Commerce has been recognized on not just one… but SEVEN of Built In’s Best Places to Work 2026 lists!
Commerce Logo

Commerce

Application Security Engineer II

Posted 15 Hours Ago
Be an Early Applicant
In-Office
Austin, TX
76K-128K Annually
Mid level
In-Office
Austin, TX
76K-128K Annually
Mid level
Perform application security assessments including penetration testing, code audits, and architecture reviews. Triage SAST/DAST/SCA findings, work with engineering on remediation, support incident response, improve security tooling and documentation, and research new attack vectors to reduce risk.
The summary above was generated by AI
Welcome to the Agentic Commerce Era

At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. Simply said, we help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers, working together to shape the future of commerce, this is the place for you.

BigCommerce, part of the Commerce brand family, helps merchants increase sales at every stage of their growth. From small startups to mid-market businesses and large enterprises, we provide the leading e-commerce platform. Our customers can then concentrate on what's most important: growing their businesses. We enable our customers to build, innovate, and grow, collectively reshaping the e-commerce industry.

As an Application Security Engineer II at BigCommerce, you are a developing application security practitioner who can independently execute security assessments and partner effectively with engineering teams to improve secure development practices.

You have moved beyond entry-level execution and are comfortable leading well-scoped security reviews, performing application testing with minimal guidance, and providing actionable remediation advice. You are not yet responsible for broad program ownership or formal mentorship, but you are a dependable contributor who raises the security bar through strong technical execution.

What You’ll Do
  • Perform regular and ongoing penetration testing of BigCommerce’s evolving applications and services.

  • Conduct security code audits and participate in architectural and design reviews.

  • Review project technical designs and follow through implementation to ensure secure outcomes.

  • Triage and validate findings from SAST, DAST, and SCA tools (e.g., Checkmarx, Snyk).

  • Work directly with engineering teams to provide clear, practical remediation guidance.

  • Respond to application-related security incidents, providing technical analysis and support.

  • Assist in maintaining and improving internal security tooling and automation.

  • Utilize vulnerability and telemetry data to identify trends and support risk prioritization.

  • Contribute to improving AppSec documentation, standards, and secure coding guidance.

  • Advocate secure development practices across the BigCommerce ecosystem.

  • Conduct research to identify new attack vectors relevant to our platform.
     

Who You Are:
  • Bachelor’s degree in Computer Science, Engineering, MIS, or equivalent experience.

  • 2–4 years of experience in application security-related disciplines (code review, penetration testing, security engineering, DevSecOps).

  • 1–2 years of software development experience in PHP, Ruby, Java, Scala, or similar.

  • Strong understanding of web application security concepts, vulnerabilities, exploits, and prevention techniques.

  • Experience performing independent code reviews and security assessments.

  • Hands-on experience with SAST/SCA tools such as Checkmarx and Snyk.

  • Ability to explain security issues clearly and effectively to developers.

  • Strong written and verbal communication skills.

  • Experience working with globally distributed teams

Nice to Have
  • Security certification (CISSP, OSCP, GISP, or actively pursuing).

  • Experience contributing to internal security tooling or automation.

  • Familiarity with cloud environments (AWS, GCP).

  • Experience participating in bug bounty programs.

  • Exposure to DevSecOps and CI/CD integration practices.
     

Impact & Expectations

At this level, you are expected to:

  • Independently execute well-defined security assessments.

  • Deliver accurate, actionable remediation guidance.

  • Identify recurring vulnerability patterns and suggest improvements.

  • Demonstrate sound technical judgment within your scope.

  • Operate with limited supervision on day-to-day tasks.

  • Continue developing toward senior-level depth and influence.

#LI-KE1

#LIHybrid

(Pay Transparency Range: $75,559.00 - $127,784.00)

The exact salary will be dependent on the successful candidate’s location, relevant knowledge, skills, and qualifications.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the interview process, to perform essential job functions and to receive other benefits and privileges of employment. If you need an accommodation in order to interview at Commerce, please let us know during any of your interactions with our recruiting team.

Learn more about the Commerce team, culture and benefits at https://www.commerce.com/careers/

Protect Yourself Against Hiring Scams: Our Corporate Disclaimer 

Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.
Be advised:
Commerce does not offer jobs to individuals who do not go through our formal hiring process.
Commerce will never:

  • require payment of recruitment fees from candidates;

  • request personally identifiable information through unsanctioned websites or applications;

  • attempt to solicit money from you as part of the hiring process or as part of an employment offer;

  • solicit money to complete visa requirements as part of a job offer.

If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.

Top Skills

Checkmarx
Dast
Java
PHP
Ruby
Sast
Sca
Scala
Snyk
HQ

Commerce Austin, Texas, USA Office

Commerce Austin Office Office

11920 Alterra Parkway D11 / Suite 100, 8th Floor , Austin, TX, United States, 78758

Similar Jobs at Commerce

15 Hours Ago
In-Office
Austin, TX, USA
50K-75K Annually
Mid level
50K-75K Annually
Mid level
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
As a Business Operations Analyst I, you will collaborate with teams to ensure compliance, deliver excellent customer service, manage collections, and enhance operational efficiencies within e-commerce processes.
Top Skills: ImpartnerMarketoSalesforceZuora
15 Hours Ago
In-Office
Austin, TX, USA
78K-116K Annually
Mid level
78K-116K Annually
Mid level
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
The Technical Account Manager will manage a portfolio of clients, providing technical guidance, driving growth, and optimizing eCommerce strategies while collaborating with internal teams and ensuring customer success.
Top Skills: APIsCSSEcommerceHTMLJavaScript
Yesterday
In-Office
Austin, TX, USA
148K-250K Annually
Senior level
148K-250K Annually
Senior level
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
Senior individual-contributor product leader owning strategy, roadmaps, and measurable outcomes across multiple B2B product domains. Drive cross-functional initiatives, define platform-level capabilities, enable monetization and GTM, lead discovery through launch, and ensure enterprise-scale integration, configurability, and migration support.
Top Skills: Apis,Data Models,Systems Integration,Erp,Oms,Pim,Cpq,Edi,Middleware,Punchout

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account