Back to Signal
Pulse Relay

AppSec Engineer

SeniorProduct SecurityRemoteSydney, NSW
$200k
Open to Right Opportunity

Quick Match Check

Key Skills

SAST/DAST (SonarQube, Checkmarx, Burp Suite Enterprise)Cloud Security (AWS, Azure)Container Security (Docker, Kubernetes)Threat Modeling (STRIDE, DREAD)API Security (OIDC, OAuth2, JWT)Python (for automation and scripting)CI/CD Pipeline Integration (Jenkins, GitLab CI)Web Application Firewalls (WAF)

Roles Worked

Senior Application Security Engineer
API Security Engineer
Backend Developer

Industry Experience

TechSaaSCloud Infrastructure

CyberSec People will make the introduction

Skills Assessment

1st PrinciplesCode BiasTech DepthCuriosityWar Stories8.09.09.08.08.0
1st Principles8/10

Breaks down complex problems into fundamental truths and builds solutions from the ground up

Code Bias9/10

Prefers building and shipping code over meetings and documentation

Tech Depth9/10

Deep technical expertise across security domains, tools, and architectures

Curiosity8/10

Constantly learning, experimenting, and staying ahead of emerging threats

War Stories8/10

Battle-tested experience solving real-world security incidents and challenges

Profile Summary

This Senior AppSec Engineer architects and implements robust security controls directly into the software development lifecycle, ensuring applications are secure by design. They are adept at identifying vulnerabilities early and building automated solutions that scale across large enterprise environments. Their mission is to fortify critical systems and empower development teams to deliver secure products efficiently.

Problems Solved

  • Reduced critical application vulnerabilities by 45% within 12 months at a major Australian bank (e.g., CBA) by integrating DAST/SAST tools and providing targeted developer training.
  • Engineered and deployed a custom static analysis pipeline for a cloud-native platform, identifying over 200 high-risk security flaws before production release and reducing manual review effort by 30%.
  • Developed an automated vulnerability remediation tracking system that decreased average fix time for high-severity findings by 25% across 15+ development teams.

What They Build

They build secure software development lifecycles (SSDLCs), integrating security tooling and processes from design to deployment. Their focus is on creating scalable, automated security solutions that empower developers to write secure code and minimize security debt.

What Would Make Them Move

Want a senior AppSec engineer role focused on API security and microservices. Looking for a company with a complex distributed architecture where security is genuinely hard. Not interested in compliance-driven orgs — want engineering-driven security.

Mission & Values

Application security is where the rubber meets the road. I have seen what happens when security is an afterthought, and I am driven to make sure it is never an afterthought again.

Growth Areas

DevSecOps CultureContainer SecuritySecure SDLC Design