The insurance industry runs on Vertafore. We equip agencies, MGAs, and carriers with the core digital systems, specialized AI, and data-driven foundation to eliminate distribution drag across the insurance lifecycle, spanning sales, servicing, and back-office operations. Underpinned by unmatched speed and performance power, we are the trusted backbone that’s taking the insurance industry from friction to flow with Distribution Velocity – speed, performance, and trust - to drive growth at scale. With over 95% of the top agencies and insurers and 50% of industry compliance transactions running through Vertafore, we lead at the intersection of innovation and trust, giving insurance professionals the confidence to transform and win in the AI era. Our reach is global, with headquarters in Denver, Colorado, and offices across the U.S., Canada, and India. The Senior Application Security Engineer is responsible for advancing application, product, cloud, API, identity, and AI security across Vertafore’s software engineering organization. This role partners directly with product, engineering, architecture, DevOps, cloud, and security teams to identify risk early, define secure design patterns, and embed scalable security controls into the software development lifecycle. This role will serve as a hands-on technical security partner for application teams, helping them understand and document application architecture from a security perspective, identify trust boundaries and attack paths, and implement practical mitigations. The Senior Application Security Engineer will support secure design reviews, threat modeling, secure coding practices, vulnerability management, CI/CD security controls, API security, identity and access management patterns, and emerging AI/agentic product security capabilities. A key focus of this position is securing AI-enabled applications and AI agents integrated into Vertafore products. This includes understanding AI agent architecture, authentication and authorization patterns, memory handling, prompt tracing, tool/plugin access, guardrails, model and runtime behavior, AI runtime scanning, and secure use of code-assist tools within engineering workflows. The ideal candidate is a strong application security practitioner who can translate complex technical risk into actionable engineering guidance, influence teams without direct authority, and help product teams ship securely without unnecessary friction.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed