Leading application security efforts, the full-time Vermont Licensed Senior Security Engineer will manage the AppSec program across the software development lifecycle, conduct threat modeling, and ensure secure coding practices while working in a remote-friendly environment. Key responsibilities Own and evolve the AppSec program from design reviews to post-deployment monitoring for various product deliverables Conduct threat modeling and architecture security reviews for new features and services Manage third-party and supply chain security, including the Software Bill of Materials (SBOM) program Required qualifications 5+ years of experience in security engineering with a strong focus on application security Hands-on experience with threat modeling frameworks (e.g., STRIDE, PASTA) Proficiency with common application security tools such as Semgrep, Snyk, and Burp Suite Deep understanding of web application vulnerabilities and secure coding practices Experience with software supply chain security and risk management