Demo

Application Security Engineer

Cloud and Things
York, NY Full Time
POSTED ON 4/17/2026
AVAILABLE BEFORE 5/16/2026

Our goal is to solve problems and deliver results for our clients. At Cloud and Things, you can be a part of transforming the public sector’s IT environment. Our team is on the forefront of helping to solve the government''s most complex IT challenges. If you are seeking a role that offers the opportunity to work on rewarding projects, consider a career with Cloud and Things.  

*This is an exempt position. Salary commensurate with experience*

Overview:
Location: Hybrid – Brooklyn, NY
Salary: $125,000 - $140,000

We are seeking an Application Security Engineer who will support our client with ensuring security is integrated into all stages of software development. This role will be responsible for designing and building secure applications while working closely with application administrators who manage security tools and CI/CD pipelines. The ideal candidate for this role will have strong application development experience with a demonstrated understanding of web and mobile application architecture and security protocols.

Duties:

  • Establish and apply secure coding practices within the development team.
  • Define and enforce secure coding standards for Java, .NET, Python, and JavaScript applications.
  • Conduct secure design and architecture reviews for new and legacy systems.
  • Educate developers on secure coding practices, authentication/authorization best practices, and common application vulnerabilities.
  • Apply protections aligned with:
    • OWASP Top 10
    • OWASP API Security Top 10
  • Design and implement secure REST APIs and web services.
  • Implement secure authentication/authorization using:
    • SAML2
    • OIDC
    • OAuth2
  • Secure Java and JavaScript applications, including:
    • Spring Boot
    • React
  • Ensure secure handling of tokens, sessions, and secrets.
  • Collaborate with App Admins and Security team to integrate applications into WAFs, load balancers, and other security monitoring tools

Mandatory Qualifications:
  • Associates Degree or combination of experience and education.
  • 4 years of experience in secure application development.
  • 1 year of experience with hands-on software development experience.
  • 4 years demonstrating an understanding of:
    • Web and mobile application architecture
    • Internet protocols (HTTP, HTTPS, WebSockets)
    • REST API security
  • Expertise in SAST, DAST, and SCA concepts (understanding results and remediation), in collaboration with App Admins.
  • Familiarity with security tools such as Veracode, Burp Suite, Zimperium, Prisma, Rapid7.
  • Experience applying NIST 800-53 and 800-171 controls at the application design level.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work independently within a development-focused team.

Desirable Qualifications: 
  • Experience with containerized applications (Docker, Kubernetes).
  • Knowledge of:
    • Core Java, J2EE, Spring Boot
    • React, AngularJS, HTML5, CSS, JavaScript
  • Experience designing secure GIS systems.
  • Familiarity with public safety or emergency response systems.

Cloud and Things complies with all applicable federal, state, and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws. 

AI-Assisted Resume Evaluation Notice
Cloud and Things – Talent Management

Notice to Candidates
Cloud and Things utilizes artificial intelligence (AI) tools to assist our recruiting team in evaluating candidate applications for streamlining; consistency, efficiency, and thoroughness.  All hiring decisions are ultimately made by our human recruiting professionals.

How AI Is Used
Our AI tools assist by:
  • Analyzing resumes against job requirements
  • Supporting our recruiters in candidate data evaluation
  • Ensuring consistent review standards across all applications
Important: AI serves as a support tool only. As noted above, all candidate selection and hiring decisions are made by experienced human recruiters. Your unedited resume will be processed by our AI tools as part of this evaluation.

Your Data and Privacy

Cloud and Things Data Handling:
  • Your information is processed securely and used exclusively for recruitment purposes
  • Cloud and Things may store your resume in our Applicant Tracking System (ATS) indefinitely for future job matching opportunities
    • You may opt out of long-term ATS storage by emailing your name  and your request to opt out of storing your resume in the ATS to: security@cloudandthings.com
  • All personal information is handled confidentially in accordance with our privacy policy

AI Tool Data Processing:
  • AI processing data is retained for a maximum of 90 days, after which it is deleted
  • All data sent to AI tools is encrypted in transit and at rest
  • AI tools comply with applicable privacy laws including GDPR and CCPA
  • Personal data is anonymized or minimized wherever possible during AI processing


Your Participation
By submitting your application, you acknowledge this notice and consent to AI-assisted evaluation as part of our recruitment process. You may opt out only by choosing not to submit your resume for consideration.

Salary : $125,000 - $140,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Engineer?

Sign up to receive alerts about other jobs on the Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$73,727 - $94,067
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$90,707 - $120,959
Income Estimation: 
$91,486 - $118,193
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cloud and Things

  • Cloud and Things Jersey, NJ
  • Our goal is to solve problems and deliver results for our clients. At Cloud and Things, you can be a part of transforming the public sector’s IT environmen... more
  • Just Posted

  • Cloud and Things Brooklyn, NY
  • Our goal is to solve problems and deliver results for our clients. At Cloud and Things, you can be a part of transforming the public sector’s IT environmen... more
  • Just Posted

  • Cloud and Things York, NY
  • Our goal is to solve problems and deliver results for our clients. At Cloud and Things, you can be a part of transforming the public sector’s IT environmen... more
  • Just Posted

  • Cloud and Things Brooklyn, NY
  • Our goal is to solve problems and deliver results for our clients. At Cloud and Things, you can be a part of transforming the public sector’s IT environmen... more
  • Just Posted


Not the job you're looking for? Here are some other Application Security Engineer jobs in the York, NY area that may be a better fit.

  • OpenAI York, NY
  • About The Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team... more
  • 7 Days Ago

  • associatedpress.valhalla.stage York, NY
  • The Associated Press is an independent global news organization dedicated to factual reporting. Founded in 1846, AP today remains the most trusted source o... more
  • 12 Days Ago

AI Assistant is available now!

Feel free to start your new journey!