Quanata12.04.26
AI SCORE 8.5

Senior Application Security Engineer - Remote

$220K–$350K/year

About the Role

We're hiring a Senior Application Security Engineer to join our innovative team at Quanata. In this remote role, you'll play a crucial part in safeguarding our applications and ensuring security best practices are embedded throughout the software development lifecycle.

What You'll Do

  • Serve as the primary partner for web and backend engineering teams, helping embed security best practices throughout the software development lifecycle.
  • Conduct security design reviews and threat modeling on APIs, web features, and service integrations, integrating SAST, SCA, and DAST tools into CI/CD pipelines.
  • Support secure development practices across security champions and engineering teams.
  • Review source code and deployment configurations for security vulnerabilities.
  • Collaborate with developers to triage, fix, and validate vulnerability findings.
  • Participate in cross-functional incident response and remediation planning.
  • Draft and maintain AppSec guidance for engineering teams and security champions.
  • Contribute to security awareness and enablement across the engineering organization.

Requirements

  • Bachelor's degree or equivalent relevant experience.
  • 6 - 8 years of experience in application security or full-stack development with security expertise.
  • Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards.
  • Familiar with application risk and vulnerabilities (OWASP Top 10, API Security, SSRF, etc.).
  • Experience with code scanning tools (e.g., CodeQL, Semgrep, SonarQube, Snyk).
  • Clear and thoughtful communicator with the ability to guide engineers at all levels.
  • Working concepts of offensive security testing such as pentesting or bug bounties.

Nice to Have

  • Experience with GraphQL security.
  • Participation in security champions programs or secure SDLC rollouts.
  • Contributions to open-source security tooling.
  • Familiarity with infrastructure-as-code and container security.

What We Offer

  • A competitive salary range of $220,000 to $350,000, determined based on skills and experience.
  • Comprehensive health, wellness, and other benefits including medical, dental, vision, and life insurance.
  • A one-time payment of $2,000 for home office equipment and furniture.
  • Four weeks of paid time off in the first year, with additional parental leave benefits.
  • Up to $5,000 annually for professional development and learning opportunities.
  • Remote-first work environment with flexible arrangements.
  • Core meeting hours from 9 AM - 2 PM Pacific time for collaboration.
Language Requirements
EnglishC1
BasicIntermediateAdvancedNative
Why This Job8.5 of 10

This Senior Application Security Engineer role at Quanata offers a competitive salary, remote work flexibility, and the opportunity to work with cutting-edge security technologies.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Proficient in JavaScript and TypeScript, with hands-on experience in securing Node.js applications and implementing GraphQL best practices to fortify APIs against vulnerabilities.

Self-motivated and disciplined, thriving in a fully remote environment, with a strong ability to manage time effectively and collaborate asynchronously with cross-functional teams.

Deep understanding of OWASP principles and practical experience with SAST and DAST tools, demonstrating a proactive mindset in identifying and mitigating security risks throughout CI/CD pipelines.

Learning Resources

JavaScript Security Best Practicesarticle

Career Path

Senior Application Security Engineer(Now)Application Security Manager(1-2 years)Director of Security Engineering(3-5 years)

Market Overview

Market Size 2024
$35.4B
Annual Growth
12.5%
AI Adoption
45%
Investment
+150%
Labour Demand
+30%
Avg Salary
$130K

Skills & Requirements

Required
JavaScriptTypeScriptNode.js
Growing in Demand
Cloud SecurityDevSecOpsContainer Security
Declining
jQueryAngularJS 1.x

Domain Trends

Increased Focus on DevSecOps
Organizations are integrating security practices into their DevOps processes, with 70% of companies adopting DevSecOps practices by 2025.
Growth of API Security
With the rise of microservices, API security is becoming critical, with a projected 40% increase in demand for API security tools and expertise.
Shift to Serverless Architectures
The adoption of serverless architectures is growing, with 60% of organizations expected to deploy serverless applications by 2025, requiring security engineers to adapt their skills.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.