Irvine, CA

Salary
$103,170–$158,873
Posted
Aug 6, 2026
Location
Irvine, CA
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

An application security engineer role embedded within a Cyber Defense organization at an automotive IT services firm. The position is responsible for defining Secure SDLC standards, building and maintaining a hardened container image repository, integrating automated security testing (SAST, DAST, dependency scanning) into CI/CD pipelines, and driving vulnerability remediation in partnership with engineering and development teams.

Senior level · 5+ years · Los Angeles-Long Beach-Anaheim, CA · Full-time

Pay in the description: $103,170–$158,873

Quick apply — this platform usually takes a CV and a few fields.

Must have (6)
SASTDASTCI/CDSecure SDLCcontainer image hardeningOWASP Top 10
Nice to have (3)
Docker or Kubernetesthreat modelingCISSP, Cism, Csslp or Gwapt

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 120 people in the Los Angeles-Long Beach-Anaheim, CA area plausibly meet what this posting asks for (information security analysts). range 25–180

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,481 (middle half $96,915–$170,448). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 8, 2026. It is a model, not a headcount.

Why we read it this way (6)

The title reads 'Application Security Engineer III' but the body consistently frames this as a 'Senior Application Security Engineer' role — advertised seniority is called Senior based on that explicit framing.

SOC classification is a genuine judgment call: the role is primarily security analysis and governance (SAST/DAST integration, Secure SDLC, vulnerability management), pointing to 15-1212, but it also involves hands-on engineering work (building container image pipelines, CI/CD tooling), which could support 15-1252. 15-1212 was chosen as the primary because security analysis and standards-setting dominate the described responsibilities.

Docker and Kubernetes appear only under Preferred Qualifications ('e.g.' examples of container platforms), so both are marked preferred. They are listed separately because they are distinct tools used together, not interchangeable substitutes — though the posting does present them as examples of the same category.

The bachelor's degree requirement accepts 'equivalent work experience' as a substitute, so the degree requirement is set to None.

CISSP, CISM, CSSLP, and GWAPT are listed as 'highly desirable' certifications under Preferred Qualifications; CISSP is used as the primary skill name with the others as alternatives.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): open-source/dependency vulnerability scanning.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗