
AppSec Engineer – Remote
Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential.
Job Title: AppSec Engineer Location: 100% Remote (U.S.) Position Type: Full-time, Direct W2 Salary Range: $80,000–$100,000 Annually Experience Required: 6+ years
Sponsorship: U.S. Citizens, Green Card Holders, EAD Holders, and H-1B transfer candidates are encouraged to apply. We are unable to sponsor new H-1B visa petitions for this position.
Job Summary We are looking for an AppSec Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production.
Required Qualifications
Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
Five or more years of application security or security engineering experience.
Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns.
Hands-on experience performing code review across at least two major languages.
Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling.
Strong understanding of authentication, authorization, and cryptographic primitives.
Experience with cloud security and modern infrastructure controls.
Strong communication skills with technical and non-technical audiences.
Proficiency in at least one programming language for tooling and automation.
Experience working closely with engineering teams in an Agile environment.
Preferred Qualifications
Industry certifications such as OSCP, OSCE, GWAPT, or CISSP.
Experience with offensive security tooling and red-team operations.
Bug bounty experience, public CVEs, or open-source security contributions.
Familiarity with AI/LLM application security considerations.
Exposure to regulated industries with strict compliance requirements.
How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to Vision Technologies is an Equal Opportunity Employer.Equal Employment Opportunity (EEO) Statement
Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall.
BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.
Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. The company leverages cutting-edge technologies including large language models, AI-powered architectures, and enterprise integration platforms to create scalable, secure, and user-friendly applications. They specialize in LLM-based application architectures, prompt engineering strategies, and enterprise system integrations such as Coupa procurement solutions. The company is actively expanding its AI and machine learning capabilities while maintaining a focus on production-grade implementations across multiple business domains.