Talent.com
Connvertex Technologies Inc.
Mid Application Security EngineerConnvertex Technologies Inc. • San Francisco, CA, United States
Mid Application Security Engineer

Mid Application Security Engineer

Connvertex Technologies Inc. • San Francisco, CA, United States
1 day ago
Job type
  • Full-time
  • Quick Apply
Job description

RESPONSIBILITIES

  • Perform application security assessments including manual code review, SAST, DAST, SCA, and targeted penetration testing.
  • Lead threat modeling sessions for new features, architectural changes, and AI/LLM-backed workflows with customer product and engineering teams.
  • Integrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) with minimal developer friction.
  • Triage, track, and drive remediation of findings across web, mobile, and API surfaces with developer-friendly workflows and SLAs.
  • Design and maintain secure coding standards, authentication and authorization patterns (OAuth 2.0, SAML, JWT), and training materials for customer development teams.
  • Evaluate third-party libraries, vendor integrations, and open-source dependencies for supply chain and security risk.
  • Support incident response activities and contribute to post-incident analysis with a focus on application-layer root cause.
  • Write and maintain documentation, runbooks, and architecture decision records (ADRs) for AppSec tooling, coding standards, and remediation playbooks.

QUALIFICATIONS

  • 3 to 5 years of experience in application security, penetration testing, or secure software development.
  • Strong knowledge of OWASP Top 10, CWE, and common web and API vulnerability classes.
  • Hands-on experience with at least two of the following: SAST, DAST, SCA, or IAST tools in real CI/CD environments.
  • Proficiency in one or more programming languages (Python, Go, JavaScript/TypeScript, or Java) for automation, tooling, and integration work.
  • Familiarity with modern development workflows including Git, CI/CD pipelines, and containerized environments.
  • Solid understanding of authentication and authorization frameworks (OAuth 2.0, SAML, JWT).
  • Excellent communication skills with the ability to translate security findings into actionable engineering tasks.
  • Must be located in the SF Bay Area or willing to travel to our San Francisco office on a regular cadence.

NICE TO HAVE

  • Relevant certifications such as OSCP, GWAPT, CEH, or CSSLP.
  • Experience with bug bounty programs or responsible disclosure processes.
  • Familiarity with cloud-native security (AWS, GCP, or Azure) and cloud-native workload protection.
  • Prior contributions to open-source security tooling.
Create a job alert for this search

Mid Application Security Engineer • San Francisco, CA, United States

Similar jobs

Senior Application Security Engineer

ZipHQ, Inc.San Francisco, CA, United States
Full-time

The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world.Today, enterprises spend $120T+ per year globally... Show more

 • Promoted

Web Application Security Engineer

Direct Staffing IncSan Francisco, CA, United States
Full-time

Visa candidates are welcome to apply.Shopping has changed more in the past five years than in the past five decades, and going forward, retailing will require investing more in people and technolog... Show more

 • Promoted

Digital Security (4587-1) San Francisco, CA

ESR HealthcareSan Francisco, CA, United States
Full-time

Provide guidance and examples to other engineers for the documents and deliverables to assure consistency in the Project Delivery Methodology, and occasionally lead initiatives toward process and p... Show more

 • Promoted

Senior Anti-Abuse Security Engineer, Product Security Equity

SnowflakeMenlo Park, CA, United States
Full-time

A leading data platform company is seeking a Senior Anti-Abuse Security Engineer to design, build, and operate systems that protect against abuse, misuse, and fraud.The role involves working at the... Show more

 • Promoted

Security Systems Engineer (Remote)

Cisco Systems, Inc.San Francisco, CA, United States
Remote
Full-time

The application window is expected to close on 10 / 28 / 2025.Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.AI at CiscoWith Cis... Show more

 • Promoted

Senior, Advanced Application Engineer - Location Flexible

PG&E CorporationRICHMOND, California, US
Full-time

Job Category: Engineering / Science .Job Level: Individual Contributor.Business Unit: Operations - Other.Job Location: Oakland; Alameda; Alta; American Canyon; Angels Camp; Antioch; Auberry; Auburn... Show more

 • Promoted

Security Engineer, Application Security

OpenAISan Francisco, CA, United States
Full-time

Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity.The Security team protects OpenAI's technology, people, and products.We are... Show more

 • Promoted

Security Engineer

Velia multiservicesSan Francisco, CA, USA
Full-time
Quick Apply

Velia Multiservices is partnering with a fast-growing startup to find an exceptional Security Engineer ready to build and own security from the ground up.This is not a traditional security role.Thi... Show more

Application Security Engineer

JobotSan Francisco, CA, United States
Permanent

Competitive Base + Uncapped Commission, Full Benefits, Generous PTO.This Jobot Job is hosted by: Katie Whittington.Are you a fit? Easy Apply now by clicking the "Apply" button and sending us your r... Show more

 • Promoted

Senior Application Security Engineer

KubeltSan Francisco, CA, United States
Full-time

World is a network of real humans, built on privacy-preserving proof-of-human technology, and powered by a globally inclusive financial network that enables the free flow of digital assets for all.... Show more

 • Promoted

Product Security Engineer

ChimeSan Francisco, CA, United States
Full-time

We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiati... Show more

 • Promoted

Remote Senior Security Engineer -- Cloud & App Security Lead

Doctor On DemandSan Francisco, CA, United States
Remote
Full-time

A leading telehealth provider is seeking a Senior Security Engineer to design and implement security controls across application stacks in cloud environments.This role focuses on AWS security, auto... Show more

 • Promoted

Remote Senior Application Security Engineer - Zetachain

ZetachainSan Francisco, CA, United States
Remote
Full-time

Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program.The ideal candidate will be responsibl... Show more

 • Promoted

Product Security Engineer Cloud and Infrastructure

1X Technologies ASSan Carlos, CA, US
Full-time

Product Security Engineer, Cloud & Infrastructure.We build humanoid robots that work alongside people to solve labor shortages and create abundance.As a Product Security Engineer focused on clo... Show more

Application Security Architect & Developer

USA Tech RecruitSan Francisco, CA, United States
Full-time

Application Security Architect & Developer.Get AI-powered advice on this job and more exclusive features.Direct message the job poster from USA Tech Recruit.Associate Recruitment Consultant | Softw... Show more

 • Promoted

Senior Application Security Engineer - Build Core Defenses

ZipSan Francisco, CA, United States
Full-time

A leading procurement platform company in San Francisco is looking for an Application Security Engineer to join their team.This role involves designing and implementing security measures, mentoring... Show more

 • Promoted

Remote Application Security Engineer - Zetachain

Blockchain WorksSan Francisco, CA, United States
Remote
Full-time

ZetaChain aims to be the only blockchain you’ll ever need.It is a layer 1 blockchain and developer platform that connects any L1 and L2, from Ethereum to Bitcoin and beyond.Access all of crypto in ... Show more

 • Promoted

Security Engineer for Scale — AWS, SIEM & Tooling

gamma.appSan Francisco, CA, United States
Full-time

A tech innovation company in San Francisco is seeking a Security Engineer to enhance platform security as it scales.You will build security tools, review architecture, and collaborate across teams ... Show more