Support application security activities across the SDLC , including design, development, testing, release, and post-release review.
Work with Engineering and Security teams to identify, document, and track application security risks, including issues related to insecure design, weak access control, exposed secrets, vulnerable components, misconfigurations, and other common software risks.
Assist with reviewing application security findings, understanding risk context, coordinating with owners, and tracking remediation or accepted exceptions through closure.
Support basic threat modeling activities by helping identify application assets, data flows, trust boundaries, misuse scenarios, and potential security requirements.
Help promote awareness of common application security vulnerabilities, including OWASP Top 10 risks, secure coding principles, authentication and authorization concerns, input validation, data protection, and secure configuration.
Maintain clear documentation for application risks, remediation status, ownership, exceptions, timelines, and follow-up actions.
Support secure design and security review discussions for new features, product changes, integrations, and higher-risk application workflows.
Collaborate with Engineering, Product, IT, and Security teams to improve secure-by-design practices and reduce software risk over time.
Provide limited support to SOC/security operations when application-related alerts, incidents, or evidence require AppSec input, context, or follow-up.
Source code repositories and development workflow platforms
Issue-tracking and remediation management tools
CI/CD and release workflow documentation
Security documentation, risk registers, and exception trackers
Basic cloud and enterprise environments such as AWS, Azure, and Microsoft 365
Limited exposure to SOC workflows, application-related alerts, logs, incident records, and security evidence
2+ years of experience in application security, information security, software security, security operations, software engineering, or a related technical area.
Basic understanding of the software development lifecycle (SDLC) and how security fits into design, development, testing, release, and maintenance activities.
Foundational understanding of common application security vulnerabilities, including OWASP Top 10 concepts such as broken access control, injection, insecure design, authentication issues, vulnerable components, and security misconfiguration.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career