Application Security Engineer

Apply now
  • year-experience +3 years place México/LATAM contract Remote/Full Time english Advanced
Description:

We are looking for an Application Security Engineer to identify and mitigate security risks throughout the application lifecycle proactively. This role will work closely with development and security teams to embed security into application design, development, and delivery.

The ideal candidate has strong hands-on experience in application security, penetration testing, secure code review, and threat modeling, along with a strong programming background. This role also has a strong focus on leveraging AI-powered tools, automation, and custom security agents to enable continuous and scalable security testing.

What will you do?

  • Perform secure code reviews across multiple technology stacks, including PHP, JavaScript/TypeScript, Java, Python, Go, and Clojure.
  • Conduct continuous security testing and penetration testing across web applications, APIs, and cloud environments.
  • Lead threat modeling sessions with development teams to identify security risks early in the development lifecycle.
  • Build and maintain AI-powered security agents, automation, and tooling for continuous security testing.
  • Triage, prioritize, and track application security findings while working directly with developers on remediation.
  • Define and maintain secure coding guidelines, security patterns, and security best practices.
  • Support compliance efforts related to PCI-DSS, SOC 2, and ISO 27001.
  • Stay current with emerging threats, attack techniques, vulnerabilities, and security research.
  • Provide security training and guidance to development teams.
  • Collaborate with Security, Development, and Operations teams to continuously improve application security.

Requirements:
  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience
  • 3+ years of experience in Application Security, Penetration Testing, or Secure Software Development.
  • Strong programming skills in one or more of the following: PHP, JavaScript/TypeScript, Java, Python, Go, or Clojure.
  • Hands-on experience performing penetration testing of web applications, APIs, and cloud environments.
  • Strong secure code review experience with the ability to identify vulnerabilities at the source-code level.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, Attack Trees, or similar.
  • Practical experience with security testing tools and methodologies, including SAST, DAST, SCA, IAST, and manual testing.
  • Experience using AI-powered tools for security testing and building automation scripts, AI agents, or custom security tooling.
  • Strong knowledge of OWASP Top 10, OWASP ASVS, CWE, and common attack vectors.
  • Understanding of cloud security practices across cloud-native and on-premises environments.
  • Familiarity with container security concepts, including Docker and Kubernetes.
  • Knowledge of PCI-DSS, SOC 2, and ISO 27001.
  • Strong communication and collaboration skills, particularly when working with developers on security remediation.
  • Advanced English-speaking
Nice to have:
  • Experience developing custom security tools, AI agents, or automation frameworks for continuous security testing at scale.
  • Experience with Infrastructure as Code security, particularly Terraform or CloudFormation.
  • Security certifications such as OSWE, OSCP, GWAPT, BSCP, CRTO, or CSSLP.
  • Familiarity with API security standards including OAuth 2.0, OpenID Connect, and JWT security.
  • Experience with bug bounty programs or responsible disclosure.
  • Software development background with a transition into application security.