bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesXceedsearchcomApplication Security Engineer

Application Security Engineer

Xceedsearchcom · Scottsdale, AZ, United States · Active · SmartRecruiters

Job facts

FieldValue
CompanyXceedsearchcom
TitleApplication Security Engineer
Normalized title-
Department / teamInformation Technology
LocationScottsdale, AZ, United States
Work model-
Employment typeFull Time
Salary-
Statusactive
ATS providerSmartRecruiters
Posted / first seen2026-05-12 / 2026-05-31
Changed / last seen2026-05-31 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Xceedsearchcom.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through SmartRecruiters.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Scottsdale.Open
Department jobsActive postings in Information Technology.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyXceedsearchcom
Source9c5aada6-425e-40ab-a50f-7da7345d3254
ATS providerSmartRecruiters

Description

Insurance Company Company is seeking a  Lead Application Security Engineer  to play a critical dual role at the intersection of secure software development and hands‑on engineering leadership. This position is ideal for a technologist who is passionate about building modern applications  and  ensuring they are secure by design. In this role, you will embed application security expertise directly into the engineering organization. Approximately half of your focus will be on application security, identifying vulnerabilities, guiding remediation efforts, and providing meaningful security metrics and reporting. The other half will be spent leading and contributing to the design, development, and delivery of applications built with  Java and Angular. The ideal candidate naturally bridges security and engineering, influencing architecture decisions, mentoring development teams, and championing best practices that balance strong security with scalability, performance, and delivery speed. This position is based in our Scottsdale, AZ office. After completing an initial training period, the role offers a hybrid schedule with four days in the office and one remote day per week. Responsibilities Application Security Conduct application security assessments and vulnerability scans using Veracode (SAST, DAST, and SCA) across Java, Spring Boot REST services, AngularJS, and Angular applications. Analyze, prioritize, and track security findings through their full remediation lifecycle, ensuring timely resolution and appropriate escalation. Hands-on remediate security vulnerabilities directly in Java, Spring Boot, AngularJS, and Angular codebases, while also guiding developers on secure coding practices and mitigation techniques specific to the Java and JavaScript ecosystem. Review, assess, and implement REST API security controls hands-on, including coding authentication, authorization, input validation, and data protection solutions directly within Spring Boot services. Produce clear, well-structured vulnerability reports and executive summaries for both technical teams and leadership. Establish and maintain application security policies, standards, and guidelines aligned with OWASP and industry best practices. Participate in Architecture Review Board discussions to identify and address security risks in proposed designs. Evaluate AI-generated code from tools such as GitHub Copilot for security risks and guide developers on safe AI-assisted development practices. Leverage AI-assisted security tooling to accelerate vulnerability detection, triage, and remediation workflows. Support compliance and audit activities related to application security controls. Lead Software Engineering Take full ownership of team deliverables, ensuring quality, stability, and resilience of applications. Establish and enforce coding standards and development practices for high-quality, secure software delivery. Serve as the technical lead for major system components, guiding architecture and technical decisions while remaining an active, hands-on contributor to the codebase. Actively design, write, review, and maintain code for scalable user interfaces and services, contributing directly to efficient, responsive applications built on Java, Spring Boot, Angular, and microservices architectures. Understand data flows and system integrations to support solution design, and write code directly to facilitate defect resolution and system improvements. Identify and resolve performance issues, defects, and system inefficiencies through direct, hands-on code contributions or delegating fixes to others as needed. Act as the primary technical liaison with stakeholders, translating requirements into scalable solutions and managing expectations. Foster a culture of accountability, security awareness, and continuous improvement through coaching and mentoring. Qualifications Bachelor’s degree in Computer Science, Information Technology, or equivalent experience. 5+ years of hands-on application security engineering experience, including vulnerability assessment and remediation. 7+ years of software development experience with Java and Angular/AngularJS. 3+ years of experience in a technical leadership or lead engineering capacity. Proficient in: Java, Spring Boot, Spring Security, REST Web Services, Microservices, JavaScript, TypeScript, AngularJS, Angular, HTML, CSS, JUnit, Mockito, Git, Maven, and SQL. Hands-on experience with enterprise application security scanning platforms such as Veracode, Checkmarx, Fortify, or similar tools, including SAST, DAST, and SCA scan configuration, results interpretation, and developer-facing remediation guidance. Strong understanding of the OWASP Top 10 and how vulnerabilities manifest in enterprise Java and JavaScript applications. Experience securing REST APIs, including OAuth2, JWT, and Spring Security implementations. Demonstrated ability to produce clear vulnerability reports with severity ratings, impact assessments, and recommended mitigations for both technical and non-technical audiences. Experience in project estimation, requirements gathering, system design, agile story creation, release support, and agile methodologies. Preferred knowledge in: GitHub Copilot, AI-assisted security tooling, AWS, GCP, Drupal, Jasmine, Karma, IntelliJ, Eclipse, STS, WebStorm, Rancher, Jira, PL/SQL, Checkmarx, Fortify, or Burp Suite. Security certifications such as CSSLP, CEH, GWAPT, or equivalent application security credentials are a plus. Strong written and verbal communication skills with the ability to engage both development teams and IT leadership effectively. Excellent analytical and problem-solving abilities with strong attention to detail. Team-oriented, adaptable, and motivated to support both engineering excellence and organizational security goals. All your information will be kept confidential according to EEO guidelines. Thank You Arnold Avila Xceed Search (480) 419-1311 http://www.xceedsearch.com

Full job record

Job ID27d2550de204ff6f799ade348893a4db25341be6
Org IDc8ecba3b-19bf-4210-8544-e53758a295e3
Source ID9c5aada6-425e-40ab-a50f-7da7345d3254
Board ID9c5aada6-425e-40ab-a50f-7da7345d3254
Providersmartrecruiters
Provider Job Key744000126179759
TitleApplication Security Engineer
Normalized Title
Statusactive
Activeyes
Location TextScottsdale, AZ, United States
DepartmentInformation Technology
Team
Employment Typefull_time
Workplace Type
Remote Policy
CountryUnited States
RegionAZ
CityScottsdale
Salary RawInsurance Company Company is seeking a  Lead Application Security Engineer  to play a critical dual role at the intersection of secure software development and hands‑on engineering leadership. This position is ideal for a technologist who is passionate about building modern applications  and  ensuring they are secure by design. In this role, you will embed application security expertise directly into the engineering organization. Approximately half of your focus will be on application security, identifying vulnerabilities, guiding remediation efforts, and providing meaningful security metrics and reporting. The other half will be spent leading and contributing to the design, development, and delivery of applications built with  Java and Angular. The ideal candidate naturally bridges security and engineering, influencing architecture decisions, mentoring development teams, and championing best practices that balance strong security with scalability, performance, and delivery speed. This position is based in our Scottsdale, AZ office. After completing an initial training period, the role offers a hybrid schedule with four days in the office and one remote day per week. Responsibilities Application Security Conduct application security assessments and vulnerability scans using Veracode (SAST, DAST, and SCA) across Java, Spring Boot REST services, AngularJS, and Angular applications. Analyze, prioritize, and track security findings through their full remediation lifecycle, ensuring timely resolution and appropriate escalation. Hands-on remediate security vulnerabilities directly in Java, Spring Boot, AngularJS, and Angular codebases, while also guiding developers on secure coding practices and mitigation techniques specific to the Java and JavaScript ecosystem. Review, assess, and implement REST API security controls hands-on, including coding authentication, authorization, input validation, and data protection solutions directly within Spring Boot services. Produce clear, well-structured vulnerability reports and executive summaries for both technical teams and leadership. Establish and maintain application security policies, standards, and guidelines aligned with OWASP and industry best practices. Participate in Architecture Review Board discussions to identify and address security risks in proposed designs. Evaluate AI-generated code from tools such as GitHub Copilot for security risks and guide developers on safe AI-assisted development practices. Leverage AI-assisted security tooling to accelerate vulnerability detection, triage, and remediation workflows. Support compliance and audit activities related to application security controls. Lead Software Engineering Take full ownership of team deliverables, ensuring quality, stability, and resilience of applications. Establish and enforce coding standards and development practices for high-quality, secure software delivery. Serve as the technical lead for major system components, guiding architecture and technical decisions while remaining an active, hands-on contributor to the codebase. Actively design, write, review, and maintain code for scalable user interfaces and services, contributing directly to efficient, responsive applications built on Java, Spring Boot, Angular, and microservices architectures. Understand data flows and system integrations to support solution design, and write code directly to facilitate defect resolution and system improvements. Identify and resolve performance issues, defects, and system inefficiencies through direct, hands-on code contributions or delegating fixes to others as needed. Act as the primary technical liaison with stakeholders, translating requirements into scalable solutions and managing expectations. Foster a culture of accountability, security awareness, and continuous improvement through coaching and mentoring. Qualifications Bachelor’s degree in Computer Science, Information Technology, or equivalent experience. 5+ years of hands-on application security engineering experience, including vulnerability assessment and remediation. 7+ years of software development experience with Java and Angular/AngularJS. 3+ years of experience in a technical leadership or lead engineering capacity. Proficient in: Java, Spring Boot, Spring Security, REST Web Services, Microservices, JavaScript, TypeScript, AngularJS, Angular, HTML, CSS, JUnit, Mockito, Git, Maven, and SQL. Hands-on experience with enterprise application security scanning platforms such as Veracode, Checkmarx, Fortify, or similar tools, including SAST, DAST, and SCA scan configuration, results interpretation, and developer-facing remediation guidance. Strong understanding of the OWASP Top 10 and how vulnerabilities manifest in enterprise Java and JavaScript applications. Experience securing REST APIs, including OAuth2, JWT, and Spring Security implementations. Demonstrated ability to produce clear vulnerability reports with severity ratings, impact assessments, and recommended mitigations for both technical and non-technical audiences. Experience in project estimation, requirements gathering, system design, agile story creation, release support, and agile methodologies. Preferred knowledge in: GitHub Copilot, AI-assisted security tooling, AWS, GCP, Drupal, Jasmine, Karma, IntelliJ, Eclipse, STS, WebStorm, Rancher, Jira, PL/SQL, Checkmarx, Fortify, or Burp Suite. Security certifications such as CSSLP, CEH, GWAPT, or equivalent application security credentials are a plus. Strong written and verbal communication skills with the ability to engage both development teams and IT leadership effectively. Excellent analytical and problem-solving abilities with strong attention to detail. Team-oriented, adaptable, and motivated to support both engineering excellence and organizational security goals. All your information will be kept confidential according to EEO guidelines. Thank You Arnold Avila Xceed Search (480) 419-1311 http://www.xceedsearch.com
Salary Min
Salary Max
Salary Currency
Salary Periodday
Source URLhttps://jobs.smartrecruiters.com/XceedSearchcom/744000126179759-application-security-engineer
Apply URLhttps://jobs.smartrecruiters.com/XceedSearchcom/744000126179759-application-security-engineer?oga=true
First Seen At2026-05-31 17:42:31Z
Last Seen At2026-06-06 10:46:56Z
Last Checked At2026-06-06 10:46:56Z
Last Changed At2026-05-31 17:42:31Z
Inactive At
Source Posted At2026-05-12 22:52:27Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=smartrecruiters/board=xceedsearchcom/date=2026-06-06/2026-06-06T10-46-55-006Z-321b2486be69af6ec294369f216640d05e7c5da89ac1006c9bb09e7fe684c327.json
Event Fields
{
  "content_hash": "7995dc4c072b560f2ed351e6dbef5e253c9eea5749aa076d5f47d9b39d8e1581",
  "source_hash": "f5a5d51f7c2ab7fafaecd04998f0c4681fbb0a773392fe0c2dae300ed0ac6096",
  "last_changed_at": "2026-05-31T17:42:31.681Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Scottsdale, AZ, United States",
    "city": "Scottsdale",
    "region": "AZ",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T10:46:56.761Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Scottsdale, AZ, United States",
      "city": "Scottsdale",
      "region": "AZ",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": null,
  "salary_period": "day",
  "workplace_type": null,
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "744000126179759",
  "ref": "https://api.smartrecruiters.com/v1/companies/xceedsearchcom/postings/744000126179759",
  "name": "Application Security Engineer",
  "uuid": "2f05d6d2-2b16-4052-8b41-2c4432802881",
  "detail": {
    "id": "744000126179759",
    "name": "Application Security Engineer",
    "uuid": "2f05d6d2-2b16-4052-8b41-2c4432802881",
    "jobAd": {
      "sections": {
        "jobDescription": {
          "text": "<p>Company is seeking a&#xa0;<strong>Lead Application Security Engineer&#xa0;</strong>to play a critical dual role at the intersection of secure software development and hands‑on engineering leadership. This position is ideal for a technologist who is passionate about building modern applications&#xa0;<em>and</em>&#xa0;ensuring they are secure by design.</p><p>In this role, you will embed application security expertise directly into the engineering organization. Approximately half of your focus will be on application security, identifying vulnerabilities, guiding remediation efforts, and providing meaningful security metrics and reporting. The other half will be spent leading and contributing to the design, development, and delivery of applications built with&#xa0;<strong>Java and Angular.</strong></p><p>The ideal candidate naturally bridges security and engineering, influencing architecture decisions, mentoring development teams, and championing best practices that balance strong security with scalability, performance, and delivery speed.</p><p>This position is based in our Scottsdale, AZ office. After completing an initial training period, the role offers a hybrid schedule with four days in the office and one remote day per week.</p><p><strong>Responsibilities</strong></p><p><strong>Application Security</strong></p><ul><li>Conduct application security assessments and vulnerability scans using Veracode (SAST, DAST, and SCA) across Java, Spring Boot REST services, AngularJS, and Angular applications.</li><li>Analyze, prioritize, and track security findings through their full remediation lifecycle, ensuring timely resolution and appropriate escalation.</li><li>Hands-on remediate security vulnerabilities directly in Java, Spring Boot, AngularJS, and Angular codebases, while also guiding developers on secure coding practices and mitigation techniques specific to the Java and JavaScript ecosystem.</li><li>Review, assess, and implement REST API security controls hands-on, including coding authentication, authorization, input validation, and data protection solutions directly within Spring Boot services.</li><li>Produce clear, well-structured vulnerability reports and executive summaries for both technical teams and leadership.</li><li>Establish and maintain application security policies, standards, and guidelines aligned with OWASP and industry best practices.</li><li>Participate in Architecture Review Board discussions to identify and address security risks in proposed designs.</li><li>Evaluate AI-generated code from tools such as GitHub Copilot for security risks and guide developers on safe AI-assisted development practices.</li><li>Leverage AI-assisted security tooling to accelerate vulnerability detection, triage, and remediation workflows.</li><li>Support compliance and audit activities related to application security controls.</li></ul><p><strong>Lead Software Engineering</strong></p><ul><li>Take full ownership of team deliverables, ensuring quality, stability, and resilience of applications.</li><li>Establish and enforce coding standards and development practices for high-quality, secure software delivery.</li><li>Serve as the technical lead for major system components, guiding architecture and technical decisions while remaining an active, hands-on contributor to the codebase.</li><li>Actively design, write, review, and maintain code for scalable user interfaces and services, contributing directly to efficient, responsive applications built on Java, Spring Boot, Angular, and microservices architectures.</li><li>Understand data flows and system integrations to support solution design, and write code directly to facilitate defect resolution and system improvements.</li><li>Identify and resolve performance issues, defects, and system inefficiencies through direct, hands-on code contributions or delegating fixes to others as needed.</li><li>Act as the primary technical liaison with stakeholders, translating requirements into scalable solutions and managing expectations.</li><li>Foster a culture of accountability, security awareness, and continuous improvement through coaching and mentoring.</li></ul><p><strong>Qualifications</strong></p><ul><li>Bachelor’s degree in Computer Science, Information Technology, or equivalent experience.</li><li>5+ years of hands-on application security engineering experience, including vulnerability assessment and remediation.</li><li>7+ years of software development experience with Java and Angular/AngularJS.</li><li>3+ years of experience in a technical leadership or lead engineering capacity.</li><li>Proficient in: Java, Spring Boot, Spring Security, REST Web Services, Microservices, JavaScript, TypeScript, AngularJS, Angular, HTML, CSS, JUnit, Mockito, Git, Maven, and SQL.</li><li>Hands-on experience with enterprise application security scanning platforms such as Veracode, Checkmarx, Fortify, or similar tools, including SAST, DAST, and SCA scan configuration, results interpretation, and developer-facing remediation guidance.</li><li>Strong understanding of the OWASP Top 10 and how vulnerabilities manifest in enterprise Java and JavaScript applications.</li><li>Experience securing REST APIs, including OAuth2, JWT, and Spring Security implementations.</li><li>Demonstrated ability to produce clear vulnerability reports with severity ratings, impact assessments, and recommended mitigations for both technical and non-technical audiences.</li><li>Experience in project estimation, requirements gathering, system design, agile story creation, release support, and agile methodologies.</li><li>Preferred knowledge in: GitHub Copilot, AI-assisted security tooling, AWS, GCP, Drupal, Jasmine, Karma, IntelliJ, Eclipse, STS, WebStorm, Rancher, Jira, PL/SQL, Checkmarx, Fortify, or Burp Suite.</li><li>Security certifications such as CSSLP, CEH, GWAPT, or equivalent application security credentials are a plus.</li><li>Strong written and verbal communication skills with the ability to engage both development teams and IT leadership effectively.</li><li>Excellent analytical and problem-solving abilities with strong attention to detail.</li><li>Team-oriented, adaptable, and motivated to support both engineering excellence and organizational security goals.</li></ul><p>&#xa0;</p><p>&#xa0;</p>",
          "title": "Job Description"
        },
        "qualifications": {
          "text": "",
          "title": "Qualifications"
        },
        "companyDescription": {
          "text": "<p>Insurance Company<br>\n<br>\n&#xa0;</p>",
          "title": "Company Description"
        },
        "additionalInformation": {
          "text": "<p>All your information will be kept confidential according to EEO guidelines.</p><p>&#xa0;</p><p>Thank You<br>\nArnold Avila<br>\nXceed Search<br>\n(480) 419-1311<br>\nhttp://www.xceedsearch.com</p><p>&#xa0;</p>",
          "title": "Additional Information"
        }
      }
    },
    "jobId": "4b7d7708-d7ef-4602-9655-5cb0c804a038",
    "active": true,
    "company": {
      "name": "XceedSearch.com",
      "identifier": "XceedSearchcom"
    },
    "creator": {
      "name": "Arnold A",
      "avatarUrl": "https://c.smartrecruiters.com/sr-employee-image-prod-aws-dc5/5135d923e4b0b42dcb46f6ba?r=s3-eu-central-1&_1408030263371"
    },
    "jobAdId": "e7ee9d93-277b-4d9e-bdff-f9132984b411",
    "applyUrl": "https://jobs.smartrecruiters.com/XceedSearchcom/744000126179759-application-security-engineer?oga=true",
    "function": {
      "id": "information_technology",
      "label": "Information Technology"
    },
    "industry": {
      "id": "insurance",
      "label": "Insurance"
    },
    "language": {
      "code": "en",
      "label": "English",
      "labelNative": "English (US)"
    },
    "location": {
      "city": "Scottsdale",
      "hybrid": false,
      "region": "AZ",
      "remote": false,
      "address": "North Scottsdale Road",
      "country": "us",
      "latitude": "33.6257086",
      "longitude": "-111.9257057",
      "fullLocation": "Scottsdale, AZ, United States"
    },
    "refNumber": "REF369O",
    "postingUrl": "https://jobs.smartrecruiters.com/XceedSearchcom/744000126179759-application-security-engineer",
    "visibility": "PUBLIC",
    "customField": [
      {
        "fieldId": "COUNTRY",
        "valueId": "us",
        "fieldLabel": "Country/Region",
        "valueLabel": "United States"
      },
      {
        "fieldId": "58b7e8c2e4b09a6d37a0d616",
        "valueId": "default",
        "fieldLabel": "Brands",
        "valueLabel": "XceedSearch.com"
      }
    ],
    "referralUrl": "https://jobs.smartrecruiters.com/external-referrals/company/XceedSearchcom/publication/2f05d6d2-2b16-4052-8b41-2c4432802881?dcr_ci=XceedSearchcom",
    "defaultJobAd": true,
    "releasedDate": "2026-05-12T22:52:27.770Z",
    "experienceLevel": {
      "id": "mid_senior_level",
      "label": "Mid-Senior Level"
    },
    "typeOfEmployment": {
      "id": "permanent",
      "label": "Full-time"
    }
  },
  "company": {
    "name": "XceedSearch.com",
    "identifier": "XceedSearchcom"
  },
  "creator": {
    "name": "Arnold A"
  },
  "jobAdId": "e7ee9d93-277b-4d9e-bdff-f9132984b411",
  "function": {
    "id": "information_technology",
    "label": "Information Technology"
  },
  "industry": {
    "id": "insurance",
    "label": "Insurance"
  },
  "language": {
    "code": "en",
    "label": "English",
    "labelNative": "English (US)"
  },
  "location": {
    "city": "Scottsdale",
    "hybrid": false,
    "region": "AZ",
    "remote": false,
    "address": "North Scottsdale Road",
    "country": "us",
    "latitude": "33.6257086",
    "longitude": "-111.9257057",
    "fullLocation": "Scottsdale, AZ, United States"
  },
  "refNumber": "REF369O",
  "department": {},
  "visibility": "PUBLIC",
  "customField": [
    {
      "fieldId": "COUNTRY",
      "valueId": "us",
      "fieldLabel": "Country/Region",
      "valueLabel": "United States"
    },
    {
      "fieldId": "58b7e8c2e4b09a6d37a0d616",
      "valueId": "default",
      "fieldLabel": "Brands",
      "valueLabel": "XceedSearch.com"
    }
  ],
  "defaultJobAd": true,
  "releasedDate": "2026-05-12T22:52:27.770Z",
  "detail_errors": [],
  "experienceLevel": {
    "id": "mid_senior_level",
    "label": "Mid-Senior Level"
  },
  "typeOfEmployment": {
    "id": "permanent",
    "label": "Full-time"
  }
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/27d2550de204ff6f799ade348893a4db25341be6?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/c8ecba3b-19bf-4210-8544-e53758a295e3JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/9c5aada6-425e-40ab-a50f-7da7345d3254JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/27d2550de204ff6f799ade348893a4db25341be6/eventsJSON