Senior Application Security Engineer managing application security with Django/Python at Energy Solutions. Focus on risk management, collaborating with development teams, and improving security practices.
Responsibilities
Contribute to the application security roadmap for our internal applications—prioritize risks and sequence work across codebases, application layer, and DevOps.
Consult with engineers to communicate requirements, create actionable tickets/acceptance criteria, and drive adoption.
Conduct pull request reviews focused on security, provide guidance on refactors, and approve/deny with clear rationale.
Serve as a steward for SAST/scanning: review static code scan results, triage findings, eliminate noise, and drive remediation with owners.
Build reference implementations in Django/Python (i.e. authentication patterns, input validation, secrets handling, rate limiting, geo-based access) without direct responsibility for production feature development.
Map SOC 2/NIST to engineering work: translate requirements into stories, controls, and automated evidence in CI/CD.
Threat modeling & architecture: navigate libraries/architectures and document secure patterns (ADRs/RFCs) that teams follow.
Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.
Collaborate with software developers and code base leads.
Act as a liaison between technical requirements from the business (i.e. security, privacy, compliance) and development teams.
Participate as a subject matter expert in security architecture, including new designs and design reviews.
Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.
Review architecture and compliance-related code changes for security impact.
Ensure compliance with all company security policies and standards.
Manage and maintain all security related tickets, including recommendations, testing, and validation.
Requirements
Minimum of 5 years' experience in application security experience.
Practice and implementation with Django/Python with a clear application-security focus (production experience and impact, not theory).
Engineering background (software or DevOps/SRE) with the ability to read/modify code, review PRs, and build PoCs.
Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
Experience embedding secure SDLC into Git-based workflows and CI/CD (pre-commit, pipeline gates, policy-as-code).
Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.
Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging/monitoring).
Clear, persuasive communication (verbal and written) and prioritization.
Excellent time management skills with a proven ability to meet deadlines.
Application Support Engineer supporting client - facing operations and product implementations for financial technology. Responsible for handling operational issues and providing support across various channels.
Quantum Applications Engineer developing quantum algorithms and applications, mapping them to Atom Computing hardware. Collaborating with partners to advance quantum computing solutions.
Application Engineer responsible for creating bids and coordinating technical offers in water transport projects at Xylem. Collaboration with engineering firms and project management for optimal cost calculations.
Electrical Application Engineer providing power transmission and Motion Control expertise for SEW - EURODRIVE. Driving sales activity and maintaining customer relationships in the Boston area.
Manager leading data engineering and applications for Xcel Energy, ensuring reliability and scalability of pipelines. Overseeing a team to deliver data services and maintain standards.
Applications Engineer for Test & Measurement platform at Pico, acting as a link between engineering and global customers. Responsible for product integration, customer support, and training.
Principal Application Development Engineer at NCR Voyix developing solutions in Oracle Fusion Cloud/EBS. Working on integrations, data migration, and ERP technical architecture with a global team.
Field Application Engineer supporting OPAL - RT's real - time simulation tools and providing customer training. Involves international travel and collaboration across multiple sectors in China.
Director seeking mechanical SDA application engineering team leadership within Cadence. Overseeing staffing, technical vision, and customer engagement.
Application Engineer collaborating with ITO and engineering to aid oil and gas operations at Baker Hughes. Focusing on system objectives, product improvements, and client communications in Stord, Norway.