Application Security Engineer at CivicPlus in Remote, United States
- Company: CivicPlus
- Location: Remote, United States
- Posted: Sep 24, 2026
- Type: Full-time
- Salary: $80k - $90k (anticipated hiring range); estimated grade range $70,300 - $101,300
- Experience: 7+ years
Overview
Your Impact As an Application Security Engineer you will help embed security across CivicPlus's software development lifecycle, leading application security testing and vulnerability remediation to protect the products local governments and residents rely on.
Job description
- Your Impact
- As an Application Security Engineer you will help embed security across CivicPlus's software development lifecycle, leading application security testing and vulnerability remediation to protect the products local governments and residents rely on.
Responsibilities
- Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC).
- Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC.
- Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements.
- Coordinate external, independent penetration testing of production environments.
- Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST).
- Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats.
Requirements
- We know that excellent candidates come from diverse backgrounds. Even if you don't meet 100% of the listed requirements, we encourage you to apply!
- 3–7 years of experience in application security, secure development, penetration testing, or a related field.
- Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST).
- Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations.
- Security+, GSEC, GSSP, or equivalent certification.
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred).
- Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments.
- AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality.
- Demonstrated ability to effectively use AI tools to enhance productivity and outcomes.
Skills
Preferred
- Secure coding practices
Benefits
- Estimated Salary Grade Range: $70,300 - $101,300
- Anticipated Hiring Range: $80k - $90k.
- The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience and is based on a 40-hour work week.
- Benefits: Comprehensive health insurance, dental insurance, vision insurance, Flexible Time Off, 401(k) plan, and more.
About CivicPlus
At CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured.