Logo for CivicPlus

Application Security Engineer

Role overview

Qualifications

  • 3–7 years of experience in application security, secure development, penetration testing, or a related field
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST)
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred)
  • Security+, GSEC, GSSP, or equivalent certification

Responsibilities

  • Perform security code reviews, threat modeling, and architecture reviews across all development projects
  • Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC
  • Identify, track, and validate vulnerabilities and security defects from security testing and scanning
  • Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST)

Key facts

  • Remote from: United States
  • Full time
  • Senior (5-10 years)
  • Application Security Engineer
  • English

Hard skills

Other skills

  • Collaboration
  • Communication

About the company

CivicPlus logo

CivicPlus

IT Services & IT Consulting

CivicPlus is the only government technology company exclusively committed to powering and empowering governments to efficiently operate, serve, and govern through the use of our innovative and integrated technology solutions purpose-built and supported by former municipal leaders and award-winning support teams. When many residents hear the word government, they think of federal and state leaders and agencies. However, in reality, residents interact more with the local leaders whose work and initiatives impact them directly where they live, work, play, and raise their families. At CivicPlus®️, we believe that every interaction between residents and their local government should be exceptional and frictionless. It’s why we build technology solutions designed to foster positive and powerful civic experiences. With more than 20 years of experience, CivicPlus has earned the trust of over 12,000 customers, their 100,000+ local government users, and their 340 million+ residents in the U.S. and Canada alone.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Your Impact

As an Application Security Engineer you will help embed security across CivicPlus's software development lifecycle, leading application security testing and vulnerability remediation to protect the products local governments and residents rely on.

About CivicPlus

At CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured.

What You'll Do

As an Application Security Engineer, you will:

  • Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC).
  • Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC.
  • Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements.
  • Coordinate external, independent penetration testing of production environments.
  • Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST).
  • Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats.

What We're Looking For

We know that excellent candidates come from diverse backgrounds. Even if you don't meet 100% of the listed requirements, we encourage you to apply!

Preferred Qualifications:

  • 3–7 years of experience in application security, secure development, penetration testing, or a related field.
  • Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST).
  • Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations.
  • Security+, GSEC, GSSP, or equivalent certification.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred).
  • Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments.
  • AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality.
  • Demonstrated ability to effectively use AI tools to enhance productivity and outcomes.

Compensation and Benefits

  • Estimated Salary Grade Range: $70,300 - $101,300
    • Anticipated Hiring Range: $80k - $90k.
    • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience and is based on a 40-hour work week.
  • Benefits: Comprehensive health insurance, dental insurance, vision insurance, Flexible Time Off, 401(k) plan, and more.

Our Hiring Process

  1. Introductory call with Talent Acquisition
  2. Interview with the Hiring Manager
  3. Panel Interview with CivicPlus team members, including an interview project activity
  4. Offer

Note: The process may vary slightly depending on the role.

Additional Information

  • CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US.
  • This position will remain open until October 7, 2026 at 4pm CT. We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team.
  • At CivicPlus, we embrace AI and automation as tools that help people work smarter, move faster, and focus on higher-value work that strengthens communities. We encourage thoughtful, responsible use of technology to improve efficiency, support innovation, and enhance the employee and customer experience—while keeping human judgment, collaboration, and accountability at the center of what we do.

Equal Opportunity Commitment

CivicPlus is proud to be an Equal Employment Opportunity employer. We celebrate and support diversity for the benefit of our employees, products, clients, and communities. Reasonable accommodations are available during the interview process.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at CivicPlus

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.