Application Security Engineer
Job Description
Purpose Brands is looking for an Application Security Engineer to strengthen application security within a DevSecOps operating model. In this hybrid role, you will help embed security controls, automation, and secure development practices throughout the software delivery lifecycle for cloud-based applications running on AWS and Azure.
You will work closely with engineering and DevOps teams to integrate security testing into CI/CD pipelines, improve the quality of security signals by tuning tools, and support remediation efforts based on risk and business impact. The result is a more consistent, scalable approach to application security across modern cloud and container-based environments.
Responsibilities
- Integrate application security practices across the SDLC, from design through deployment and ongoing maintenance
- Conduct application security assessments using SAST, DAST, and SCA (software composition analysis)
- Develop and maintain threat models for critical systems and applications, partnering with engineering teams to drive remediation
- Promote secure coding practices and contribute to secure development standards aligned with OWASP and industry best practices
- Collaborate with engineering and DevOps teams to integrate security tooling into CI/CD pipelines for automated, repeatable testing
- Analyze and manage vulnerability findings from tools such as GitHub Advanced Security, Syft, Clair, Qualys, and similar solutions
- Tune security tooling to reduce false positives and improve signal quality for development teams
- Support security automation to improve consistency, efficiency, and scalability across application environments
- Help secure applications deployed on AWS and/or Azure, including IaaS, PaaS, and container-based platforms
- Identify and assess risks to the confidentiality, integrity, and availability of application data in cloud environments
- Work with cloud and platform security engineers to ensure application security controls align with broader cloud security architecture
- Own and curate application security controls within Cloud Engineering and Platform Engineering, aligned with NIST CSF, CIS Benchmarks, and CSA CCM
- Triage, prioritize, and track remediation of application vulnerabilities based on risk and business impact
- Assist with security investigations involving application vulnerabilities or security events
- Participate in periodic reviews of application security controls to validate effectiveness and compliance
- Provide guidance, education, and actionable recommendations to engineering teams
- Contribute to continuous improvement of application security processes, standards, and metrics
- Support governance, risk management, and compliance initiatives related to application security
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related field
- 3–5 years of experience in application security, security engineering, or software engineering with a strong security focus
- Hands-on experience performing code reviews and application security testing across modern languages, frameworks, and APIs
- Experience with application security tools including SAST, DAST, and dependency scanning (for example, GitHub Dependabot or similar)
- Strong understanding of OWASP Top 10, secure coding principles, authentication/authorization, and API security
- Practical experience supporting applications in AWS and/or Azure cloud environments
- Familiarity with CI/CD pipelines, DevOps workflows, and DevSecOps concepts
- Ability to communicate security risks and remediation guidance clearly to developers and non-security stakeholders
- Analytical skills to balance security risk with delivery velocity
Technologies
AWS, Azure, IaaS, PaaS, container-based platforms, SAST, DAST, SCA, GitHub Advanced Security, Syft, Clair, Qualys, OWASP Top 10, OWASP, GitHub Dependabot, CI/CD pipelines, DevOps, DevSecOps, NIST CSF, CIS Benchmarks, CSA CCM
Benefits
- Medical, Dental and Vision Coverage
- Hybrid Work Environment
- Life and Disability Insurance
- Unlimited Time off + Paid Holidays
- Flexible Fridays between Memorial Day and Labor Day
- 401(K) Savings Plan Matching at 4%
- 10 Coaching and Therapy sessions
- Mental Health Benefits
- Brand Discounts & Reimbursements
- In-house workout facilities
- Professional Development Opportunities
- Team Building, Employee Engagement Activities & so much more
Preferred Certifications
- Security+, CSSLP, GWAPT, GWEB, CEH, GPEN, or other application security-focused certifications
Work Schedule
Purpose Brands LLC follows the hybrid work model for employees at our Boca Raton (FL), Woodbury (MN), and Seattle (WA) offices:
- Remote optional: Fridays
- On-site days: Mondays, Tuesdays, Wednesdays and Thursdays