Post Job Free
Sign in

Senior Application Security Engineer

Company:
Anveta
Location:
Houston, TX
Posted:
September 08, 2026
Apply

Description:

Great candidate, however, we are looking for someone with a stronger Application Security background. Certifications like DevSecOps and CISSP are helpful, but they are not enough on their own.

The ideal candidate should have hands-on experience implementing security technologies like SAST, SCA, DAST, IAST, IaC, and Container Security, and should have worked closely with development teams.

Experience with tools such as Snyk, Checkmarx, Veracode, Apiiro, or Cycode is a big plus.

Overall, the client is looking for a strong Senior Application Security Engineer with DevSecOps Team Lead-level experience.

App Sec; Houston, TX

Priority skills

Application Security (required)

Software Development experience (super beneficial)

DevSecOps experience (super beneficial) Working Arrangement:

3-days onsite/2-day offsite Reporting Location:

Houston, TX (1501 McKinney St, Houston TX 77010 I believe) Duration:

Default to end of 2027 (will gather more info on this) Role Overview

We are seeking a Senior Application Security Engineer to help secure our software development lifecycle by leveraging traditional SAST/DAST tools and leveraging AI-enabled tools to identify and remediate code vulnerabilities. This role partners closely with development, DevOps, and security teams to drive secure coding practices and improve application risk posture at scale. Uses AI-driven tools to improve vulnerability detection accuracy, automate code review, and accelerate remediation across the software lifecycle.

Key Responsibilities

Embed application security into the SDLC, CI/CD pipelines, and developer workflows

Perform and oversee SAST, DAST, SCA, and API security testing

Leverage AI-based code scanning tools to enhance vulnerability detection, reduce false positives, and accelerate remediation

Partner with developers to remediate vulnerabilities and improve secure coding practices

Conduct threat modeling and security reviews for applications and APIs

Track and report security metrics (e.g., vulnerability trends, remediation timelines) AI-Based Code Scanning & Intelligent Security Automation

Implement and manage AI-powered code scanning solutions to analyze source code, APIs, and dependencies for security vulnerabilities across the SDLC

Leverage AI/ML capabilities to identify complex vulnerability patterns, insecure coding practices, and hidden attack paths that traditional tools may miss

Use AI to reduce false positives, improve signal-to-noise ratio, and enable more efficient triage of security findings

Apply AI-assisted insights to perform root cause analysis and provide developers with actionable, context-aware remediation guidance

Integrate AI-enabled security scanning into CI/CD pipelines to provide real-time feedback during development and code commits

Evaluate and optimize AI models and rulesets to improve detection accuracy and alignment with enterprise risk priorities

Partner with engineering teams to embed AI-assisted code review and secure coding recommendations into developer workflows (e.g., pull requests, IDE plugins)

Monitor and measure the effectiveness of AI-based scanning through metrics such as detection rates, false positive reduction, and remediation speed

Stay current on emerging AI security tools, LLM-based code analysis, and automated remediation technologies, and drive adoption where they add value Required Qualifications

7+ years of experience in application security, DevSecOps, or secure software engineering

Strong knowledge of OWASP Top 10 and secure coding practices

Experience with application security tools (e.g., SAST, DAST, SCA)

Experience integrating security into CI/CD pipelines

Knowledge of Ghazdo and GitHub Advance security

Proficiency in at least one programming language (e.g., Python, Java, JavaScript) Priority skills

Application Security (required)

Software Development experience (super beneficial)

DevSecOps experience (super beneficial)

Working Arrangement:

3-days onsite/2-day offsite Reporting Location:

Houston, TX (1501 McKinney St, Houston TX 77010 I believe) Duration:

Default to end of 2027 (will gather more info on this)

Apply