Application security engineer

  • Full Time
  • Remote

Explore Available Jobs with a Simple Search...

Application security engineer

About TaxDome

At TaxDome, we’re building the #1 practice management platform for accounting firms in the US and globally. Founded in 2017, we’ve grown into a 400+ fully remote team across 40+ countries, serving tens of thousands of businesses worldwide with millions of end clients.

How we work

You’ll be part of a globally distributed teambuilt on trust, ownership, and self-management.

We focus on outcomes over activity — prioritizing clear ownership, pragmatic decision-making, and accountability for results over rigid processes. Collaboration is central to how we operate: we communicate openly, involve the right people early, and continuously improve how we build products and teams together.

About this role

We’re looking for a Senior Application Security Engineer to join our engineering organization. You will not just “run tools” — you will own the application security roadmap. You will act as a bridge between security, development, and DevOps, ensuring that our SaaS platform remains secure by design without slowing down our release velocity. We need a builder and a strategist. You will be responsible for maturing our security posture according to the BSIMM framework, automating security within our CI/CD pipelines, and fostering a culture of security among our developers.

What you’ll be responsible for

  • Build the Program: Spearhead the creation and evolution of our Application Security program, utilizing the BSIMM (Building Security In Maturity Model) framework to measure growth and identify gaps.
  • Secure Design & Threat Modeling: Partner with engineering squads during the design phase. Initially, develop threat models for new features and architectural changes to identify flaws before code is written. Eventually, move to the coach role, and review the threat models produced by security champions embedded in development teams.
  • Tooling & Automation: Select, configure, and manage the AppSec tool stack (SAST, DAST, SCA, IAST). Focus on “shifting left” by integrating these tools directly into our CI/CD pipelines to provide rapid feedback to developers.
  • Vulnerability Management: Triage automated findings to filter out false positives. Work directly with developers to explain the risk of vulnerabilities and provide specific code-level remediation guidance in Ruby or TypeScript.
  • Policy & Governance: Create and enforce pragmatic application security policies, architecture, and coding standards to ensure delivery of a secure product.
  • Security Champions: Build and mentor a “Security Champions” program within the development teams to scale security knowledge across the organization.
  • Incident Support: Assist the infrastructure/SecOps teams during security incidents, specifically regarding application-layer vector analysis and forensic code reviews.

What you bring

Must-have

  • Engineering Background: 5+ years of total experience in software engineering or DevOps. You must have a software engineering background.
  • AppSec Experience: 3+ years of dedicated experience in Application Security.
  • Tech Stack Proficiency: Strong familiarity with Ruby on Rails and TypeScript. You should be able to spot a logical vulnerability in a Rails controller or an XSS flaw in a front-end component during a manual code review.
  • Core Knowledge: Deep understanding of the OWASP Top 10, OWASP API Top 10, CWE Top 25, and common attack vectors (SQLi, XSS, SSRF, IDOR, Deserialization).
  • CI/CD Integration: Proven experience integrating security tools into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Autonomy: You are a self-starter who can define your own priorities, manage stakeholders, and drive projects to completion without micromanagement.
  • Experience with Docker and Kubernetes, and a deep understanding of container security and EKS best practices.

Nice-to-have

  • Our preference is for a builder archetype, but we would consider candidates with breaker/red team experience.
  • Cloud Security: Experience securing applications deployed on AWS.
  • Compliance: Experience assisting with SOC2 Type II, ISO 27001, and GDPR compliance audits.

What we offer

At TaxDome, we aim to create an environment where people can do their best work and grow alongside the company.

  • Competitive compensation, paid in USD
  • Fully remote work with flexible hours
  • 30 paid days off annually, plus sick days as needed
  • Health & well-being support
  • Learning & development budget to support your professional growth
  • English lessons reimbursement
  • Co-working space reimbursement
  • Company-provided equipment (conditions may vary depending on the role)
  • A high level of autonomy and ownership in your work
  • The opportunity to make a real impact in a fast-growing global SaaS company
  • A collaborative, international team with a strong product mindset

Job Overview

Offered Salary
Career Level
Industry
IT & Software Developmentit
Experience
Qualification
error: Content is protected !!
Select your currency
NGN Nigerian naira