Senior Application Security Engineer (52213)

On-site$120k – $180k

About this role

Job DetailsPosition Type: Full Time / Experienced LevelSalary Range: $120,000.00 - $180,000.00 Salary/yearJob Category: Corporate ITCitrin Cooperman offers a dynamic work environment, fostering professional growth and collaboration. We’re continuously seeking talented individuals who bring a problem-solving mindset, fresh perspectives, and sharp technical expertise. We know you have choices, so our team of collaborative, innovative professionals are ready to support your professional development. At Citrin Cooperman, we offer competitive compensation and benefits and most importantly, the flexibility to manage your personal and professional life to focus on what matters most to you!

We are seeking a Senior Application Security Engineer to join our Information Security team within the Information Technology department. Candidate would be responsible for strengthening the security posture of our applications and cloud infrastructure. This role sits at the intersection of software engineering, cloud architecture, and security, with a focus on empowering developers to build secure software while hardening our cloud environment. You will design, implement, and operate security tooling across the software development lifecycle and champion a security first culture across engineering teams.

Responsibilities are, but not limited to

Application & Developer Security

Integrate security controls into the developer workflow, including SAST, DAST, SCA, secrets scanning, and IaC scanning.
Partner with development teams to remediate vulnerabilities and provide secure coding guidance and training.
Investigate, prioritize, and drive remediation of application security findings.
Conduct secure code reviews, security assessments, and vulnerability analysis.
Build self-service security tooling and repeatable security design patterns that make the secure path the easy path for developers.
Create and maintain security standards, procedures, and best practices that scale across teams.

Cloud Security

Design and implement security controls across Azure workloads, including identity (Entra ID), networking, encryption, and key management.
Configure and manage cloud-native security services.
Establish and enforce cloud security posture standards, compliance baselines, and guardrails using policy-as-code (e.g., Azure Policy).
Monitor, triage, and respond to cloud security findings and misconfigurations.
Deploy, tune, and operate CNAPP tooling (e.g., Wiz, Prisma Cloud, Microsoft Defender for Cloud, Aqua) covering CSPM, CWPP, CIEM, and container/Kubernetes security.
Prioritize and drive remediation of cloud and workload risks based on business context and exploitability.
Build dashboards and reporting to communicate cloud risk to technical and executive stakeholders.
Detect anomalies, investigate alerts, and respond to evolving threats across our cloud ecosystems.
Partner with product and engineering teams to integrate security into application design and development.
Lead threat modeling exercises and identify practical security solutions for complex systems.

CI/CD & SDLC Pipeline Security

Embed automated security gates and controls into CI/CD pipelines (e.g., GitHub Actions, Azure DevOps, GitLab, Jenkins).
Work with development team to secure the software supply chain, including artifact signing, dependency management, and SBOM generation.
Harden build environments, pipeline credentials, and deployment processes.
Define and measure security metrics and KPIs across the SDLC.

QualificationsThe ideal candidate must

Have a bachelor’s degree in computer science, cybersecurity, information security, or related field, or equivalent experience.
Have relevant certifications (e.g., Azure Security Engineer Associate, CKS, GIAC, OSCP).
Have a 5+ years of experience in Application Security, Secure Software Development, DevSecOps, Security Engineering, or a related cybersecurity discipline.
Have hands-on experience securing major cloud environments (AWS, Azure, GCP) and services.
Possess a strong understanding of application security concepts (OWASP Top 10, secure SDLC, threat modeling).
Have experience integrating security tooling into CI/CD pipelines.
Be proficient with at least one scripting or programming language (e.g., Python, PowerShell, Go).
Have familiarity with infrastructure-as-code (Terraform, Bicep, ARM) and containerization (Docker, Kubernetes).
Have a strong security-first mindset.
Be analytical and detail oriented.
Have excellent communication skills.
Be collaborative and accountable.

Company at a glance

Citrin Cooperman is one of the nation’s largest and fastest-growing professional services firms. Since 1979 our daily mission has been to help middle-market companies and high net worth individuals find success in their business and personal financial lives through our proactive guidance, specialized services, and passion for excellence. Rooted in our core values, we deliver a comprehensive, integrated business approach, including tailored insights throughout the lifecycle of our clients. Whether your operations and assets are located around the corner or across the globe, we provide new perspectives on strategies that help you achieve your short- and long-term goals. With over 30 offices and more than 3,300 professionals, Citrin Cooperman is included in the Top 20 Firms by Accounting Today. Learn more about Citrin Cooperman at citrincooperman.com.

"Citrin Cooperman" is the brand under which Citrin Cooperman & Company, LLP, a licensed independent CPA firm, and Citrin Cooperman Advisors LLC serve clients’ business needs. The two firms operate as separate legal entities in an alternative practice structure. The entities of Citrin Cooperman & Company, LLP and Citrin Cooperman Advisors LLC are independent member firms of the Moore North America, Inc. (MNA) Association, which is itself a regional member of Moore Global Network Limited (MGNL). All the firms associated with MNA are independently owned and managed entities. Their membership in, or association with, MNA should not be construed as constituting or implying any partnership between them.

Founded1979
Team Size1,001-5,000 employees
WorkspaceOn-site
IndustryProfessional Services

Top Benefits

  • Competitive compensation
  • Professional development support
  • Flexibility to manage personal and professional life

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?