Home › Companies › Careers Hwkaufman Icims Com › Application Security Engineer
Application Security Engineer
Careers Hwkaufman Icims Com · UNAVAILABLE, UNAVAILABLE, US · Active · iCIMS
Job facts
| Field | Value |
|---|---|
| Company | Careers Hwkaufman Icims Com |
| Title | Application Security Engineer |
| Normalized title | - |
| Department / team | Information Technology |
| Location | UNAVAILABLE, UNAVAILABLE, United States |
| Work model | - |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | iCIMS |
| Posted / first seen | 2026-05-29 / 2026-05-31 |
| Changed / last seen | 2026-06-01 / 2026-06-18 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Careers Hwkaufman Icims Com. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through iCIMS. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in UNAVAILABLE. | Open |
| Department jobs | Active postings in Information Technology. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Careers Hwkaufman Icims Com |
| Source | 1fe0a2eb-ff8a-45cb-b1b4-63697bbd38ef |
| ATS provider | iCIMS |
Description
Responsibilities
The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements, proactively mitigating threats, and collaborating closely with developers to enhance the overall security posture of our applications.
As a subject matter expert in application security, the Application Security Engineer will lead the charge in finding and implementing innovative security solutions while ensuring the organization remains resilient against evolving threats. This individual will work closely with development and IT teams to embed security into application architecture, offer technical guidance to junior team members, and drive the implementation of security initiatives essential for meeting business and compliance needs.
Responsibilities
Partner with development teams to embed security best practices across the SDLC, including design, development, and deployment, and providesecure coding guidance
Conduct threat modeling and security architecture reviews to identifydesign-level risks and implement appropriate security controls
Identify, assess, and mitigate application vulnerabilities through a combination of automated (SAST/DAST) and manual code reviews, as well as penetration testing, and drive risk-based remediation
Implement and manage application security tools, including SAST, DAST, Software Composition Analysis (SCA), and other security scanning solutions
Ensure application security practices align with regulatory standards such as NYDFS, NIST, and OWASP guidelines
Partner with DevOps, IT, and security teams to integrate security into CI/CD pipelines and engineering workflows
Design and oversee the implementation of authentication, authorization, and access control mechanisms for APIs and platforms
Develop and enforce secure usage standards and governance for AI tools and AI-generated code, addressing risks such as prompt injection, data leakage, insecure code generation, and model misuse, while aligning with regulatory and industry standards
Qualifications
5+ years of experience in application security, secure software development, and vulnerability management
Strong knowledge of secure coding practices, OWASP Top 10,OWASP Top 10 for LLMs, MITRE ATLAS, and common security vulnerabilities
Experience with containerization technologies such as Docker and Kubernetes, the principles of container operation, and their secure interaction
Experience with security testing tools (e.g., Burp Suite, Fortify, Veracode, or similar)
Experience with Black Duck/Polaris with Apex code (Salesforce) is a plus
Familiarity with DevSecOpsprinciples and integrating security into CI/CD pipelines
Direct experience with security tools such as vulnerability scanners, intrusion detection systems, and log analysis tools
Understanding of regulatory frameworks and compliance requirements (e.g., NYDFS, GDPR, SOC 2)
Ability in scripting and automation using languages such as Python, PowerShell, or Bashand leverage AI driven tools to streamline and enhance security process and workflows
Experience with BlackDuck/Polaris and Apex code (Salesforce) is a plus
Relevant certifications such as Certified DevSecOpsEngineer, CISSP, OWASP certifications, GIAC GWAPT
#LI-CC1
About Our Company
H.W. Kaufman Group is a powerful global network of companies dedicated to shaping the future of insurance. With thousands of dedicated professionals across an extensive network of over 60 offices around the world, we lead by offering innovative solutions that are at the forefront of the industry. We are privately owned and thus free from the influence of Wall Street. This allows us the ability to adapt to constantly fluctuating market conditions. From brokerage, underwriting, and real estate to claims, loss control and risk management services, our depth of services is unrivaled.
Equal Opportunity Employer
The H.W. Kaufman Group of companies is an equal opportunity employer. All employment decisions are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, gender, gender identity, age, national origin, disability, veteran status, marital status, pregnancy, sexual orientation, genetic information or any other status or condition protected by the laws or regulations in the locations where we operate.
In addition, Kaufman will make reasonable accommodations to known physical or mental limitations of an otherwise qualified person with a disability, unless the accommodation would impose an undue hardship on the operation of our business.
Full job record
| Job ID | e322020b7115597bf799283c69ad66e013756b94 |
| Org ID | 99b3254a-abe8-4107-9251-788eccafff74 |
| Source ID | 1fe0a2eb-ff8a-45cb-b1b4-63697bbd38ef |
| Board ID | 1fe0a2eb-ff8a-45cb-b1b4-63697bbd38ef |
| Provider | icims |
| Provider Job Key | 9091 |
| Title | Application Security Engineer |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | UNAVAILABLE, UNAVAILABLE, US |
| Department | Information Technology |
| Team | — |
| Employment Type | full_time |
| Workplace Type | — |
| Remote Policy | — |
| Country | United States |
| Region | UNAVAILABLE |
| City | UNAVAILABLE |
| Salary Raw | Responsibilities The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements, proactively mitigating threats, and collaborating closely with developers to enhance the overall security posture of our applications. As a subject matter expert in application security, the Application Security Engineer will lead the charge in finding and implementing innovative security solutions while ensuring the organization remains resilient against evolving threats. This individual will work closely with development and IT teams to embed security into application architecture, offer technical guidance to junior team members, and drive the implementation of security initiatives essential for meeting business and compliance needs. Responsibilities Partner with development teams to embed security best practices across the SDLC, including design, development, and deployment, and providesecure coding guidance Conduct threat modeling and security architecture reviews to identifydesign-level risks and implement appropriate security controls Identify, assess, and mitigate application vulnerabilities through a combination of automated (SAST/DAST) and manual code reviews, as well as penetration testing, and drive risk-based remediation Implement and manage application security tools, including SAST, DAST, Software Composition Analysis (SCA), and other security scanning solutions Ensure application security practices align with regulatory standards such as NYDFS, NIST, and OWASP guidelines Partner with DevOps, IT, and security teams to integrate security into CI/CD pipelines and engineering workflows Design and oversee the implementation of authentication, authorization, and access control mechanisms for APIs and platforms Develop and enforce secure usage standards and governance for AI tools and AI-generated code, addressing risks such as prompt injection, data leakage, insecure code generation, and model misuse, while aligning with regulatory and industry standards Qualifications 5+ years of experience in application security, secure software development, and vulnerability management Strong knowledge of secure coding practices, OWASP Top 10,OWASP Top 10 for LLMs, MITRE ATLAS, and common security vulnerabilities Experience with containerization technologies such as Docker and Kubernetes, the principles of container operation, and their secure interaction Experience with security testing tools (e.g., Burp Suite, Fortify, Veracode, or similar) Experience with Black Duck/Polaris with Apex code (Salesforce) is a plus Familiarity with DevSecOpsprinciples and integrating security into CI/CD pipelines Direct experience with security tools such as vulnerability scanners, intrusion detection systems, and log analysis tools Understanding of regulatory frameworks and compliance requirements (e.g., NYDFS, GDPR, SOC 2) Ability in scripting and automation using languages such as Python, PowerShell, or Bashand leverage AI driven tools to streamline and enhance security process and workflows Experience with BlackDuck/Polaris and Apex code (Salesforce) is a plus Relevant certifications such as Certified DevSecOpsEngineer, CISSP, OWASP certifications, GIAC GWAPT #LI-CC1 About Our Company H.W. Kaufman Group is a powerful global network of companies dedicated to shaping the future of insurance. With thousands of dedicated professionals across an extensive network of over 60 offices around the world, we lead by offering innovative solutions that are at the forefront of the industry. We are privately owned and thus free from the influence of Wall Street. This allows us the ability to adapt to constantly fluctuating market conditions. From brokerage, underwriting, and real estate to claims, loss control and risk management services, our depth of services is unrivaled. Equal Opportunity Employer The H.W. Kaufman Group of companies is an equal opportunity employer. All employment decisions are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, gender, gender identity, age, national origin, disability, veteran status, marital status, pregnancy, sexual orientation, genetic information or any other status or condition protected by the laws or regulations in the locations where we operate. In addition, Kaufman will make reasonable accommodations to known physical or mental limitations of an otherwise qualified person with a disability, unless the accommodation would impose an undue hardship on the operation of our business. |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://careers-hwkaufman.icims.com/jobs/9091/application-security-engineer/job |
| Apply URL | https://careers-hwkaufman.icims.com/jobs/9091/application-security-engineer/job |
| First Seen At | 2026-05-31 18:37:50Z |
| Last Seen At | 2026-06-18 08:17:50Z |
| Last Checked At | 2026-06-18 08:17:50Z |
| Last Changed At | 2026-06-01 13:31:42Z |
| Inactive At | — |
| Source Posted At | 2026-05-29 04:00:00Z |
| Source Updated At | 2026-03-31 20:25:06Z |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-hwkaufman.icims.com/date=2026-06-18/2026-06-18T08-17-47-608Z-ee7624818f6b0950765c67278a7bf8793fcb263223db95c96c0915f25b24723c.json |
Event Fields
{
"content_hash": "a6b1171f9170cb00586fb6fd39e3277573bbb08f26d537c50f7b0a2422882042",
"source_hash": "2e4ba3db06ba66ed2b0cfa30e41f30f52021128e86712390efc9948af1cc4c1c",
"last_changed_at": "2026-06-01T13:31:42.835Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "UNAVAILABLE, UNAVAILABLE, US",
"city": "UNAVAILABLE",
"region": "UNAVAILABLE",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-18T08:17:50.771Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "UNAVAILABLE, UNAVAILABLE, US",
"city": "UNAVAILABLE",
"region": "UNAVAILABLE",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"countries": [
"United States"
]
},
"remote_policy": null,
"salary_period": null,
"workplace_type": null,
"salary_currency": null
}Extensions
{}Native Structured
{
"json_ld": {
"url": "https://careers-hwkaufman.icims.com/jobs/9091/application-security-engineer/job",
"@type": "JobPosting",
"title": "Application Security Engineer",
"@context": "http://schema.org",
"datePosted": "2026-05-29T04:00:00.000Z",
"description": "<h2></h2>\n<p></p>\n<h2>Responsibilities</h2>\n<p>The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements, proactively mitigating threats, and collaborating closely with developers to enhance the overall security posture of our applications. </p>\n<p> </p>\n<p>As a subject matter expert in application security, the Application Security Engineer will lead the charge in finding and implementing innovative security solutions while ensuring the organization remains resilient against evolving threats. This individual will work closely with development and IT teams to embed security into application architecture, offer technical guidance to junior team members, and drive the implementation of security initiatives essential for meeting business and compliance needs. </p>\n<p> </p>\n<p><strong>Responsibilities</strong> </p>\n<p> </p>\n<ul>\n <li> Partner with development teams to embed security best practices across the SDLC, including design, development, and deployment, and providesecure coding guidance </li>\n <li>Conduct threat modeling and security architecture reviews to identifydesign-level risks and implement appropriate security controls </li>\n <li>Identify, assess, and mitigate application vulnerabilities through a combination of automated (SAST/DAST) and manual code reviews, as well as penetration testing, and drive risk-based remediation</li>\n <li>Implement and manage application security tools, including SAST, DAST, Software Composition Analysis (SCA), and other security scanning solutions</li>\n <li>Ensure application security practices align with regulatory standards such as NYDFS, NIST, and OWASP guidelines</li>\n <li>Partner with DevOps, IT, and security teams to integrate security into CI/CD pipelines and engineering workflows</li>\n <li>Design and oversee the implementation of authentication, authorization, and access control mechanisms for APIs and platforms</li>\n <li>Develop and enforce secure usage standards and governance for AI tools and AI-generated code, addressing risks such as prompt injection, data leakage, insecure code generation, and model misuse, while aligning with regulatory and industry standards</li>\n</ul>\n<h2>Qualifications</h2>\n<ul>\n <li>5+ years of experience in application security, secure software development, and vulnerability management</li>\n <li>Strong knowledge of secure coding practices, OWASP Top 10,OWASP Top 10 for LLMs, MITRE ATLAS, and common security vulnerabilities </li>\n <li>Experience with containerization technologies such as Docker and Kubernetes, the principles of container operation, and their secure interaction</li>\n <li>Experience with security testing tools (e.g., Burp Suite, Fortify, Veracode, or similar)</li>\n <li>Experience with Black Duck/Polaris with Apex code (Salesforce) is a plus </li>\n <li>Familiarity with DevSecOpsprinciples and integrating security into CI/CD pipelines </li>\n <li>Direct experience with security tools such as vulnerability scanners, intrusion detection systems, and log analysis tools</li>\n <li>Understanding of regulatory frameworks and compliance requirements (e.g., NYDFS, GDPR, SOC 2)</li>\n <li>Ability in scripting and automation using languages such as Python, PowerShell, or Bashand leverage AI driven tools to streamline and enhance security process and workflows </li>\n <li>Experience with BlackDuck/Polaris and Apex code (Salesforce) is a plus </li>\n <li>Relevant certifications such as Certified DevSecOpsEngineer, CISSP, OWASP certifications, GIAC GWAPT </li>\n</ul>\n<p>#LI-CC1</p>\n<h2>About Our Company</h2>\n<p>H.W. Kaufman Group is a powerful global network of companies dedicated to shaping the future of insurance. With thousands of dedicated professionals across an extensive network of over 60 offices around the world, we lead by offering innovative solutions that are at the forefront of the industry. We are privately owned and thus free from the influence of Wall Street. This allows us the ability to adapt to constantly fluctuating market conditions. From brokerage, underwriting, and real estate to claims, loss control and risk management services, our depth of services is unrivaled.</p>\n<p> </p>\n<p><strong>Equal Opportunity Employer </strong></p>\n<p> </p>\n<p>The H.W. Kaufman Group of companies is an equal opportunity employer. All employment decisions are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, gender, gender identity, age, national origin, disability, veteran status, marital status, pregnancy, sexual orientation, genetic information or any other status or condition protected by the laws or regulations in the locations where we operate.</p>\n<p> </p>\n<p>In addition, Kaufman will make reasonable accommodations to known physical or mental limitations of an otherwise qualified person with a disability, unless the accommodation would impose an undue hardship on the operation of our business.</p>\n<p> </p>",
"directApply": true,
"jobLocation": [
{
"@type": "Place",
"address": {
"@type": "PostalAddress",
"postalCode": "UNAVAILABLE",
"addressRegion": "UNAVAILABLE",
"streetAddress": "UNAVAILABLE",
"addressCountry": "US",
"addressLocality": "UNAVAILABLE",
"postOfficeBoxNumber": "UNAVAILABLE"
}
}
],
"validThrough": "2026-06-30T04:00:00.000Z",
"employmentType": "FULL_TIME",
"jobLocationType": "TELECOMMUTE",
"hiringOrganization": {
"name": "H.W. Kaufman Group",
"@type": "Organization",
"sameAs": "http://www.kaufmanfinancialgroup.com"
},
"occupationalCategory": "Information Technology"
},
"detail_meta": {
"url": "https://careers-hwkaufman.icims.com/jobs/9091/application-security-engineer/job?in_iframe=1",
"http_status": 200,
"content_type": "text/html;charset=UTF-8",
"response_bytes": 42145,
"compact_response_bytes": 6335,
"original_response_bytes": 42145
},
"sitemap_job": {
"id": "9091",
"url": "https://careers-hwkaufman.icims.com/jobs/9091/application-security-engineer/job",
"slug": "application-security-engineer",
"lastmod": "2026-03-31T16:25:06-04:00"
},
"detail_errors": []
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/e322020b7115597bf799283c69ad66e013756b94?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/99b3254a-abe8-4107-9251-788eccafff74JSONGET https://api.bluedoor.sh/job-postings/v1/sources/1fe0a2eb-ff8a-45cb-b1b4-63697bbd38efJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/e322020b7115597bf799283c69ad66e013756b94/eventsJSON