OpenGov
AI and ERP solutions for local and state governments
ApplicationSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Application Security Engineer at OpenGov. Skills: Application Security, SAST, DAST, SCA. Embed security into CI/CD pipelines. Drive adoption of secure coding best practices”
Industry & Context.
root-cause analysis; deep-dive analysis
What They're Looking For.
Must Have
5+ years of application security, secure development, or software engineering experience, Hands-on experience with SAST, DAST, SCA, secrets scanning, container scanning, and CI/CD integration, Expertise in OWASP Top 10, ASVS, SANS CWE Top 25, and secure coding principles, Ability to perform threat modeling, code review, and architecture analysis, Experience partnering with Engineering to drive remediation and long-term maturity improvements
Nice to Have
Experience in SaaS, multi-tenant systems, or high-scale cloud environments (AWS preferred), Familiarity with SOC 2, GovRAMP, & TX-RAMP, Prior background in DevOps, software engineering, or cloud security
What You'll Do.
Embed security into CI/CD pipelines
Drive adoption of secure coding best practices
Lead threat modeling exercises
and tune AppSec tooling
Partner with DevOps on automated testing
Evaluate emerging technologies
and root-cause analysis
Ensure timely remediation
Support security reviews
Conduct manual reviews of critical code paths
Advise on secure design patterns
Collaborate with Security Operations
Perform deep-dive analysis of new vulnerabilities
Mentor engineering teams on secure design
Lead internal workshops
Contribute to internal AppSec documentation
How You'll Work.
Team & Collaboration
partners closely with Software Engineering, Product, DevOps, and Security Operations; Drive adoption of secure coding best practices across engineering teams; Experience partnering with Engineering to drive remediation; Partner with DevOps to ensure automated testing integrates; Ensure timely remediation through cross-functional partnership; Collaborate with Security Operations during active incidents; Mentor engineering teams on secure design; Lead internal workshops, brown bags, and knowledge-sharing sessions
Communication Scope
guidance; direct partnership; knowledge-sharing sessions
Process & Methodology
prioritization, driving the right balance of risk, velocity, and operational maturity
Full Job Description
OpenGov is the leader in AI and ERP solutions for local and state governments in the U.S. More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov Public Service Platform to operate efficiently, adapt to change, and strengthen the public trust. Category-leading products include enterprise asset management, procurement and contract management, accounting and budgeting, billing and revenue management, permitting and licensing, and transparency and open data. These solutions come together in the OpenGov ERP, allowing public sector organizations to focus on priorities and deliver maximum ROI with every dollar and decision in sync. Learn about OpenGov’s mission to power more effective and accountable government and the vision of high-performance government for every community at OpenGov.com http://OpenGov.com. JOB SUMMARY: The Application Security Engineer is a technical individual who is responsible for ensuring the security, integrity, and resilience of our cloud-native SaaS applications. This role partners closely with Software Engineering, Product, DevOps, and Security Operations to embed security into every phase of the SDLC. The ideal candidate is hands-on, highly collaborative, and capable of scaling AppSec processes that align with best practices, regulatory requirements, and the needs of a rapidly growing technology organization. RESPONSIBILITIES: - Embed security into CI/CD pipelines through scalable guardrails, automated security checks, and continuous improvements to developer workflows. - Drive adoption of secure coding best practices across engineering teams through tooling, guidance, and direct partnership. - Lead threat modeling exercises for high-risk features and new architecture patterns. - Own, maintain, and tune AppSec tooling including SAST, DAST, SCA, secrets scanning, container scanning, and dependency management. - Partner with DevOps to ensure automated testing integrates into build, test,
Applying for this Application Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about OpenGov?
Real rants from real employees. Read before you apply.