Application Security Engineer

Apply now »

Date: Sep 15, 2026

Location: Renton, WA, US, 98057

Company: PACCAR

Company Information

PACCAR is a Fortune 500 company established in 1905. PACCAR Inc is recognized as a global leader in the commercial vehicle, financial, and customer service fields with internationally recognized brands such as Kenworth, Peterbilt, and DAF trucks. PACCAR is a global technology leader in the design, manufacture and customer support of high-quality light-, medium- and heavy-duty trucks under the Kenworth, Peterbilt and DAF nameplates. PACCAR designs and manufactures advanced diesel engines and also provides customized financial services, information technology and truck parts related to its principal business. Whether you want to design the transportation technology of tomorrow, support the staff functions of a dynamic, international leader, or build our excellent products and services — you can develop the career you desire with PACCAR. Get started!

Division Information

PACCAR’s Information Technology Division (ITD), located in Renton, WA utilizes cutting-edge technology to provide systems development, consulting, voice and data communications services to the entire Corporation, which has high visibility in the technology sector.

Requisition Summary

As an Application Security Engineer, you will be a key member of the Global Security group within the IT Division at PACCAR and will be reporting directly to the Principal Engineer. You will provide security guidance to development teams, including secure code review and scanning, vulnerability assessments, and security testing to help application teams build and deploy secure applications and APIs.

In this role, you will support security governance and help ensure adherence to application security controls and risk analysis across the organization's application portfolio throughout the SDLC. This includes internally developed applications, third-party developed applications, commercial off-the-shelf (COTS) solutions, and open-source software.

You will utilize a risk-based methodology and "shift-left" approach to engage early in the software development lifecycle, working alongside engineering teams to help prevent security defects before they are introduced. You will contribute to a team culture that values openness, teamwork, continuous improvement, learning, commitment, and empathy.

Job Functions / Responsibilities

 

Security Assessments & Testing

 

  • Perform source code reviews using manual analysis and Static Application Security Testing (SAST) tools to identify vulnerabilities.
  • Execute web security assessments on websites, web applications, web services, and APIs using Dynamic Application Security Testing (DAST) tools.
  • Review test results from automated security tools, ensure automated tests complete successfully, and identify and remove false positives from tool reports.
  • Participate in developing and reviewing threat models to proactively identify security risks.

 

Developer Engagement & Remediation

  • Engage with development teams to provide vulnerability remediation support through consultation or hands-on assistance.
  • Assist developers with understanding security defects, associated risk, and defining acceptable solutions to fix defects.
  • Collaborate with teams to integrate secure coding practices and security tooling into CI/CD pipelines.
  • Contribute to code reviews and design discussions with a security lens.

 

Security Governance & Standards

 

  • Support adherence to application security controls and contribute to risk analysis of applications across the SDLC.
  • Participate in the creation, maintenance, and communication of PACCAR secure coding standards, guidelines, and examples.
  • Support the implementation of secure design principles according to organizational policies, standards, and application security patterns.
  • Assist in creating technical security documents including assessment reports and remediation guidance.

 

Training & Culture

 

  • Share application security knowledge with the engineering team through brown bags, secure coding tournaments, and developer outreach activities.
  • Actively participate in improving security culture and awareness throughout the organization.
  • Participate in security incident response when needed.

 

Tooling & Automation

 

  • Help maintain and tune Secure SDLC tools including SAST, DAST, and Software Composition Analysis (SCA) platforms.
  • Support the integration of security tooling and automated security checks within CI/CD pipelines.
  • Stay current with security technologies, products, and emerging trends relevant to application security.

Qualifications

  • Basic Qualifications

    • Bachelors degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.
    • 5+ years of professional experience in application or software security, including hands-on work in areas such as secure code review, vulnerability assessment, threat analysis, or secure development practices.
    • Hands-on experience with application security testing tools, including DAST platforms (e.g., Burp Suite, WebInspect, OWASP ZAP) and SAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube).
    • Proficiency in one or more programming languages: C#, JavaScript, and/or Python.
    • Strong working knowledge of web application technologies including HTTP, HTML, CSS, JavaScript.
    • Expert-level understanding of the OWASP Top 10 and common web application vulnerabilities and website security concepts such as headers, cookies, CORS, XSS, CSRF.
    • Familiarity with web authentication technologies such as OAuth and/or SAML.
    • Experience with Software Development Life Cycle (SDLC) and development methodologies such as Waterfall and Agile.
    • Experience with control systems: Git, GitHub, Azure DevOps

     

    Preferred Experience 

    • Experience working in a large enterprise environment.
    • Experience with penetration testing or security tools (e.g., Kali Linux, Nmap).
    • Familiarity with cloud environments such as Azure, AWS, or GCP.
    • Certified Secure Software Lifecycle Professional (CSSLP)
    • Certified Information Systems Security Professional (CISSP)
    • CompTIA Security+

Additional Job Board Information

PACCAR Benefits

 

As a U.S. PACCAR employee, you have a full range of benefit options including:

  • 401k with up to a 5% company match
  • Employee Stock Purchase Program (ESPP)
  • Fully funded pension plan that provides monthly benefits after retirement
  • Comprehensive paid time off – minimum of 10 paid vacation days (additional days are provided with additional seniority/years of service), 12 paid holidays, and sick time
  • Tuition reimbursement for continued education
  • Medical, dental, and vision plans for you and your family
  • Flexible spending accounts (FSA) and health savings account (HSA)
  • Paid short-and long-term disability programs
  • Life and accidental death and dismemberment insurance
  • EAP services that include wellness plans, estate planning, financial counseling and more

 

PACCAR is an Equal Opportunity Employer/Protected Veteran/Disability. At PACCAR, we value talent and promote growth and development. We carefully consider numerous compensation factors, including your education, training, or experience. Applicants and employees for this position will not be sponsored for work authorization, including, but not limited to H-1B visas, now or in the future. The salary range for this position is $90,000 - $141,000 annually. Additionally, this role is eligible for the full range of benefit options listed above.


Nearest Major Market: Seattle
Nearest Secondary Market: Bellevue

Job Segment: Testing, Test Engineer, Open Source, Cloud, Computer Science, Technology, Engineering

Apply now »