solutions provides an excellent benefits package including medical, dental and vision insurance, other pre-tax contribution plans and an Employee Stock Ownership Plan (ESOP).

    AI Use

    At Energy Solutions we believe in the importance of authentic interactions and equitable opportunities. We base our candidate selection on one's own skills, knowledge, and experience. To ensure the integrity and fairness of our interview process, the use of artificial intelligence (AI) tools (including Generative AI) or other means to generate or assist with responses during interviews is strictly prohibited. This practice supports our commitment to create a transparent and equitable space where skills, knowledge and experience skills can truly shine.

    Equal Opportunity Employer

    Energy Solutions is an affirmative action-equal opportunity employer and prohibits discrimination and harassment of any type. We afford equal employment opportunities to employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristics protected by law. Energy Solutions conforms to the spirit as well as to the letter of all applicable laws and regulations.

    Office Locations and a Remote Workforce

    Energy Solutions operates as a predominantly remote workforce with offices in six different locations . Employees who reside within 40 miles of an office (except New York) will be assigned to that location, though in-office attendance requirements may vary by team. At this time, we are not accepting applications from candidates residing in the following states : Delaware, Kentucky, Mississippi, Montana, Nebraska, North Dakota, and Wyoming.

    Background Check Information

    Information will be requested to perform the compulsory background check. A drug screen and authorization to work in the U.S. indefinitely are preconditions of employment. Energy Solutions is an equal opportunity employer.

    Reasonable Accommodations

    Energy Solutions is committed to providing access and reasonable accommodation for individuals with disabilities. If you require accommodations in completing this application, interviewing, and / or completing any pre-employment testing, or otherwise participating in the employee selection process, please email accommodation@energy-solution.com .

    Privacy Notice for Job Applicants

    [job_alerts.create_a_job]

    Application Security Engineer • Oakland, CA, United States

    [internal_linking.similar_jobs]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Zip • San Francisco, CA, United States
    [job_card.full_time]
    The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Security Engineer — Cloud & App Platform

    Senior Security Engineer — Cloud & App Platform

    Sentry • San Francisco, CA, United States
    [job_card.full_time]
    A leading software monitoring company is seeking a Senior Security Engineer in San Francisco to enhance its cloud security posture. In this role, you will lead security initiatives, collaborate with...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Imprint • San Francisco, CA, United States
    [job_card.full_time]
    Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Rakuten, Booking.H-E-B, Fetch, and Brooks Bro...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Product Security Engineer — Build Secure, Scalable Apps

    Senior Product Security Engineer — Build Secure, Scalable Apps

    Rippling • San Francisco, CA, United States
    [job_card.full_time]
    A technology company in San Francisco is seeking a hands-on Staff Security Engineer to enhance its Product Security program. The ideal candidate will have over 10 years of experience in product secu...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer — Shape Global Privacy

    Senior Application Security Engineer — Shape Global Privacy

    Kubelt • San Francisco, CA, United States
    [job_card.full_time]
    A leading technology organization in California is looking for a Security Architect to tackle complex security challenges throughout the product lifecycle. The role requires at least 5 years of expe...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Cloud Security Engineer — Privacy & Crypto

    Senior Cloud Security Engineer — Privacy & Crypto

    Hp Iq • San Francisco, CA, United States
    [job_card.full_time]
    A major technology company is seeking a Senior Software Engineer specializing in Services Security to design and implement secure cloud services. The ideal candidate has extensive experience in secu...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Application Security Engineer : Build Secure Cloud Apps

    Senior Application Security Engineer : Build Secure Cloud Apps

    CloudFlare • San Francisco, CA, United States
    [job_card.full_time]
    A leading cybersecurity company is seeking a Senior Application Security Engineer.This role involves working closely with engineering teams to secure products, assess new features, and contribute t...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior App Security Engineer : Cloud & Threat Modeling

    Senior App Security Engineer : Cloud & Threat Modeling

    Verticalmove, Inc • San Francisco, CA, United States
    [job_card.full_time]
    A leading technology firm based in San Francisco is seeking a Senior & Lead Application Security Engineer to ensure the security integrity of their SaaS and data platforms.The ideal candidate will ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Software Engineer - Identity & Security Products

    Senior Software Engineer - Identity & Security Products

    Twilio • San Francisco, CA, United States
    [job_card.full_time]
    At Twilio, we're shaping the future of communications, all from the comfort of our homes.We deliver innovative solutions to. As we continue to revolutionize how the world interacts, we're acquiring ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior App Security Engineer — AI-Driven Security

    Senior App Security Engineer — AI-Driven Security

    Brex • San Francisco, CA, United States
    [job_card.full_time]
    A leading financial technology firm in San Francisco is searching for a Senior Application Security Engineer to identify and respond to security vulnerabilities. The role involves penetration testin...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Fullstack Engineer Security Workflows & Integrations

    Senior Fullstack Engineer Security Workflows & Integrations

    Menlo Ventures • San Francisco, CA, United States
    [job_card.full_time]
    A leading application security firm in San Francisco is seeking experienced developers to join their Security Workflows team. This role involves building customer-facing integrations, mentoring juni...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer : Build Secure Apps

    Senior Application Security Engineer : Build Secure Apps

    ZipHQ, Inc. • San Francisco, CA, United States
    [job_card.full_time]
    A leading procurement technology firm in San Francisco is seeking its first Application Security Engineer to build security guardrails and enhance product security across their platforms.The succes...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry.io • San Francisco, CA, United States
    [job_card.full_time]
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Application Security Engineer

    Application Security Engineer

    Monograph • San Francisco, CA, United States
    [job_card.full_time]
    Our mission is to modernize the payments infrastructure for trucking and logistics.We're building Stripe for Transportation, centering our customers in every way and offering them world-class custo...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Application Security Engineer

    Senior Application Security Engineer

    Airwallex • San Francisco, CA, United States
    [job_card.full_time]
    Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000 businesses ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Blockchain Security Engineer

    Senior Blockchain Security Engineer

    Gemini • San Francisco, CA, United States
    [job_card.full_time]
    Senior Application Security Engineer.Senior Application Security Engineer.Get AI-powered advice on this job and more exclusive features. Gemini is a global crypto and Web3 platform founded by Camero...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Lead Application Security Engineer — AI / ML Security & SSDLC

    Lead Application Security Engineer — AI / ML Security & SSDLC

    Coupa Software • San Francisco, CA, United States
    [job_card.full_time]
    A leading technology firm in San Francisco is seeking a Lead Application Security Engineer to enhance and expand its application security practices. Key responsibilities include driving security arc...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Offensive Security Engineer AppSec & Cloud Pentesting

    Senior Offensive Security Engineer AppSec & Cloud Pentesting

    Astranis • San Francisco, CA, United States
    [job_card.full_time]
    A leading satellite communications company in San Francisco is looking for a Senior Offensive Security Engineer to lead penetration testing and adversarial simulations. The candidate should have ove...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]