About this role
About the Role Arctic Wolf is transforming its Application Security function to be AI-first. We are seeking a Senior AppSec Engineer to scale secure-by-design practices across cloud, SaaS, and AI-enabled platforms, partnering with engineering teams to identify, assess, and reduce application security risk throughout the software development lifecycle. What You'll Do
- Conduct threat modeling exercises for applications, APIs, microservices, and AI/LLM-enabled capabilities
- Perform application security reviews and vulnerability assessments across the SDLC
- Triage and validate findings from SAST, DAST, SCA, IaC, container, and other AppSec security tools
- Partner with engineering teams to provide clear, actionable remediation guidance and support risk-based decision making
- Support secure development practices by identifying opportunities for process, tooling, and workflow improvements
- Contribute to the refinement of security standards, SOPs, playbooks, and reusable security guidance
- Help drive adoption and optimization of AppSec tooling and automation across engineering teams
- Collaborate with developers, product managers, architects, and Security Champions to improve security awareness and maturity
- Mentor junior engineers, interns, or peers and contribute to a culture of continuous learning
- Stay current on emerging application security risks, attack techniques, vulnerabilities, and industry best practices What We're Looking For
- 5+ years of experience in application security, secure software development, or related security engineering roles
- Strong understanding of application security fundamentals including OWASP Top 10, secure coding principles, and common attack patterns
- Experience conducting threat modelling and security architecture reviews
- Hands-on experience with AppSec tooling such as SAST, DAST, SCA and vulnerability management platforms
- Experience validating and triaging security findings and working directly with engineering teams on remediation
- Familiarity with cloud-native application architectures and modern development practices
- Ability to communicate technical security risks and recommendations clearly to developers, product managers, and leadership audiences
- Strong analytical and problem-solving skills with the ability to identify root causes and propose practical solutions
- Ability to independently manage multiple priorities and drive deliverables to completion Nice to Have
- Experience securing cloud environments in AWS, Azure, or GCP
- Familiarity with AI/GenAI application security concepts and frameworks such as the OWASP Top 10 for LLMs
- Experience in SaaS environments, microservices architectures, or large-scale engineering organizations
- Familiarity with CI/CD pipelines and DevSecOps practices Compensation & Benefits Not disclosed.