AppSec Security Engineer

Ares Management CorporationArlington, VA
$240,000 - $270,000Hybrid

About The Position

We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this role, you will embed directly with our Product and Engineering teams to secure both our third-party SaaS applications and our home-grown applications. You will serve as a trusted security consultant and a hands-on engineer. You will review complex API designs, threat model new features, and build custom security tooling. You will play a critical role in defining security development standards from scratch and automating security controls directly into our CI/CD pipelines. We’re seeking someone who is excited to bring an automation-first mindset and who knows how to balance developer needs with risk-informed pragmatism. You will bridge security, development and operation cultures by translating between development who want speed, security teams who want safety, and operation teams who want stability. We value diverse backgrounds, perspectives, and experiences, and we are committed to building a team where everyone feels they belong. We especially encourage candidates from underrepresented communities in cybersecurity and technology to apply. Our interview process focuses on problem-solving ability, practical skills, and collaborative mindset.

Requirements

  • Proficient in SAST/SCA/DAST, container/IaC scanners, and secret scanning into pipelines.
  • Hands-on with one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins).
  • Proficient in Terraform/IaC, Kubernetes, and cloud provider security (Azure preferred).
  • Significant hands-on application security experience, including expert knowledge of established standards (OWASP Top 10, API Security Top 10, OWASP LLM Top 10) and how common vulnerability classes manifest in production systems.
  • Strong Threat modeling and security review experience with Product and Engineering teams.
  • Experience building security tooling or automation (scripts, pipelines, libraries).
  • Familiarity with Azure and Kubernetes security controls as they relate to application-layer risks.
  • Demonstrated experience reviewing API designs and implementations for auth anti-patterns, token mismanagement, injection risks, and sensitive data exposure.
  • Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch.
  • Familiarity with OIDC workload identity, artifact registries, and software supply chain controls.
  • Clear communicator who can translate risk into engineering work.

Nice To Haves

  • Built policy gates with OPA/Gatekeeper or Kyverno; authored custom policies.
  • Azure Security Certification is preferred.
  • Advanced certifications in cloud and AI security are a plus.

Responsibilities

  • Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tools into pipelines for home-grown apps.
  • Develop secure IaC patterns using Terraform, Helm, and Kustomize.
  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default.
  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products.
  • Lead security design and threat modeling sessions based on OWASP Top 10 and Mitre & Attack with Product and Engineering teams during early software design phases.
  • Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks.
  • Define and validate security controls for Azure and Kubernetes to mitigate application-layer risks.
  • Define AppSec coverage, tooling, and assessment processes from scratch across our application landscape.
  • Own and evolve our application security program including establishing and maintaining SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production.
  • Partner with engineering teams and stakeholders to remediate vulnerabilities and drive long-term improvements in secure coding practices.
  • Translate complex security risks into clear, actionable engineering requirements for development teams.

Benefits

  • Comprehensive Medical/Rx, Dental and Vision plans
  • 401(k) program with company match
  • Flexible Savings Accounts (FSA)
  • Healthcare Savings Accounts (HSA) with company contribution
  • Basic and Voluntary Life Insurance
  • Long-Term Disability (LTD) and Short-Term Disability (STD) insurance
  • Employee Assistance Program (EAP)
  • Commuter Benefits plan for parking and transit
  • Access to a world-class medical advisory team
  • A mental health app that includes coaching, therapy and psychiatry
  • A mindfulness and wellbeing app
  • Financial wellness benefit that includes access to a financial advisor
  • New parent leave
  • Reproductive and adoption assistance
  • Emergency backup care
  • Matching gift program
  • Education sponsorship program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service