Senior Application Security Engineer
Quick Summary
Perform security assessments, including penetration testing, vulnerability scanning, and code reviews, to identify security weaknesses in applications.
Via is using technology to transform transportation around the world. From changing a single person’s daily commute to reducing humanity’s collective environmental footprint — we’ve got huge goals.
As a Senior Application Security Engineer at Via, you will be a key member of the team, responsible for ensuring the security of Via's applications throughout the software development lifecycle. You will work closely with development, operations, and product teams to identify and mitigate vulnerabilities, promote secure coding practices, and build a robust application security program.
Responsibilities
~1 min read- →Perform security assessments, including penetration testing, vulnerability scanning, and code reviews, to identify security weaknesses in applications.
- →Collaborate with development teams to remediate identified vulnerabilities and implement secure coding practices.
- →Define and implement application security testing strategies, including static analysis, dynamic analysis, and software composition analysis.
- →Use AI (LLMs, agents, MCP-based tooling) to improve AppSec work such as vulnerability triage, code review, remediation and detection, and set best practices for doing so safely.
- →Design and build security tooling and automation, such as CI/CD integrations, internal services and AI-assisted workflows.
- →Contribute to the development and maintenance of application security policies, standards, and procedures.
- →Research and evaluate new application security tools and technologies.
- →Monitor application security metrics and provide regular reports on the security posture of applications.
- →Participate in incident response activities related to application security.
- →Champion a security-first culture within the engineering organization.
- A Bachelor's degree in Computer Science or a related field is a plus.
- Minimum of 4 years of experience as an Application Security Engineer or a similar role.
- Strong understanding of application security concepts, including OWASP Top 10, CWE Top 25, and SANS Critical Security Controls.
- Experience with various application security testing tools and techniques (e.g., SAST, DAST, SCA).
- Proficiency in at least one scripting language (e.g., Python, JavaScript, Ruby).
- Experience with secure coding practices and vulnerability remediation.
- Familiarity with CI/CD pipelines and DevOps practices.
- Excellent communication and collaboration skills.
- Ability to work independently and as part of a team.
- Experience with cloud platforms (AWS is an advantage).
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 7, 2026
- First seen
- October 7, 2026
- Last seen
- October 7, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- October 7, 2026
Signal breakdown
Via Transportation, Inc. is a technology company providing software and operational solutions to optimize public transportation networks globally, aiming to make transit more efficient, equitable, and sustainable.
View company profileBrowse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
