Citrin Cooperman Logo

Citrin Cooperman

Senior Application Security Engineer, Development (52213)

Posted 7 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
120K-180K Annually
Senior level
Remote
Hiring Remotely in USA
120K-180K Annually
Senior level
Design, implement, and operate application and cloud security controls across the SDLC. Integrate security tooling (SAST/DAST/SCA/IaC), secure CI/CD pipelines, run secure code reviews and threat modeling, deploy and manage cloud security posture and CNAPP tooling, and partner with engineering teams to remediate vulnerabilities and build secure, repeatable patterns.
The summary above was generated by AI

Citrin Cooperman offers a dynamic work environment, fostering professional growth and collaboration. We’re continuously seeking talented individuals who bring a problem-solving mindset, fresh perspectives, and sharp technical expertise. We know you have choices, so our team of collaborative, innovative professionals are ready to support your professional development. At Citrin Cooperman, we offer competitive compensation and benefits and most importantly, the flexibility to manage your personal and professional life to focus on what matters most to you!

We are seeking a Senior Application Security Engineer to join our Information Security team within the Information Technology department. Candidate would be responsible for strengthening the security posture of our applications and cloud infrastructure. This role sits at the intersection of software engineering, cloud architecture, and security, with a focus on empowering developers to build secure software while hardening our cloud environment. You will design, implement, and operate security tooling across the software development lifecycle and champion a security first culture across engineering teams.

Responsibilities are, but not limited to:

Application & Developer Security

  • Integrate security controls into the developer workflow, including SAST, DAST, SCA, secrets scanning, and IaC scanning.
  • Partner with development teams to remediate vulnerabilities and provide secure coding guidance and training.
  • Investigate, prioritize, and drive remediation of application security findings.
  • Conduct secure code reviews, security assessments, and vulnerability analysis.
  • Build self-service security tooling and repeatable security design patterns that make the secure path the easy path for developers.
  • Create and maintain security standards, procedures, and best practices that scale across teams.

Cloud Security

  • Design and implement security controls across Azure workloads, including identity (Entra ID), networking, encryption, and key management.
  • Configure and manage cloud-native security services.
  • Establish and enforce cloud security posture standards, compliance baselines, and guardrails using policy-as-code (e.g., Azure Policy).
  • Monitor, triage, and respond to cloud security findings and misconfigurations.
  • Deploy, tune, and operate CNAPP tooling (e.g., Wiz, Prisma Cloud, Microsoft Defender for Cloud, Aqua) covering CSPM, CWPP, CIEM, and container/Kubernetes security.
  • Prioritize and drive remediation of cloud and workload risks based on business context and exploitability.
  • Build dashboards and reporting to communicate cloud risk to technical and executive stakeholders.
  • Detect anomalies, investigate alerts, and respond to evolving threats across our cloud ecosystems.
  • Partner with product and engineering teams to integrate security into application design and development.
  • Lead threat modeling exercises and identify practical security solutions for complex systems.

CI/CD & SDLC Pipeline Security

  • Embed automated security gates and controls into CI/CD pipelines (e.g., GitHub Actions, Azure DevOps, GitLab, Jenkins).
  • Work with development team to secure the software supply chain, including artifact signing, dependency management, and SBOM generation.
  • Harden build environments, pipeline credentials, and deployment processes.
  • Define and measure security metrics and KPIs across the SDLC.
Qualifications

The ideal candidate must:

  • Have a bachelor’s degree in computer science, cybersecurity, information security, or related field, or equivalent experience.
  • Have relevant certifications (e.g., Azure Security Engineer Associate, CKS, GIAC, OSCP).
  • Have a 5+ years of experience in Application Security, Secure Software Development, DevSecOps, Security Engineering, or a related cybersecurity discipline.
  • Have hands-on experience securing major cloud environments (AWS, Azure, GCP) and services.
  • Possess a strong understanding of application security concepts (OWASP Top 10, secure SDLC, threat modeling).
  • Have experience integrating security tooling into CI/CD pipelines.
  • Be proficient with at least one scripting or programming language (e.g., Python, PowerShell, Go).
  • Have familiarity with infrastructure-as-code (Terraform, Bicep, ARM) and containerization (Docker, Kubernetes).
  • Have a strong security-first mindset.
  • Be analytical and detail oriented.
  • Have excellent communication skills.
  • Be collaborative and accountable.

Similar Jobs

An Hour Ago
In-Office or Remote
United States
Entry level
Entry level
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Handle inbound and outbound mortgage collections calls, review account status, collect payments, evaluate customer finances, negotiate repayment solutions, and document account actions. Ensure compliance with customer information security, debt collection, and mortgage regulations while meeting quality, productivity, and operational targets. The role includes extensive training and operates on a hybrid schedule with three days onsite and two days remote in Irving, Texas.
Top Skills: Ai SimulationsDigital Phone SystemsExcelMicrosoft WordMsp/Black Knight
2 Hours Ago
Remote or Hybrid
179K-322K Annually
Senior level
179K-322K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Leads a specialized casualty claims team managing severe-exposure portfolios, complex litigation, coverage issues, reserves, settlements, vendors, and claim-handling protocols. Partners with legal, underwriting, actuarial, reinsurance, and other stakeholders to develop strategies, monitor litigation trends, address legal system abuse, manage financial outcomes, and improve operational performance. Coaches claims leaders, oversees staffing and portfolio capacity, and presents strategic recommendations to executives and business partners.
Top Skills: Guidewire Claims System
4 Hours Ago
Remote or Hybrid
83K-157K Annually
Senior level
83K-157K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Own model observability for Auto Physical Damage data science products, including traditional ML and GenAI/LLM systems. Build monitoring pipelines, dashboards, metrics, thresholds, alerts, and remediation documentation. Detect drift, performance degradation, anomalies, and data-quality issues; support MLOps, LLMOps, governance, compliance, and audit reporting. Analyze business outcomes, identify improvement opportunities, and communicate model health findings to technical and non-technical stakeholders.
Top Skills: AWSAzureEmblemExcelGCPLlmopsMlopsPowerPointPythonSASSQLStreamlitTableauVBA

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account