Python/Django Senior Application Security Engineer

Stellenbeschreibung:

Python/Django Senior Application Security Engineer (Hybrid - US)

We are seeking a Senior Application Security Engineer who will work with our development team to manage security and risk on our internally developed applications. The engineer will make risk‑based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms. This role is primarily focused on execution and consulting but should be familiar with roadmap and strategy and contribute where appropriate. Must have the ability to read, review, and make recommendations on secure Django/Python patterns.

Responsibilities

  • Contribute to the application security roadmap for our internal applications—prioritize risks and sequence work across codebases, application layer, and DevOps.
  • Consult with engineers to communicate requirements, create actionable tickets/acceptance criteria, and drive adoption.
  • Conduct pull request reviews focused on security, provide guidance on refactors, and approve/deny with clear rationale.
  • Serve as a steward for SAST/scanning: review static code scan results, triage findings, eliminate noise, and drive remediation with owners.
  • Build reference implementations in Django/Python (authentication patterns, input validation, secrets handling, rate limiting, geo‑based access) without direct responsibility for production feature development.
  • Map SOC2/NIST to engineering work: translate requirements into stories, controls, and automated evidence in CI/CD.
  • Threat modeling & architecture: navigate libraries/architectures and document secure patterns (ADRs/RFCs) that teams follow.
  • Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.
  • Collaborate with software developers and code base leads.
  • Act as a liaison between technical requirements from the business (security, privacy, compliance) and development teams.
  • Participate as a subject matter expert in security architecture, including new designs and design reviews.
  • Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.
  • Review architecture and compliance‑related code changes for security impact.
  • Ensure compliance with all company security policies and standards.
  • Manage and maintain all security related tickets, including recommendations, testing, and validation.

Qualifications

  • Minimum of 5 years of experience in application security.
  • Practice and implementation with Django/Python with a clear application‑security focus.
  • Engineering background (software or DevOps/SRE) with the ability to read/modify code, review PRs, and build PoCs.
  • Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
  • Experience embedding secure SDLC into Git‑based workflows and CI/CD (pre‑commit, pipeline gates, policy‑as‑code).
  • Practical knowledge of SOC2 and familiarity with NIST800-53; can turn requirements into technical tasks and evidence.
  • Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging/monitoring).
  • Clear, persuasive communication (verbal and written) and prioritization.
  • Excellent time management skills with a proven ability to meet deadlines.
  • Excellent interpersonal and negotiation skills.

Preferred Qualifications

  • Bachelors degree in Computer Science or equivalent work experience.
  • CISSP, GIAC, Security+, AWS Security and other related security certifications.
  • Prior experience reporting to or partnering with a security architect, or being the app‑sec lead in a smaller org.
  • Strong organizational skills and attention to detail.
  • Strong analytical and problem‑solving skills.
  • Ability to prioritize tasks according to severity.
  • Ability to adapt to the needs of the organization.
  • Proficient in AWS Security services (e.g., CloudWatch, GuardDuty).

Salary & Benefits

The salary range for this role is $119,100 – $147,400 annually, with a target compensation of $119,000 to $131,600 based on experience and qualifications. Compensation is commensurate with experience and includes a generous retirement package. Energy Solutions provides an excellent benefits package including medical, dental and vision insurance, other pre‑tax contribution plans and an Employee Stock Ownership Plan (ESOP).

Equal Opportunity Employer

Energy Solutions is an affirmative action‑equal opportunity employer and prohibits discrimination and harassment of any type. We afford equal employment opportunities to employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristics protected by law. Energy Solutions conforms to the spirit as well as to the letter of all applicable laws and regulations.

#J-18808-Ljbffr
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    18 Aug 2026
  • Standort:

    Remote
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!