Logo for Technosylva

Senior Application Security Engineer

Role overview

Qualifications

  • Minimum 10 years of experience across Application Security, S-SDLC/DevSecOps, or Software Engineering/Security Engineering
  • Proven track record driving AppSec programs in medium or large organizations within modern SDLC, cloud-native, and SaaS environments
  • Strong technical expertise in AppSec fundamentals: OWASP Top 10, API security, multi-tenant application security, threat modeling, and security architecture reviews
  • Hands-on DevSecOps experience: CI/CD pipeline security, SAST/DAST, SCA, secrets management, container/Kubernetes security, and IaC security

Responsibilities

  • Lead the evolution of Technosylva's Application Security program and roadmap, defining and improving secure SDLC processes across all engineering teams
  • Establish scalable security-by-design practices integrated into development workflows
  • Build practical and measurable AppSec KPIs and reporting for leadership
  • Work closely with DevOps and Engineering teams to embed security into CI/CD pipelines

About the company

Technosylva logo

Technosylva

Cleantech / Climate Tech

Technosylva is the leading provider of wildfire and extreme weather risk mitigation solutions for electric utilities and fire agencies. Since 1997, we've operationalized wildfire science to support critical decisions that enhance daily operations and long-term planning. Our mission is to reduce the impact of wildfires and extreme weather through real-time insights and predictive modeling. Our solutions combine the best source data and science, cutting edge AI and modeling, operationally proven application software, and industry-leading scientists and experts to support the most complex and important decisions made by utilities and fire agencies. Follow us here on LinkedIn for: • Actionable insights on wildfire risk and other extreme weather • Use cases from electric utilities and fire agencies worldwide • How to apply tech-enabled decision support for public safety and infrastructure • Collaboration models for coordinated wildfire and weather response Whether you’re responding in real time or just getting started with a wildfire and extreme weather plan, we’re here to help you make informed, effective decisions.

Company details

IndustryCleantech / Climate Tech
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

ROLE OVERVIEW 

Technosylva is seeking a highly experienced Senior Application Security Engineer to elevate and mature our Application Security (AppSec) program across a modern cloud-native software environment.

This role is not limited to technical execution. We are looking for a security professional who combines deep hands-on AppSec expertise with strong business, communication, coordination, and program execution skills. The ideal candidate will partner closely with Engineering, Product, Platform, Infrastructure, and Security leadership to drive scalable security improvements across the software development lifecycle (S-SDLC).

This position will play a key role in transforming AppSec from a primarily tooling-focused function into a strategic, measurable, and business-aligned security capability.


RESPONSABILITIES 

  • Lead the evolution of Technosylva's Application Security program and roadmap, defining and improving secure SDLC processes across all engineering teams.
  • Establish scalable security-by-design practices integrated into development workflows, driving adoption of secure coding standards, threat modeling, and security architecture reviews.
  • Build practical and measurable AppSec KPIs and reporting for leadership.
  • Improve and optimize GitLab/GitHub security capabilities and integrations (SAST, DAST, dependency scanning, container scanning, secrets detection, and IaC security workflows).
  • Work closely with DevOps and Engineering teams to embed security into CI/CD pipelines, defining risk-based security gates and exception processes while reducing developer friction.
  • Partner directly with developers, architects, and technical leads to remediate vulnerabilities, translate security requirements into actionable tasks, and conduct code reviews.
  • Establish mature application vulnerability management processes: improve triage, prioritization based on business risk, SLAs, tracking through closure, and executive reporting.
  • Own and drive AppSec initiatives from planning through execution across cross-functional teams (Engineering, Infrastructure, Product, Security), producing clear documentation and implementation plans.
  • Help improve security culture within engineering teams by delivering secure coding guidance, workshops, awareness sessions, and mentoring junior engineers.
  • Act as a trusted advisor rather than only an enforcement function, adapting communication effectively for both technical and non-technical stakeholders.


REQUIREMENTS 

  • Minimum 10 years of experience across Application Security, S-SDLC/DevSecOps, or Software Engineering/Security Engineering.
  • Proven track record driving AppSec programs in medium or large organizations within modern SDLC, cloud-native, and SaaS environments.
  • Strong technical expertise in AppSec fundamentals: OWASP Top 10, API security, multi-tenant application security, threat modeling, and security architecture reviews.
  • Hands-on DevSecOps experience: CI/CD pipeline security, SAST/DAST, SCA, secrets management, container/Kubernetes security, and IaC security (Terraform preferred).
  • Strong understanding of software engineering practices, experience with modern development frameworks/APIs, and the ability to read and review production-grade code.
  • Strong business and operational capabilities: project management, executive-level reporting, documentation practices, and prioritizing work based on business risk.
  • Excellent communication, coordination, and interpersonal skills, with the ability to influence engineering teams without direct authority.
  • High level of ownership, autonomy, maturity, and proactive problem-solving.


PREFERRED QUALIFICATIONS

  • Penetration testing experience, red teaming, or an offensive security background.
  • Experience leading vulnerability management programs, security automation, and scripting.
  • Practical experience applying AI/ML tools in development and cybersecurity (e.g., ChatGPT, Claude, GitHub Copilot).
  • Specialized experience with GitLab / GitHub Security features.
  • Security certifications such as CSSLP, CISSP, OSCP, GIAC, or Azure/AWS certifications.


BENEFITS 

  • Competitive annual salary.
  • Private health insurance and a flexible benefits plan, allowing you to tailor part of your compensation package to your personal needs.
  • Annual bonus based on individual performance and company results.
  • Flexible working hours.
  • Remote work options.


At Technosylva, we value diverse experiences and skills, and we understand that every career path is unique. We encourage anyone who believes they meet most of the requirements and is interested in growing and contributing in this role to apply.


DISCLAIMER

Final salary and benefits will depend on a variety of factors, including location, experience, training, qualifications, and market conditions.


EQUAL OPPORTUNITY STATEMENT

Technosylva is an Equal Opportunity Employer. We are committed to fostering an inclusive environment where diverse perspectives lead to better solutions.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Technosylva

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.