OpenGov
AI and ERP solutions for local and state governments
Sr.ApplicationSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Sr. Application Security Engineer at OpenGov. Skills: Application Security, Secure Coding, Threat Modeling, CI/CD Security. Embed security into CI/CD pipelines. Drive adoption of secure coding best practices”
What You'll Achieve.
Ensure the security, integrity, and resilience of our cloud-native SaaS applications; Embed security into every phase of the SDLC; Scale AppSec processes that align with best practices, regulatory requirements, and the needs of a rapidly growing technology organization; Strengthen AppSec capabilities; Drive the right balance of risk, velocity, and operational maturity; Identify security defects that automation may miss; Power more effective and accountable government
Industry & Context.
Root-cause analysis for application vulnerabilities; Deep-dive analysis of new vulnerabilities, exploit techniques, frameworks, and supply-chain risks
What They're Looking For.
Must Have
8+ years of application security, secure development, or software engineering experience, Hands-on experience with SAST, DAST, SCA, secrets scanning, container scanning, and CI/CD integration, Expertise in OWASP Top 10, ASVS, SANS CWE Top 25, and secure coding principles, Ability to perform threat modeling, code review, and architecture analysis, Experience partnering with Engineering to drive remediation and long-term maturity improvements
Nice to Have
Experience in SaaS, multi-tenant systems, or high-scale cloud environments (AWS preferred), Familiarity with SOC 2, GovRAMP, & TX-RAMP, Prior background in DevOps, software engineering, or cloud security
What You'll Do.
Embed security into CI/CD pipelines
Drive adoption of secure coding best practices
Lead threat modeling exercises
and tune AppSec tooling
Partner with DevOps for automated testing integration
Evaluate emerging technologies and automation opportunities
and root-cause analysis for vulnerabilities
Ensure timely remediation of vulnerabilities
Support security reviews and pen test scoping
Conduct manual reviews of critical code paths
Advise on secure design patterns
Collaborate with Security Operations during incidents
Perform deep-dive analysis of new vulnerabilities
Mentor engineering teams on secure design
Lead internal workshops and knowledge-sharing sessions
Contribute to internal AppSec documentation
How You'll Work.
Team & Collaboration
Partner closely with Software Engineering, Product, DevOps, and Security Operations; Drive adoption of secure coding best practices across engineering teams; Partner with DevOps to ensure automated testing integrates into build, test, and deploy workflows; Ensure timely remediation through cross-functional partnership; Collaborate with Security Operations during active incidents; Mentor engineering teams on secure design, secure coding, and modern AppSec patterns; Lead internal workshops, brown bags, and knowledge-sharing sessions
Full Job Description
OpenGov is the leader in AI and ERP solutions for local and state governments in the U.S. More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov Public Service Platform to operate efficiently, adapt to change, and strengthen the public trust. Category-leading products include enterprise asset management, procurement and contract management, accounting and budgeting, billing and revenue management, permitting and licensing, and transparency and open data. These solutions come together in the OpenGov ERP, allowing public sector organizations to focus on priorities and deliver maximum ROI with every dollar and decision in sync. Learn about OpenGov’s mission to power more effective and accountable government and the vision of high-performance government for every community at OpenGov.com http://OpenGov.com. Role Summary The Senior Application Security Engineer is a technical leader responsible for ensuring the security, integrity, and resilience of our cloud-native SaaS applications. This role partners closely with Software Engineering, Product, DevOps, and Security Operations to embed security into every phase of the SDLC. The ideal candidate is hands-on, highly collaborative, and capable of scaling AppSec processes that align with best practices, regulatory requirements, and the needs of a rapidly growing technology organization. KEY RESPONSIBILITIES - Embed security into CI/CD pipelines through scalable guardrails, automated security checks, and continuous improvements to developer workflows. - Drive adoption of secure coding best practices across engineering teams through tooling, guidance, and direct partnership. - Lead threat modeling exercises for high-risk features and new architecture patterns. - Own, maintain, and tune AppSec tooling including SAST, DAST, SCA, secrets scanning, container scanning, and dependency management. - Partner with DevOps to ensure automated testing integrates into build, test, and
Applying for this Sr. Application Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about OpenGov?
Real rants from real employees. Read before you apply.