CivicPlus logo
CivicPlus
Posted 11 days agoVerified live 7h ago

Application Security Engineer

Brief overview

Remote
UndergradOr in progress
$70k–$101k/yrStated range
3+ yrsMinimum
10 H-1B approvalsDept. of Labor
Application SecuritySecurity Code ReviewThreat ModelingArchitecture ReviewPenetration TestingSASTDASTIASTOWASP Top 10Secure CodingCI/CD PipelinesCloud-Native ApplicationsSaaS ApplicationsSecurity+GSECGSSP

About the company

CivicPlus logo
CivicPluscivicplus.com

CivicPlus is the only government technology company exclusively committed to powering and empowering governments to efficiently operate, serve, and govern through the use of our innovative and integrated technology solutions purpose-built and supported by former municipal leaders and award-winning support teams.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
10H-1B approved
100%approval rate
3new H-1B hires
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20232
20245
20251
20262

Job description

Summary

CivicPlus is a company focused on serving local governments and the residents they support through innovative software and collaboration. The Application Security Engineer will embed security throughout the software development lifecycle by leading application security testing, reviewing designs and code, identifying vulnerabilities, and coordinating remediation and penetration testing.

Responsibilities

  • Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC)
  • Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC
  • Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements
  • Coordinate external, independent penetration testing of production environments
  • Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST)
  • Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats

Skills

  • Applicants must be authorized to work in the US
  • 3–7 years of experience in application security, secure development, penetration testing, or a related field
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST)
  • Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations
  • Security+, GSEC, GSSP, or equivalent certification
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred)
  • Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments
  • AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality
  • Demonstrated ability to effectively use AI tools to enhance productivity and outcomes

Qualifications

Must Haves

  • Applicants must be authorized to work in the US

Nice to Haves

  • 3–7 years of experience in application security, secure development, penetration testing, or a related field
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST)
  • Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations
  • Security+, GSEC, GSSP, or equivalent certification
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred)
  • Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments
  • AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality
  • Demonstrated ability to effectively use AI tools to enhance productivity and outcomes

Benefits

  • Comprehensive health insurance
  • Dental insurance
  • Vision insurance
  • Flexible Time Off
  • 401(k) plan

More jobs like this