✦ Luna Orbit — Cybersecurity

Senior Application Security Engineer

at Hewlett Packard Enterprise

Hybrid Posted March 17, 2026
Type Not Specified
Experience senior
Exp. Years Not specified
Education Not specified
Category Cybersecurity

This role involves strengthening application and API security within a large enterprise, integrating security practices into the SDLC, and automating vulnerability detection and remediation.

  • Integrate security practices throughout the SDLC
  • Promote secure coding standards
  • Design and maintain security controls within CI/CD
  • Automate security testing and vulnerability scanning
  • Conduct API risk assessments

The technical environment includes application security tools, CI/CD pipelines, WAF, SAST, DAST, container security, and threat modeling practices.

The ideal candidate is an experienced application security engineer with deep expertise in API security, secure SDLC practices, and security automation. They should have hands-on experience with WAF, SAST, DAST, and threat modeling, and be capable of influencing engineering teams in a large enterprise environment.

Application SecurityAPI SecurityDevSecOpsWAFSASTThreat Modeling
CI/CD PlatformsGitHub ActionsJenkinsGitLabAzure DevOpsAI Vulnerability ScanningSupply Chain SecuritySBOMSecrets Detection
GitHub ActionsJenkinsGitLabAzure DevOps
Application SecurityAPI SecurityCI/CDDevSecOpsWAFSASTDASTSCAContainer Image ScanningThreat ModelingCode SigningArtifact ValidationProvenanceSecurity ControlsVulnerability ScanningSecurity AutomationSecure CodingSecure API DesignCode ReviewsSecurity Testing
Application SecurityAPI SecurityCI/CDDevSecOpsWAFSASTDASTSCAContainer Image ScanningThreat ModelingCode SigningArtifact ValidationProvenanceSecurity ControlsVulnerability ScanningSecurity AutomationSecure CodingSecure API DesignCode ReviewsSecurity Testing
CollaborationCommunicationInfluencingMentoringProblem-solvingAutomation mindset
Industry Technology
Job Function Enhancing application and API security in enterprise environments
Role Subtype Cybersecurity
Tech Domains Application Security, API Security, DevSecOps, WAF, Security Controls
Application SecurityAPI SecurityCI/CDDevSecOpsWAFSASTDASTSCAContainer Image ScanningThreat ModelingCode SigningArtifact ValidationProvenanceSecurity ControlsVulnerability ScanningSecurity AutomationSecure CodingSecure API DesignCode ReviewsSecurity Testing

Lack of experience in application security or API security, No experience with security automation tools, No familiarity with WAF, SAST, DAST

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile