Logo for Riva Scientific

Application Security Engineer II

Role overview

Qualifications

  • 5+ years of experience in application security engineering roles
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design
  • Hands-on experience threat modeling and running security architecture reviews

Responsibilities

  • Secure AWS or comparable cloud-native environments with modern development practices
  • Secure AI/ML-powered systems focusing on prompt injection, model supply chain, and agentic-workflow risks
  • Collaborate cross-functionally with engineering, DevOps, and product teams
  • Define scope in a growing security program

About the company

Riva Scientific logo

Riva Scientific

IT Services & IT Consulting

Riva Scientific was started with a vision of offering core competencies, domain expertise, management, and industry best practices in an integrated and effective manner to deliver software solutions and services to the Pharmaceuticals, Life Sciences, Chemical, and Technology sectors. Our team of engineers, industry experts, thought leaders, and management specialists bring extensive experience in delivering fully validated and compliant systems and solutions meeting regulatory requirements such as US FDA’s GMP, 21 CFR Part 11, data integrity, and others. We optimize our delivery models per your requirements to ensure reliable, timely, and cost-effective results. Our wide range of services supports ongoing business needs from conceptualizing new product ideas, continued operational support to existing systems to regulatory compliance assessments & gap remediation.

Company details

IndustryIT Services & IT Consulting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

Position: Application Security Engineer II
Experience: 5+ years
Location: Remote



  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.

Nice to Have

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.


Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Riva Scientific

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.