What are the responsibilities and job description for the Application Security Engineer position at TPA technologies?
This is a Full Time, Direct Hire Position with our Private Equity client in Boston, MA
This role follows a hybrid work model, offering up to 18 remote workdays per quarter. For example, you could work in the office four days per week and take one remote day each week (based on a typical 13-week quarter), with approximately five additional remote days available to use as needed.
We are seeking an Application Security Engineer (ASE) to join a leading private equity client’s Security Engineering team. This individual will play a key role in advancing the organization’s application security program, partnering closely with engineering, platform, and risk teams to ensure secure software development practices across the enterprise.
This is a highly visible, cross-functional role focused on embedding security into the SDLC, improving secure coding practices, and safeguarding sensitive financial data, client information, and critical business systems.
Key Responsibilities
- Lead application security across the SDLC (code reviews, architecture, testing)
- Identify and remediate vulnerabilities across apps, APIs, and systems
- Perform threat modeling and SAST/DAST/SCA testing
- Define security standards, including for AI-assisted development tools
- Integrate security into CI/CD and promote DevSecOps practices
- Partner with engineering, risk, and compliance teams
- Support audits, pen testing, and incident response
- Secure and monitor third-party SaaS applications (SSPM)
- Track security metrics and improve program effectiveness
- Provide secure coding guidance and training
- Strong application security knowledge (e.g., OWASP Top 10)
- Experience securing web apps, APIs, and microservices
- Hands-on with SAST, DAST, and SCA tools
- Familiarity with AI coding tools (e.g., GitHub Copilot) and risks
- Proficiency in Java, Python, C#, or JavaScript
- Experience with cloud, containers, IaC, and DevSecOps
- Strong communication across technical and business teams
Preferred Qualifications
- Bachelor’s degree or equivalent experience
- Security certifications (CISSP, CSSLP, OSCP, etc.)
- Experience in regulated industries (finance, fintech, etc.)
- Knowledge of frameworks (SOC 2, SOX, PCI DSS, GDPR)
Salary : $120,000 - $155,000