Application Security Engineer

Arcadiacareers

Washington, DC, United States
Base: $131,250 to $235,156; bonus/equity: competit...
**
Vulnerability management lifecycle
Sast, dast, sca tooling
Ci/cd pipeline integration
** Arcadia is seeking an Application Security Engineer to join its Information Security team, responsible for managing the vulnerability lifecycle and integrating security practices into development processes. The ideal candidate will have hands-on experience with application security tools and a collaborative mindset, ensuring effective communication within a diverse engineering team. **

Job Summary

  • Own the end-to-end vulnerability management lifecycle: triage, prioritize, and drive remediation of findings from SAST, DAST, and SCA tooling in partnership with engineering squads.
  • Maintain, optimize, and extend security tooling integrations within the CI/CD pipeline with the goal of automating everything that can be automated.
  • Launch and run a Security Champions program, including workshops and office hours, to embed security knowledge directly into development teams across multiple geographies.

Matching Summary

Match Score: 75

** Arcadia is seeking an Application Security Engineer to join its Information Security team, responsible for managing the vulnerability lifecycle and integrating security practices into development processes. The ideal candidate will have hands-on experience with application security tools and a collaborative mindset, ensuring effective communication within a diverse engineering team. **

Salary

Base: $131,250 to $235,156; Bonus/Equity: competitive equity component; Benefits: competitive benefits

Skills & Requirements

Must-have

  • vulnerability management lifecycle
  • SAST, DAST, SCA tooling
  • CI/CD pipeline integration
  • threat modeling product designs
  • container security Docker Kubernetes
  • API security patterns REST GraphQL

Nice-to-have

  • Security Champions program
  • AWS security services
  • threat modeling frameworks
  • technical risk communication

Key Requirements

  • 3-5 years Application Security experience
  • Hands-on proficiency with SAST, DAST, SCA, or CSPM tooling
  • Strong working knowledge of CI/CD pipelines
  • Experience with container security and API security

Work Rights

Not specified

Tailored Resume

Cover Letter