MeridianLink

Application Security Engineer

Remote
Python C# Java PowerShell AWS Azure GCP API Docker Kubernetes Burp Suite Kali Linux Metasploit WebInspect OWASP Top 10
Description

Application Security Engineer

Department: General & Administrative

Location: US Remote

Compensation: $98.9K – $134.5K

Employment Type: FullTime

Job Description

The Application Security Engineer plays a key role in MeridianLink’s application security program, helping safeguard internally developed software and client data. This role is responsible for assessing the security of applications and supporting infrastructure to strengthen MeridianLink’s overall security posture.

The Application Security Engineer works closely with development, engineering, and product teams to identify and address security risks throughout the software development lifecycle. This is a highly technical, hands-on position focused on evaluating and securing applications across multiple layers of the technology stack. The individual in this role applies an adversarial mindset to identify vulnerabilities, assess emerging threats, and drive improvements as the threat landscape evolves.

Security and trust are foundational to MeridianLink’s commitment to its customers. This role supports and advances a security-by-design approach across applications and services.

Expected Duties

  • Support application security initiatives while collaborating with senior application security engineers and other security team members as needed.

  • Coordinate third-party security assessments of application, network, and data services supporting MeridianLink’s products.

  • Translate security testing results into clear, business-impact risk assessments, providing developers and product owners with actionable guidance on real-world exposure and remediation priorities.

  • Participate in application security reviews and threat modeling activities, including static and dynamic testing.

  • Interpret business and technical requirements to support the design and development of secure applications and infrastructure.

  • Perform automated and manual vulnerability assessments on a recurring basis using industry-standard tools to validate findings across applications, cloud infrastructure, and endpoints.

  • Provide input into the design and implementation of application security solutions that enforce consistent security controls across applications and products.

  • Conduct remediation validation of identified security findings, verifying fixes are effective and confirming additional instances have been identified and resolved

  • Design, build, test, document, deploy, monitor, and support application security and security operations tooling.

  • Automate security testing and vulnerability management processes where appropriate.

  • Proactively identify opportunities to improve security architecture and recommend enhancements to address evolving threats.

  • Partner with developers to promote secure coding practices and integrate security controls into the SDLC.

  • Collaborate cross-functionally to implement and support automated static and dynamic testing within CI/CD pipelines.

  • Serve as a security point of contact for development and engineering teams, supporting the remediation of identified risks and vulnerabilities.

  • Review new or proposed applications and provide guidance on secure architecture and design considerations.

  • Support regulatory and compliance-related initiatives as required.

  • Act as a subject matter expert in application security, secure coding practices, and penetration testing.

  • Participate in the internal CSIRT on-call rotation and support incident response activities as needed.

Qualifications: Knowledge, Skills, and Abilities

The Application Security Engineer performs moderately complex responsibilities independently while supporting peers and leadership on more advanced initiatives. This role requires the ability to apply established policies and procedures to resolve a wide range of security-related issues while continuing to develop technical expertise.

  • Bachelor’s degree and 2–4 years of related experience, or equivalent practical experience.

  • Experience using industry-standard application and security testing tools, including Burp Suite, Kali Linux, Metasploit, and WebInspect.

  • Experience performing static and dynamic application security testing (SAST/DAST).

  • Experience conducting threat modeling and a solid understanding of common application security vulnerabilities (OWASP Top 10, SANS).

  • Experience with programming or scripting languages such as Python, C#, Java, or PowerShell, and familiarity with modern web technologies.

  • Hands-on experience securing cloud-based applications and services in AWS, Azure, or GCP environments.

  • Strong understanding of application security practices and CI/CD integration, with experience securing APIs and web applications.

  • Experience performing security design and architecture reviews for new technologies and applications.

  • Understanding of infrastructure as code, automation, container security, and orchestration technologies.

  • Strong analytical and problem-solving skills, with the ability to work across development and security disciplines.

  • Ability to clearly communicate security concepts to both technical and non-technical stakeholders.

MeridianLink
MeridianLink

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say