SlipstreamJobsFresh Startup & VC-Backed Jobs

Application Security Engineer

Awardco - Lindon, UT, United States - In-office - posted 2026-07-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Awardco is seeking an Application Security Engineer to build and mature their application security program as the company scales its SaaS platform. You will partner closely with product, engineering, and operations teams to design, build, and ship secure features without slowing down innovation. Key responsibilities include embedding security checkpoints into planning, design, development, testing, and release processes. You'll facilitate threat modeling for new services, APIs, and integrations, and recommend secure patterns and architectures for multi-tenant SaaS and cloud-native components. You'll perform targeted secure code reviews for high-risk features, configure and tune SAST, DAST, dependency, and container scanning tools, and integrate AI-assisted application security tools like GitHub Advanced Security, Snyk, and Wiz into developer workflows. You'll help define and maintain secure coding standards across engineering teams, triage and prioritize vulnerability remediation, and advise on secure use of authentication, authorization, cryptography, and data protection controls. A major focus is enabling developers through secure coding guidance, training, and a Security Champions program. You'll create playbooks, checklists, and self-service guidance to help developers ship secure code independently, champion a "secure by default" mindset, and assist with incident investigation and remediation. Required qualifications include 6+ years in application security or software engineering with strong security focus for web applications or APIs. You need hands-on experience securing cloud-hosted, multi-tenant SaaS applications on major public cloud platforms, deep familiarity with OWASP Top 10 and common vulnerability classes, and experience with modern programming languages (JavaScript/TypeScript, Java, C#, Python, Go). You should have hands-on experience with SAST, DAST, dependency scanning, and modern AI-assisted security tooling, plus solid understanding of CI/CD pipelines and security integration. Strong communication skills, ability to balance risk with delivery timelines, and demonstrated mentoring ability are essential.

Similar roles