Application Security Engineer I

CarGurusBoston, MA
$96,000 - $120,000Hybrid

About The Position

CarGurus is looking for an Application Security Engineer I to join our growing Security Engineering and Architecture team. This is a hands-on technical role focused on helping secure the applications, products, and infrastructure that power CarGurus. In this role, you will partner with engineers and senior security team members to help review services for security best practices, support vulnerability remediation, and contribute to security guardrails that reduce common application and developer-environment risks. This role is a strong fit for someone early in their security career who is excited to learn application security fundamentals, build practical technical skills, and grow in a collaborative engineering environment.

Requirements

  • 0 to 2 years of experience in cybersecurity, application security, software engineering, or a related technical field
  • Interest in leveraging modern technologies, including AI and ML, to improve security outcomes
  • Familiarity with application security concepts such as secure coding, vulnerability management, threat modeling, or risk assessment
  • Familiarity with cloud infrastructure and technologies such as AWS, Kubernetes, containers, or infrastructure as code
  • Familiarity with standard SDLC processes and engineering tools such as GitHub and CI/CD automation
  • Familiarity with at least one programming or scripting language such as Python, Go, Java, or a similar language
  • Strong passion for continuous learning, especially in cybersecurity and technology

Nice To Haves

  • Internship, co-op, academic, or hands-on project experience in security or software development is a plus

Responsibilities

  • Support threat modeling and security risk assessments for CarGurus applications and products
  • Assist in training developers on secure coding, AI-assisted development, and secure SDLC practices
  • Help triage, prioritize, assign, and track remediation of vulnerabilities
  • Contribute to the operation and improvement of code and infrastructure scanning tools and policies that help monitor and enforce security guardrails
  • Assist in investigations involving application security issues
  • Partner with development teams and senior security engineers to help design and implement security controls for a cloud-first infrastructure (AWS, Kubernetes, and related technologies)

Benefits

  • equity for all employees
  • career development programs
  • corporate giving programs
  • employee resource groups (ERGs) and communities
  • flexible hybrid model
  • robust time off policies
  • daily free lunch
  • new car discount
  • meditation and fitness apps
  • commuting cost coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service