Full Time

Application Security Engineer - Awardco - Lindon, UT

Awardco

Lindon, UT
Posted 14 days ago

Awardco is reimagining the workplace to be more rewarding, supportive, and fun for everyone. As one of the fastest-growing companies in the employee experience industry, our mission is to help employees love what they do, love where they work, and get recognized for their efforts—especially our own employees! And as winners of Glassdoor's Best Places to Work, Best in Brightest in the Nation, and Great Place to Work, we do much more than talk the talk.

We're looking for an Application Security Engineer joining our IT & Security team to build and mature our application security program as we continue to scale our SaaS platform. In this role, you'll partner closely with product, engineering, and operations teams to design, build, and ship secure features — without slowing down creativity and innovation. You'll own the secure software development lifecycle, lead security reviews for new capabilities, and help drive a culture where every engineer treats security as part of quality.

You'll also play a key role in enabling developers, building the skills and tooling they need to own security in their code through secure coding guidance, training, and a strong Security Champions program. If you enjoy rolling up your sleeves, solving real-world security problems, and making cloud products safer by design, this role is for you.

What you will do:
• Embed security checkpoints into planning, design, development, testing, and release processes.
• Partner with engineering leads to ensure new features ship with security built in, not bolted on.
• Facilitate threat modeling for new services, APIs, and integrations.
• Recommend secure patterns and architectures for multi-tenant SaaS and cloud-native components.
• Perform targeted secure code reviews for high‑risk features and components.
• Configure and tune SAST, DAST, dependency, and container scanning to reduce noise and highlight real risk.
• Integrate and optimize AI-assisted application security tools (e.g., GitHub Advanced