Application Security Engineer

CivicPlus, LLC

Remote, United StatesFull-timeRemotePosted 7 days ago

Get more Security Engineer openings

A short daily email when similar roles appear in Remote. No account needed.

Your Impact

As an Application Security Engineer you will help embed security across CivicPlus's software development lifecycle, leading application security testing and vulnerability remediation to protect the products local governments and residents rely on.

About CivicPlus

At CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured.

What You'll Do

As an Application Security Engineer, you will:

  • Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC).
  • Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC.
  • Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements.
  • Coordinate external, independent penetration testing of production environments.
  • Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST).
  • Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats.

What We're Looking For

We know that excellent candidates come from diverse backgrounds. Even if you don't meet 100% of the listed requirements, we encourage you to apply!

Preferred Qualifications:

  • 3–7 years of experience in application security, secure development, penetration testing, or a related field.
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST).
  • Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations.
  • Security+, GSEC, GSSP, or equivalent certification.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred).
  • Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments.
  • AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality.
  • Demonstrated ability to effectively use AI tools to enhance productivity and outcomes.

Compensation and Benefits

  • Estimated Salary Grade Range: $70,300 - $101,300
    • Anticipated Hiring Range: $80k - $90k.
    • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience and is based on a 40-hour work week.
  • Benefits: Comprehensive health insurance, dental insurance, vision insurance, Flexible Time Off, 401(k) plan, and more.

Our Hiring Process

  1. Introductory call with Talent Acquisition
  2. Interview with the Hiring Manager
  3. Panel Interview with CivicPlus team members, including an interview project activity
  4. Offer

Note: The process may vary slightly depending on the role.

Additional Information

  • CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US.
  • This position will remain open until October 7, 2026 at 4pm CT. We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team.
  • At CivicPlus, we embrace AI and automation as tools that help people work smarter, move faster, and focus on higher-value work that strengthens communities. We encourage thoughtful, responsible use of technology to improve efficiency, support innovation, and enhance the employee and customer experience—while keeping human judgment, collaboration, and accountability at the center of what we do.

Equal Opportunity Commitment

CivicPlus is proud to be an Equal Employment Opportunity employer. We celebrate and support diversity for the benefit of our employees, products, clients, and communities. Reasonable accommodations are available during the interview process.

The average job posting receives 250 applications.

Stand out by tailoring your resume to this specific role. Our AI resume builder highlights the skills and experience that matter most to this employer.

Frequently asked questions

Who is hiring for Application Security Engineer at CivicPlus, LLC?+
CivicPlus, LLC is actively hiring for this Application Security Engineer role. Click "Apply Now" to submit your application directly on CivicPlus, LLC's careers page — Careeronaut doesn't charge employers or candidates for referrals.
When was this Application Security Engineer role posted?+
This listing was first posted on 2026-09-17. We pull the latest copy from the source feed daily, and any role that's taken down gets removed from Careeronaut within seven days so you don't waste time on stale listings.
How should I apply to this Application Security Engineer role?+
Start by tailoring your resume to the posting — most applicants send generic CVs and the first filter recruiters use is keyword relevance. Careeronaut's AI does this automatically: paste the job description, get a matched resume in under a minute, and download as PDF or DOCX.
Where can I find more Security Engineer jobs in Remote?+
Browse all open security engineer roles in Remote on the listing pages linked below. You can filter by salary, remote-friendly, and posting date.