Application Security Engineer

4 days ago


Atlanta, Georgia, United States Stefanini North America and APAC Full time

Details:
Job Description

Stefanini Group is hiring
Exciting opportunity awaits, let us help you get started

Click Apply now or you may call: / email: Manisha Singh ) for faster processing

*Position Summary*
As a key member of our Internal Product Security Engineering team, you will lead penetration-testing engagements for high-scale web applications and APIs, validating security controls and uncovering exploitable weaknesses. In parallel, you will conduct structured threat-modeling workshops and security-design reviews for new features and services, managing each engagement from scoping to remediation follow-up in close partnership with engineering and cross-functional stakeholders. The insights you provide will drive prompt fixes and shape the organization's long-term security roadmap.

*Key Responsibilities*

  • Penetration Testing
  • Plan, execute, and document manual and tool-assisted tests for enterprise-scale web apps and REST/GraphQL/gRPC APIs.
  • Demonstrate exploitation paths (auth / logic / data exposure) and develop proofs-of-concept.
  • Retest remediations and deliver clear, prioritized reports.
  • Threat Modeling & Security Design Review
  • Facilitate formal and informal Threat Modeling using STRIDE-like frameworks or Attack-Tree sessions for new or significantly modified services.
  • Produce risk artefacts, recommend mitigations, and track closure of findings.
  • Security Engineering & Advocacy
  • Champion secure-by-default patterns (least privilege, IaC hardening, SDL best practices) across the SDLC.
  • Contribute to internal security tooling and CI/CD guardrails.

Job Requirements

Details:
Requirements:

  • Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.
  • 4 + years in product or application security engineering with hands-on web/API penetration-testing work.
  • Expertise with a leading pentest platform (Burp Suite Pro, OWASP ZAP, Nuclei, etc.).
  • Scripting/automation ability in Python, Go, or similar; quick at reading unfamiliar codebases.
  • Practical experience with STRIDE or comparable threat-model frameworks.
  • Familiarity with cloud-native environments (microservices, Kubernetes, serverless).
  • Communication: Exceptional written and verbal skills for both technical and non-technical audiences.

*Preferred Qualifications*

  • Offensive-security certifications (OSCP, OSWE, OSWA, BSCP).
  • Secure-coding experience in languages such as: Java, , C#, Python, or Rust.
  • Experience in security controls for cloud platforms such as AWS, Azure, or Google Cloud.
  • Open-source contributions, bug-bounty recognitions, or CTF placements.
  • Exposure to mobile or desktop application security.
  • Knowledge of or interest in AI security controls and testing.

Personal Attributes

  • Maintains professionalism under pressure.
  • Meticulous eye for detail.
  • Self-driven and proactive.
  • Thrives on complex challenges.
  • Dependable, cooperative team player.

*Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives*

About Stefanini Group
The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like Americas, Europe, Africa and Asia, and more than 400 clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting, company with global presence. We are CMM Level 5 company.



  • Atlanta, Georgia, United States Stefanini Group Full time

    Details:Stefanini Group is hiringExciting opportunity awaits, let us help you get startedClick Apply now or you may call: / email: Manisha Singh ) for faster processingPosition SummaryAs a key member of our Internal Product Security Engineering team, you will lead penetration-testing engagements for high-scale web applications and APIs, validating security...


  • Atlanta, Georgia, United States NextPath Career Partners Full time

    NextPath Career Partnersis currently seeking anLead Application Security Engineerto join our client's team inAtlanta, GA.This is anhybrid, directhire****position.SALARY:$120-$160K + Bonus (depending on experience)Unfortunately, at this time our client is unable to sponsor or transfer visas. Only candidates authorized to work in the US without sponsorship...


  • Atlanta, Georgia, United States Happy Returns, Inc. Full time

    Job Title: Cloud Security Engineer (DevSecOps)Location: Remote – U.S. only (must have legal authorization to work in the U.S.; no sponsorship available)Reports To: Head of Information SecurityAbout UsHappy Returns' mission is to make returns easier for shoppers and more efficient for retailers, transforming returns from a costly friction point into a...


  • Atlanta, Georgia, United States HD Supply Full time $120,000 - $180,000 per year

    Preferred QualificationsMaster's degree in computer science, engineering, or a related field.10+ years of experience in application engineering.Prior experience in a lead or mentorship role.Job SummaryProvides engineering expertise for application development activities, including configuring, designing, developing, troubleshooting, and debugging complex...


  • Atlanta, Georgia, United States AceStack Full time

    Job Title: Web Application Security & Penetration Testing AssociateLocation: Atlanta, GAContractJob Summary:We are seeking a skilled and detail-oriented Web Application Security and Penetration Testing Associate. This role involves identifying vulnerabilities in web applications, APIs, and related AWS infrastructure through manual and automated penetration...


  • Atlanta, Georgia, United States Bose Corporation Full time

    You know the moment. It's the first notes of that song you love, the intro to your favorite movie, or simply the sound of someone you love saying "hello." It's in these moments that sound matters most.  At Bose, we believe sound is the most powerful force on earth. We've dedicated ourselves to improving it for more than 60 years. And we're passionate down...

  • Application Engineer

    2 weeks ago


    Atlanta, Georgia, United States BlackRock Full time

    About This RoleAbout this roleAt BlackRock, we are looking for Software Engineers who like to innovate and solve complex problems. We recognize that strength comes from diversity, and will embrace your unique skills, curiosity, drive, and passion while giving you the opportunity to grow technically and as an individual.With over USD $9 trillion of assets we...

  • Security Engineer

    4 days ago


    Atlanta, Georgia, United States USM Full time

    Company Description USM Business Systems Inc. is a quickly developing worldwide System Integrator, Software and Product Development, IT Outsourcing and Technology assistance supplier headquartered in Chantilly, VA with off-shore delivery centers in India. We offer world-class ability in giving most astounding quality and administrations through industry best...


  • Atlanta, Georgia, United States Geotab Full time

    Who we are: Geotab is a global leader in IoT and connected transportation and certified "Great Place to Work." We are a company of diverse and talented individuals who work together to help businesses grow and succeed, and increase the safety and sustainability of our communities.   Geotab is advancing security, connecting commercial vehicles to the...


  • Atlanta, Georgia, United States Neptune Technology Group Full time

    Neptune Technology Group Inc.is a technology company serving water utilities across North America. Since 1892, we have continually focused on the evolving needs of water utilities – revenue optimization, operational efficiencies, and improved customer service. With our portfolio of smart water meters, data collection systems and software, we make data...