
Application Security Engineer
LancesoftNew York, NY
Automate your job search with Sonara.
Submit 10x as many applications with less effort than one manual application.1
Reclaim your time by letting our AI handle the grunt work of job searching.
We continuously scan millions of openings to find your top matches.

Overview
Remote
On-site
Job Description
Hybrid in Charlotte, NC & New York, NY Application Security Engineer What You’ll Do
- Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering.
- Standing up and operating the AppSec tooling stack —SAST, SCA, secrets scanning, and container/IaC scanning —integrated into business unit CI/CD pipelines.
- Designing and implementing AI-assisted triage workflows on top of AppSec tooling so that finding volume does not overwhelm developers and false positives are filtered before reaching engineering teams.
- Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process.
- Partnering with business unit development leaders to build the relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.
- Contributing to AI security strategy —evaluating emerging tools (AI code review assistants, agentic security testing, automated security requirement generation) and recommending what to operationalize and what to defer.
- Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction.
- 7+ years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.
- Hands-on experience deploying and operating modern AppSec tooling (e.G., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security).
- Working code-level proficiency in at least three commonly-used languages (e.G., Python, JavaScript/TypeScript, Java, C#, Go) sufficient to read, review, and triage findings.
- Strong scripting and automation skills in Python or equivalent;comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
- Demonstrated ability to influence engineering organizations without direct authority —negotiating standards, driving adoption, and partnering with development leaders.
- Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks.
- Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).
- Familiarity with one or more compliance frameworks relevant to our environment (HITRUST, HIPAA, NIST AI RMF, SOC 2).
- Prior experience working in a regulated or healthcare-adjacent environment.
- Cloud security depth in at least one major provider (AWS, Azure, GCP).
Automate your job search with Sonara.
Submit 10x as many applications with less effort than one manual application.

FAQs About Application Security Engineer Jobs at Lancesoft
What is the work location for this position at Lancesoft?
This job at Lancesoft is located in New York, NY, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Lancesoft?
Candidates can expect a pay range of $65.
What employment applies to this position at Lancesoft?
The employer has not provided this information. This may be discussed during the hiring process.
What is the process to apply for this position at Lancesoft?
You can apply for this role at Lancesoft either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.