Pax8 Logo

Pax8

Application Security Engineer

Posted 22 Hours Ago
Be an Early Applicant
In-Office
Greenwood Village, CO
137K-168K
Junior
In-Office
Greenwood Village, CO
137K-168K
Junior
The Application Security Engineer supports secure development processes, evaluates security defects, conducts threat modeling, and trains teams on secure coding practices.
The summary above was generated by AI
Pax8 is the leading cloud-based technology marketplace, simplifying the cloud journey for our partners by integrating technology, business intelligence and proactive service to deliver an unparalleled experience. Serving thousands of partners through the indirect sales channel, our mission is to build the technology marketplace of the future. We are a fast-growing, dynamic and  high-energy startup organization, allowing you to make a meaningful impact on the business. Culture is important to us, and at Pax8, it’s business, and it IS personal. We are passionate, creative and humorously offbeat. We work hard, keep it fun, and expect the best. 
 
We Elev8 each other. We Advoc8 for our partners. We Innov8 continuously. We Celebr8 life.

No matter who you are, Pax8 is a place you can call home. We know there’s no such thing as a “perfect" candidate, so we don’t look for the right "fit" – instead, we look for the add. We encourage you to apply for a role at Pax8 even if you don’t meet 100% of the bullet points. We believe in cultivating an environment with a diversity of perspectives, in hopes that we can all thrive in an inclusive environment. 

We are only as great as our people. And we have great people all over the world. No matter where you live and work, you’re a part of the Pax8 team. This means embracing hybrid- and remote-work whenever possible.  

Position Summary: 

Pax8’s Platform Security team is responsible for the implementation and operation of our application and infrastructure security program. As a vital member of this group, the Application Security Engineer helps build and reinforce the security posture of Pax8’s software development lifecycle.

This role collaborates closely with our software development teams as we evolve our world-class software marketplace. The AppSec Engineer is responsible for supporting the identification, evaluation, and mitigation of security defects; conducting and maintaining application threat models; assisting with the design and implementation of secure development frameworks; helping to train teams on secure coding practices; and validating security processes throughout the application build, deployment, and operation processes.

Essential Responsibilities (includes, but is not limited to):

  • Serve as a subject matter expert on application security to help drive security considerations into product design and software development processes.
  • Assist in creating and maintaining risk assessments and threat models against evolving features in the Pax8 software platform.
  • Support the development and management of application security testing processes, including automated testing and manual design review processes.
  • Assist teams in reproducing, triaging, and addressing security vulnerabilities.
  • Contribute to the development of security standards and best practices, both in the form of written documentation and code-based guardrails.
  • Participate in maintaining application security tooling and associated process documentation as necessary.
  • Support security awareness efforts within the software engineering organization by participating in the delivery of security training sessions.

Ideal Skills, Experience, and Competencies:

  • At least two (2) years of experience in application/product security.
  • Background in the OWASP Top 10 application security defects, including the ability to identify and remediate such vulnerabilities in different languages.
  • Experience with modern software languages (we primarily use Kotlin and JavaScript).
  • Experience developing threat models and leading secure code reviews.
  • Experience with application security testing processes such as SAST, SCA, and DAST through detection, triage, and remediation.
  • Knowledge of secure architecture and secure design patterns in a web-based microservices environment.
  • Background in cloud-based infrastructure and containerized application environments.
  • Experience with modern workflow management processes such as ticketing systems.
  • Experience with modern source code management systems and CI/CD platforms.
  • Ability to execute independently within a small, nimble team.

Required Behaviors:

  • Compassionate Candour—We aim to assist others with candid, actionable feedback.
  • Seek to Understand—Be open, curious and committed to learning.
  • We Before Me—Actively collaborate and seek out diverse perspectives to ensure a win for Team Pax8.
  • Do What You Say—Take ownership and honor your commitments; prioritize and deliver.
  • Light Up Learning—Be brave and try new ideas; be vulnerable and share your failures so everyone can learn from our mistakes.
  • Driven by Passion—Connects personal passion to Pax8 mission, resilient in face of adversity and uncertainty in pursuit of mission.

Required Education & Certifications:

  • B.A./B.S. in a related field (e.g., Computer Science, Engineering, Cybersecurity) or equivalent work experience
Compensation:
  • Qualified candidates can expect a compensation range of $137,000/yr to $168,000/yr or more depending on experience.

Expected Closing Date: 7/15/2025

#LI-REMOTE #LI-AG1 #DICE-A





*** Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed ***
 
At Pax8 we believe that your Total Rewards should include a benefits package that shows how much we value our greatest assets. All FTE Pax8 people enjoy the following benefits:
  • Non-Commissioned Bonus Plans or Variable Commission
  • 401(k) plan with employer match
  • Medical, Dental & Vision Insurance
  • Employee Assistance Program
  • Employer Paid Short & Long Term Disability, Life and AD&D Insurance
  • Flexible, Open Vacation
  • Paid Sick Time Off
  • Extended Leave for Life events
  • RTD Eco Pass (For local Colorado Employees)
  • Career Development Programs
  • Stock Option Eligibility
  • Employee-led Resource Groups

Please take a moment to review our Proprietary Rights and Non-Competition Agreement —this document outlines important information about your rights and responsibilities if you join our team.

 Pax8 is an EEOC Employer.
Equal Opportunities
Pax8 is an equal opportunities employer and welcome individuals who are in possession of the appropriate requirements to work within the country the role is based in. Offered individuals will be asked to undertake identity, security compliance and reference checks. Your privacy is important to us. Your data will be held in accordance with Data Privacy best practices and processed only in accordance with our recruiting processes.
Job Applicant Privacy Notice
 

Top Skills

JavaScript
Kotlin
Owasp
HQ

Pax8 Greenwood Village, Colorado, USA Office

The Landmark features an array of restaurants, entertainment & retail. Life in this district comes with access to some of the finest retailers in Denver. At the center of everything, The Landmark is a comfortable & connected community.

Similar Jobs

21 Days Ago
Hybrid
Denver, CO, USA
140K-200K
Senior level
140K-200K
Senior level
Security • Software • Cybersecurity
The Senior Application Security Engineer will ensure application security by developing secure code, conducting threat modeling, and engaging in security audits and customer support.
Top Skills: Application SecurityCloud InfrastructureHTTPMulti-Threaded ApplicationsRestSecure Coding PracticesTcp/IpVulnerability Testing
15 Hours Ago
In-Office
Littleton, CO, USA
96K-138K Annually
Mid level
96K-138K Annually
Mid level
Aerospace • Cloud • Digital Media • Information Technology • Mobile • News + Entertainment • Retail
The Cybersecurity Specialist will identify and analyze threats, support analysts, improve security processes, and provide incident reports.
Top Skills: EdrIdsIpsSIEMUebaXsiamXsoar
19 Hours Ago
Hybrid
Lakewood, CO, USA
120K-150K Annually
Senior level
120K-150K Annually
Senior level
Fintech • Information Technology • Security • Financial Services
The Sr Network Firewall Administrator evaluates, designs, and maintains enterprise firewall technologies and network security, providing leadership in implementation and troubleshooting across various network environments.
Top Skills: AnsibleCisco AsaFirepowerIpsIsePythonRestful ApiTerraformVpnYaml

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account