×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer

Job in Farmington Hills, Oakland County, Michigan, USA
Listing for: Amerisure Insurance
Full Time position
Listed on 2026-01-26
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant, Systems Engineer, Cloud Computing
Job Description & How to Apply Below

Overview

Amerisure creates exceptional value for its partners, policyholders, and employees. As a property and casualty insurance company, Amerisure’s promise to our partner agencies and policyholders begins with a comprehensive line of insurance products designed to protect businesses, as well as the health and safety of every employee. With an A.M. Best “A” (Excellent) rating, Amerisure serves mid-sized commercial enterprises focused in construction, manufacturing and healthcare.

Ranked as one of the top 100 Property & Casualty companies in the United States, we proudly manage nearly $1 Billion of Direct Written Premium and maintain $1.21 billion in surplus.

Amerisure is hiring!! This role would require someone to be onsite hybrid in our Farmington Hills office. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to safeguard our applications from the ground up. The ideal candidate will possess the following skill set.

Responsibilities

The Senior IT Security Engineer designs, implements, and maintains security controls to protect the organization’s systems and data. This role leads security monitoring, vulnerability management, and incident response efforts, while embedding security throughout the SDLC and integrating testing capabilities into CI/CD pipelines. The engineer supports secure development practices and conducts application and API penetration testing. Working closely with development, QA, Dev Ops, and architecture teams, this role strengthens the security posture of mission-critical SaaS and hybrid cloud applications.

The Senior Engineer also advises leadership on security strategies, emerging technologies, and alignment with business goals, ensuring innovative, compliant, and effective security solutions.

  • Configure, implement, and maintain security systems with a hands-on approach to ensure the integrity, availability and resilience of the organization’s IT infrastructure, applications and data.
  • Serve as a subject matter expert for application, API, and integration security across the enterprise. Establish and embed secure development requirements, best practices, patterns, and guardrails (Left Shift) across platforms, technology stacks, and development teams to enhance the overall application and API security posture.
  • Define, design, implement, and continuously improve application security processes, tools, and metrics. Integrate and optimize SAST, SCA, IAST, DAST, and secrets detection tools within CI/CD pipelines, and monitor, track, and report application and API security metrics to leadership.
  • Conduct comprehensive application and API security reviews, vulnerability assessments, and penetration testing, actively configuring and fine-tuning security tools to identify and remediate gaps.
  • Collaborate with cross-functional teams to enforce security best practices and ensure compliance with relevant standards and frameworks (e.g., NIST CSF, NY DFS, MI DIFS, OWASP, HIPAA/HTRUST), configuring security solutions to meet evolving business and regulatory requirements.
  • Lead incident response and digital forensics investigations, providing technical expertise to analyze cyber events and implement effective remediation actions that minimize operational impact.
  • Mentor and guide security team members, sharing knowledge and expertise in application and API security, threat analysis, vulnerability management, cloud security, and cryptography, while fostering a collaborative, learning-driven team culture.
Qualifications

Knowledge, Skills & Abilities

  • Bachelor’s degree or equivalent combination of education and experience.
  • 7+ years of experience in Application and API Security within a Dev Sec Ops  environment.
  • Required certifications include at least one CISSP, CSSLP, CCSP, GSEC, CEH, CISM, or CRISC, in addition to platform-specific certifications (AWS, Microsoft, Cisco, etc.) or domain specific certifications (OSWE, OSCP, GWAPT, or GWEB).
  • Experience in Property & Casualty insurance or other regulated industries preferred.
  • Proven experience securing SaaS and custom applications in complex…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary