Quanata logo
Quanata
Posted 66 days agoVerified live 2d ago

Application Security Engineer [Remote-US]

Brief overview

Remote
$175k–$215k/yrStated range
17 H-1B approvalsDept. of Labor
6 green cardsCertified filings
Application SecuritySecure-by-design PrinciplesOWASP Top 10ASVSMASVSThreat ModelingSTRIDEPASTACloud PlatformsProgramming LanguagesSecurity CertificationsCloud SecurityMobile Application SecurityPenetration TestingSecurity Automation

About the company

Developing risk prediction and telematics software for insurance companies.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
17H-1B approved
100%approval rate
3new H-1B hires
6PERM certified
$223,645median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20235
20244
20254
20264
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
20254
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20233
20242
20251
Top sponsored roles
Manager, Mobile EngineeringSDET EngineerSenior DesignerSDET, Back EndSenior Business Analyst
Sponsored employees from
India

Job description

Summary

Quanata is an insurance technology innovation company focused on creating advanced risk prediction and prevention solutions. They are seeking an Application Security Engineer to build secure products and services for their AI-native insurance platform, working closely with various teams to ensure security is integrated throughout the software development lifecycle.

Responsibilities

  • Partner with Product and Engineering teams to integrate security into application design and development
  • Lead threat modeling exercises and identify practical security solutions for complex systems
  • Conduct secure code reviews, application security assessments, and vulnerability analysis
  • Develop and implement automated security guardrails across the SDLC
  • Investigate, prioritize, and drive remediation of application security findings
  • Promote secure coding practices through training, coaching, and awareness initiatives
  • Collaborate with Security, Privacy, and Business Assurance teams to support compliance and risk management objectives
  • Create and maintain security standards, procedures, and best practices that scale across teams

Skills

  • Associate's degree or equivalent experience required; Bachelor's degree preferred
  • 4–6+ years of experience in software engineering, including at least 2 years focused on application security
  • Experience partnering directly with software development teams to improve application security
  • Knowledge of secure-by-design principles and modern application security practices
  • Familiarity with OWASP Top 10, ASVS, MASVS, and common application security frameworks
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar approaches
  • Working knowledge of cloud platforms and modern application architectures
  • Proficiency in at least one programming language and its security ecosystem
  • Strong communication skills and the ability to influence technical and non-technical stakeholders
  • Comfortable operating in a fast-paced environment with shifting priorities
  • Security certifications such as CSSLP, GWEB, OSWE, or similar
  • Experience working in insurance, financial services, healthcare, or other regulated industries
  • Advanced knowledge of cloud security and application security architecture
  • Experience with mobile application security, QA testing, or penetration testing
  • Familiarity with AI technologies, LLM security, or prompt engineering
  • Experience building scripts or automations to streamline security processes
  • Active involvement in the security community through conferences, mentoring, presentations, publications, or open-source contributions

Qualifications

Must Haves

  • Associate's degree or equivalent experience required; Bachelor's degree preferred
  • 4–6+ years of experience in software engineering, including at least 2 years focused on application security
  • Experience partnering directly with software development teams to improve application security
  • Knowledge of secure-by-design principles and modern application security practices
  • Familiarity with OWASP Top 10, ASVS, MASVS, and common application security frameworks
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar approaches
  • Working knowledge of cloud platforms and modern application architectures
  • Proficiency in at least one programming language and its security ecosystem
  • Strong communication skills and the ability to influence technical and non-technical stakeholders
  • Comfortable operating in a fast-paced environment with shifting priorities

Nice to Haves

  • Security certifications such as CSSLP, GWEB, OSWE, or similar
  • Experience working in insurance, financial services, healthcare, or other regulated industries
  • Advanced knowledge of cloud security and application security architecture
  • Experience with mobile application security, QA testing, or penetration testing
  • Familiarity with AI technologies, LLM security, or prompt engineering
  • Experience building scripts or automations to streamline security processes
  • Active involvement in the security community through conferences, mentoring, presentations, publications, or open-source contributions

Benefits

  • Medical, dental, vision, life insurance and supplemental income plans for you and your dependents
  • A Headspace app subscription
  • Monthly wellness allowance
  • A 401(k) Plan with a company match
  • A one-time payment of $2K will be provided to cover the purchase of in-home office equipment and furniture at your discretion
  • MacBook Pros, which we will deliver to you fully provisioned prior to your first day
  • All employees accrue four weeks of PTO in their first year of employment
  • New parents receive twelve weeks of fully paid parental leave which may be taken within one year after the birth and/or adoption of a child
  • The twelve weeks is applicable to both birthing and non-birthing parent
  • All employees receive up to $5000 each year for professional learning, continuing education and career development
  • All team members also receive LinkedIn Learning subscriptions
  • Access to multiple different coaching opportunities through BetterUp

More jobs like this