Talent.com
Senior Application Security Engineer (Hybrid - US)
Senior Application Security Engineer (Hybrid - US)Energy Solutions • Portland, OR, United States
Senior Application Security Engineer (Hybrid - US)

Senior Application Security Engineer (Hybrid - US)

Energy Solutions • Portland, OR, United States
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus on the big impacts. And we believe that market-based programs can be a powerful force to deliver large-scale energy, carbon, and water-use savings. Since 1995, we've harnessed that power to offer proven, performance-based solutions for our utility, government, and institutional customers.

Summary :

We are seeking a Senior Application Security Engineer who will work with our development team to manage security and risk on our internally developed applications. The engineer will make risk-based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms. This role is primarily focused on execution and consulting but should be familiar with roadmap and strategy and contribute where appropriate. Must have the ability to read, review, and make recommendations on secure Django / Python patterns.

Responsibilities :

  • Contribute to the application security roadmap for our internal applications-prioritize risks and sequence work across codebases, application layer, and DevOps.
  • Consult with engineers to communicate requirements, create actionable tickets / acceptance criteria, and drive adoption.
  • Conduct pull request reviews focused on security, provide guidance on refactors, and approve / deny with clear rationale.
  • Serve as a steward for SAST / scanning : review static code scan results, triage findings, eliminate noise, and drive remediation with owners.
  • Build reference implementations in Django / Python (i.e. authentication patterns, input validation, secrets handling, rate limiting, geo-based access) without direct responsibility for production feature development.
  • Map SOC 2 / NIST to engineering work : translate requirements into stories, controls, and automated evidence in CI / CD.
  • Threat modeling & architecture : navigate libraries / architectures and document secure patterns (ADRs / RFCs) that teams follow.
  • Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.
  • Collaborate with software developers and code base leads.
  • Act as a liaison between technical requirements from the business (i.e. security, privacy, compliance) and development teams.
  • Participate as a subject matter expert in security architecture, including new designs and design reviews.
  • Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.
  • Review architecture and compliance-related code changes for security impact.
  • Ensure compliance with all company security policies and standards.
  • Manage and maintain all security related tickets, including recommendations, testing, and validation.

Qualifications :

  • Minimum of 5 years' experience in application security experience.
  • Practice and implementation with Django / Python with a clear application-security focus (production experience and impact, not theory).
  • Engineering background (software or DevOps / SRE) with the ability to read / modify code, review PRs, and build PoCs.
  • Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
  • Experience embedding secure SDLC into Git-based workflows and CI / CD (pre-commit, pipeline gates, policy-as-code).
  • Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.
  • Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging / monitoring).
  • Clear, persuasive communication (verbal and written) and prioritization.
  • Excellent time management skills with a proven ability to meet deadlines.
  • Excellent interpersonal and negotiation skills.
  • Preferred Qualifications :

  • Bachelors degree in Computer Science or equivalent work experience preferred.
  • CISSP, GIAC, Security+, AWS Security and other related security certifications.
  • Prior experience reporting to or partnering with a security architect, or being the app-sec lead in a smaller org.
  • Strong organizational skills and attention to detail.
  • Strong analytical and problem-solving skills.
  • Ability to prioritize tasks according to severity
  • Ability to adapt to the needs of the organization
  • Proficient in AWS Security services (I.E. Cloud watch, Guard Duty)
  • The salary range for this role is $119,100 - $147,400 / annually, with a target compensation of $119,000 to $131,600 based on experience and qualifications.

    Compensation is commensurate with experience and includes a generous retirement package. Energy Solutions provides an excellent benefits package including medical, dental and vision insurance, other pre-tax contribution plans and an Employee Stock Ownership Plan (ESOP).

    AI Use

    At Energy Solutions we believe in the importance of authentic interactions and equitable opportunities. We base our candidate selection on one's own skills, knowledge, and experience. To ensure the integrity and fairness of our interview process, the use of artificial intelligence (AI) tools (including Generative AI) or other means to generate or assist with responses during interviews is strictly prohibited. This practice supports our commitment to create a transparent and equitable space where skills, knowledge and experience skills can truly shine.

    Equal Opportunity Employer

    Energy Solutions is an affirmative action-equal opportunity employer and prohibits discrimination and harassment of any type. We afford equal employment opportunities to employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristics protected by law. Energy Solutions conforms to the spirit as well as to the letter of all applicable laws and regulations.

    Office Locations and a Remote Workforce

    Energy Solutions operates as a predominantly remote workforce with offices in six different locations . Employees who reside within 40 miles of an office (except New York) will be assigned to that location, though in-office attendance requirements may vary by team. At this time, we are not accepting applications from candidates residing in the following states : Delaware, Kentucky, Mississippi, Montana, Nebraska, North Dakota, and Wyoming.

    Background Check Information

    Information will be requested to perform the compulsory background check. A drug screen and authorization to work in the U.S. indefinitely are preconditions of employment. Energy Solutions is an equal opportunity employer.

    Reasonable Accommodations

    Energy Solutions is committed to providing access and reasonable accommodation for individuals with disabilities. If you require accommodations in completing this application, interviewing, and / or completing any pre-employment testing, or otherwise participating in the employee selection process, please email accommodation@energy-solution.com .

    Privacy Notice for Job Applicants

    serp_jobs.job_alerts.create_a_job

    Application Security Engineer • Portland, OR, United States

    Job_description.internal_linking.related_jobs
    Lead, Assembler I, Optics - 1st Shift

    Lead, Assembler I, Optics - 1st Shift

    SigSauer • Tualatin, OR, US
    serp_jobs.job_card.full_time
    For over 250 years SIG SAUER, Inc.American ingenuity, German engineering, and Swiss precision.Today, SIG SAUER is synonymous with industry-leading quality and innovation which has made it the brand...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Substation Protection and Control Engineer

    Senior Substation Protection and Control Engineer

    Leidos Inc • Portland, OR, United States
    serp_jobs.job_card.full_time
    Looking for an opportunity to make an impact?.Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Professional

    Security Professional

    Allied Universal® • Happy Valley, OR, US
    serp_jobs.job_card.full_time
    Allied Universal®, North America’s leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Risk Engineer - Pacific Northwest Target Segments

    Risk Engineer - Pacific Northwest Target Segments

    Crum & Forster • Portland, OR, US
    serp_jobs.job_card.full_time
    Risk Engineer Loss Control Specialist Pacific Northwest.The Risk Engineer Loss Control Specialist is responsible for delivering risk management and safety services to policyholders and underwrit...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    GSOC Lead (49791)

    GSOC Lead (49791)

    Inter-Con Security Systems • Beaverton, OR, US
    serp_jobs.job_card.full_time +1
    Founded in 1973, Inter-Con Security Systems, Inc.US-owned security company, providing integrated security solutions to government and commercial customers on four continents.Inter-Con remains under...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Software Engineer, Platform - Hillsboro, USA

    Software Engineer, Platform - Hillsboro, USA

    Speechify • Hillsboro, OR, US
    serp_jobs.job_card.full_time
    The mission of Speechify is to make sure that reading is never a barrier to learning.Over 50 million people use Speechify's text-to-speech products to turn whatever they're reading – ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    System Engineer (Radar)

    System Engineer (Radar)

    Corvid Technologies LLC • Portland, OR, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Corvid Technologies is looking to add an experienced Systems Engineer for the X-Band Transportable Radar (XTR) to support the Missile Defense Agency (MDA). This system is based on-board the Pacific ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30
    Lead Engineer, Applications - Edifecs / QConnect - Remote

    Lead Engineer, Applications - Edifecs / QConnect - Remote

    Molina Healthcare • Vancouver, WA, United States
    serp_jobs.filters.remote
    serp_jobs.job_card.full_time
    Designs and builds company specific enterprise application systems and technology expertise across multiple disciplines.Applies and promotes key principles (e. Considers business problems “end-to-en...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Specialist

    Security Specialist

    Allied Universal® • Happy Valley, OR, US
    serp_jobs.job_card.full_time
    Allied Universal®, North America’s leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Target Security Specialist

    Target Security Specialist

    Target • Vancouver, WA, US
    serp_jobs.job_card.full_time
    The starting hourly rate is $20.Working at Target means helping all families discover the joy of everyday life.Target's values and culture bring that vision to life. Assets Protection (AP) teams fun...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Software Engineer - Risk Onboarding

    Senior Software Engineer - Risk Onboarding

    Mercury • Portland, OR, United States
    serp_jobs.job_card.full_time
    Senior Software Engineer - Risk Onboarding.San Francisco, CA, New York, NY, Portland, OR, or Remote within Canada or United States. Are you fascinated by shows like Breaking Bad or Ozark and wonder ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    AI Security Engineer

    AI Security Engineer

    Fisher Investments • Camas, Washington, United States
    serp_jobs.job_card.full_time
    This job is with Fisher Investments, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.The O...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Electronics Engineering

    Electronics Engineering

    Navy • Lake Oswego, OR, United States
    serp_jobs.job_card.full_time
    ABOUT The most secretive of Navy vessels, a submarine requires a select community of specially trained professionals to operate its classified, highly advanced hardware. The Sailors in the Submarine...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Application Developer

    Senior Application Developer

    Fisher Investments • Camas, Washington, United States
    serp_jobs.job_card.full_time
    This job is with Fisher Investments, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.It's ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Full-Stack Engineer - Risk Experience

    Senior Full-Stack Engineer - Risk Experience

    Mercury • Portland, OR, United States
    serp_jobs.job_card.full_time
    Senior Full-Stack Engineer - Risk Experience.San Francisco, CA, New York, NY, Portland, OR, or Remote within Canada or United States. Soaring high above the Gardon River, the Pont du Gard is a maste...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Alarm Installation & Service Technician

    Security Alarm Installation & Service Technician

    Topsarge Business Solutions • Portland, OR, US
    serp_jobs.job_card.full_time
    We are seeking a field-based technician to support a federal contract for the installation, testing, and maintenance of panic and intrusion alarm systems at Department of Veterans Affairs (VA) outp...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Senior Engineer, Implant

    Senior Engineer, Implant

    1010 Analog Devices Inc. • Beaverton, OR, United States
    serp_jobs.job_card.full_time +1
    NASDAQ : ADI ) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, and software technologie...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Electronic Warfare Specialist

    Electronic Warfare Specialist

    United States Army • Portland, OR, United States
    serp_jobs.job_card.full_time
    ELIGIBLE FOR UP TO A $16K SIGNING BONUS.Talk to your recruiter for details.As an Electromagnetic Warfare Specialist, you'll plan and execute electronic warfare operations.You'll be trained to detec...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Sr Sales Application Engineer

    Sr Sales Application Engineer

    BorgWarner • Wilsonville, OR, US
    serp_jobs.job_card.full_time
    Sr Sales Application Engineer For New Business Acquisition.The Sr Sales Application Engineer For New Business Acquisition is responsible for driving revenue growth, managing key customer relationsh...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Lead Specialist 1 (47501)

    Lead Specialist 1 (47501)

    Inter-Con Security Systems • Beaverton, OR, US
    serp_jobs.job_card.full_time +1
    Founded in 1973, Inter-Con Security Systems, Inc.US-owned security company, providing integrated security solutions to government and commercial customers on four continents.Inter-Con remains under...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted