Security Applications Engineer - Search BizAthletes - San Jose, CA
Search BizAthletes
Bay Area | Contract-to-Hire | Cybersecurity Services | Application Security Engineer We’re recruiting for an Application Security Engineer on behalf of a high-growth VAR cybersecurity services firm. This is a hands-on, client-facing role where you’ll work closely with product and engineering teams to embed security into the development lifecycle—ideal for someone who enjoys staying technical while driving real security outcomes across modern application environments. A rapidly growing cybersecurity services company delivering advanced security solutions across application, cloud, and detection domains.
The firm partners with enterprise clients to strengthen security posture, improve detection and response, and embed secure development practices across web, mobile, and API environments. Perform application security assessments including code review, SAST, DAST, SCA, and targeted testing Integrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines Triage and drive remediation of vulnerabilities across web, mobile, and API surfaces Design and implement secure coding standards and authentication/authorization patterns (OAuth 2.0, SAML, JWT) Evaluate third-party libraries and dependencies for security and supply chain risk Support incident response and contribute to application-layer root cause analysis Develop documentation, runbooks, and security playbooks to support engineering teams 3–5 years of experience in application security, penetration testing, or secure software development ~ Strong knowledge of OWASP Top 10, CWE, and common web/API vulnerabilities ~ Proficiency in one or more languages (Python, Go, JavaScript/TypeScript, or Java) ~ Ability to travel regularly to San Francisco Bay Area Familiarity with cloud security (AWS, GCP, Azure) Compensation & Structure: Contract role with potential for W2 conversion Hands-on role working directly with engineering teams to influence secure development practices Exposure