Atlanta, GA

Salary
Posted
Jul 1, 2026
Location
Atlanta, GA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual-contributor role responsible for owning and maturing an enterprise application security program at a retail company. Day-to-day work spans defining AppSec architecture and standards, embedding security into CI/CD pipelines, conducting code reviews and penetration testing, and securing AI/ML integrations. The role suits an experienced application security engineer comfortable operating as a technical authority across engineering teams and communicating risk to business stakeholders.

Senior level · 5+ years · Atlanta-Sandy Springs-Alpharetta, GA · Full-time

Must have (7)
application securityPython, Java, JavaScript or GoSAST or DastSnyk, Sonarqube, Semgrep or CheckmarxBurp Suite or Owasp Zapthreat modelingsecure code review
Nice to have (11)
penetration testingred teamPCI-DSSNISTOWASPAWS, Azure or GCPAI/MLCI/CDREST or GraphQLCSSLP, Oscp, Ceh or GwebSecurity+, Comptia Network+, Comptia A+, Isc2 Cc, Sscp or Cct

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 10 people in the Atlanta-Sandy Springs-Alpharetta, GA area plausibly meet what this posting asks for (information security analysts). range 5–15

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
secure code review4%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python62%application security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $134,382 (middle half $104,315–$168,301).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The role title is 'Lead Security Engineer – Application Security'; 'Lead' here functions as a seniority modifier equivalent to Senior, not a people-management title, so the level advertised in the title is set to Senior. The actual scope (owning an enterprise AppSec program, serving as final technical authority, broad org influence) also supports Senior rather than Staff — there is no clear cross-org, multi-team architectural authority that would push it to Staff.

SOC classification is Medium confidence. The role is primarily an Information Security Analyst (15-1212) given its AppSec program ownership, governance, compliance, and risk focus, but it has substantial hands-on software/DevSecOps engineering duties (CI/CD pipeline design, building AI-powered tooling) that could support 15-1252 Software Developers as a runner-up.

Location is inferred as Carter's Inc. headquarters in Atlanta, GA; no explicit city was stated in the posting.

The programming language requirement lists Python, Java, JavaScript, and Go as examples ('e.g.') of acceptable languages — proficiency in at least one is required. Python is used as the primary skill name with the others captured as alternatives.

SAST/DAST tooling is listed as a hard gate in the Must Have section. Snyk, SonarQube, Semgrep, and Checkmarx are listed as interchangeable SAST/DAST examples; Burp Suite and OWASP ZAP are listed as interchangeable manual/DAST testing tools — emitted as two separate skills reflecting these two distinct tool categories.

All skills under 'Preferred skills and experience' — including cloud platforms (AWS/Azure/GCP), AI/ML experience, PCI-DSS/NIST/OWASP frameworks, penetration testing/red team, CI/CD, REST/GraphQL, and certifications — are marked preferred. The Bachelor's degree is also only preferred, so the degree requirement is set to None.

No compensation figures were provided in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗