For Employers

Sun King

Application Security Engineer

Posted an hour ago
2-5 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The Application Security Engineer will own the end-to-end security posture of the product platform, including mobile apps, APIs, and cloud infrastructure. Responsibilities include performing threat modeling, penetration testing, vulnerability assessments, and integrating security tools into the CI/CD pipeline.

Application Security Engineer

Department: Global Analytics and Technology

Employment Type: Permanent - Full Time

Location: India



Description

Job location: Remote

About the role:
We are looking for an Application Security Engineer to own the end-to-end security posture of our
product platform — spanning mobile applications, REST APIs, microservices, cloud infrastructure, and
third-party integrations. In this role, the Application Security Engineer will be involved into the
product and engineering lifecycle early, shaping secure design decisions before code is written, and
validating them through rigorous assessment.



What you will be expected to do

● Own application security responsibility for assigned business functions by performing threat
modeling, architecture reviews, penetration testing, secure coding programs, and vulnerability
management.
● Perform manual penetration testing and vulnerability assessments on web applications, APIs,
and android mobile applications.
● Perform security reviews for AI‐native products, models, pipelines, and inference services.
● Onboard applications into the SSDLC program and be a security point of contact for the
application product.
● Own security incident response for product-layer issues, define remediation plans, and track
fixes through to closure.
● Integrate and tune SAST/DAST/IAST/SCA tools in CI/CD, create custom rules where needed and
actively triage false positives.
● Review and harden cloud infrastructure — Kubernetes RBAC, pod security, network policies,
Istio service mesh, Keycloak/OIDC configurations, and IAM across AWS, DigitalOcean, GCP, and
Firebase.
● Communicate vulnerabilities and risk clearly to developers, product managers, and leadership
— in language that drives actionable results.
● Conduct application security training for engineers, product managers etc.





You might be a strong candidate if you have/are

●Bachelor's degree in Computer Science, Cyber Security, or any related fields.
● At least 2 years of hands-on application security experience, ideally in product‐based or SaaS
companies working directly with engineering teams.
● Good understanding of OWASP Top 10, API Security Top 10, and common authorization flaws
including BOLA, BFLA, and privilege escalation.
● Experience in manually testing web apps, APIs, and Android apps, manual code reviews
(beyond just running tools).
● Familiarity with OAuth2, OIDC, JWT, and typical misconfigurations in providers such as Keycloak
and Firebase.
● Experience integrating and tuning SAST/DAST (and optionally SCA/IAST) tools within CI/CD
pipelines.
● Exposure to cloud‐native security: Kubernetes, containers, service mesh (Istio mTLS and
policies), and IAM concepts across at least one major cloud provider.
● Experience with Cloudflare WAF, perimeter security scanning, and/or red‐team testing is a
plus.
● Familiarity with AI/LLM security risks (e.g., OWASP LLM Top 10).
● Practical experience implementing guardrails, prompt validation, output filtering, or other
safety controls in production AI features, or assessing insecure use of third‐party AI APIs.
● Ability to script/automate (e.g., Python, Bash) to streamline testing, data collection, and
reporting.
● Interest in or experience with building AI based security tools that improve coverage or reduce
manual toil.


What Sun King offers

  • Professional growth in a dynamic, rapidly expanding, high-social-impact industry
  • An open-minded, collaborative culture made up of enthusiastic colleagues who are driven by the challenge of innovation towards profound impact on people and the planet.
  • A truly multicultural experience: you will have the chance to work with and learn from people from different geographies, nationalities, and backgrounds.
  • Structured, tailored learning and development programs that help you become a better leader, manager, and professional through the Sun King Center for Leadership.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Assets & Compliance Administrator

Full Time Australia 76000 - 96000 per year Software Development

SAP FICO Solution Architect, Public Cloud

Full Time Canada $175K - $205K per year Software Development

Senior Systems Engineer (ASR - Hardware/OnPrem)

Full Time New Zealand 120K - 150K per year Software Development

Solutions Architect

Full Time United States $170K - $218K per year Software Development

Senior Compute Network Engineer

Full Time Australia, Spain Software Development

Forward Deployed Engineer

Full Time United States $120K - $200K per year Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Application Security Engineer

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified