Application Security Engineer
PACCAR
- Location
- Renton, WA, US, 98057
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 17 approvals (FY2023)
- Posted
- Sep 15, 2026
Skills
About this role
Company Information
PACCAR is a Fortune 500 company established in 1905. PACCAR Inc is recognized as a global leader in the commercial vehicle, financial, and customer service fields with internationally recognized brands such as Kenworth, Peterbilt, and DAF trucks. PACCAR is a global technology leader in the design, manufacture and customer support of high-quality light-, medium- and heavy-duty trucks under the Kenworth, Peterbilt and DAF nameplates. PACCAR designs and manufactures advanced diesel engines and also provides customized financial services, information technology and truck parts related to its principal business. Whether you want to design the transportation technology of tomorrow, support the staff functions of a dynamic, international leader, or build our excellent products and services — you can develop the career you desire with PACCAR. Get started! Division Information
PACCAR’s Information Technology Division (ITD), located in Renton, WA utilizes cutting-edge technology to provide systems development, consulting, voice and data communications services to the entire Corporation, which has high visibility in the technology sector. Requisition Summary
As an Application Security Engineer, you will be a key member of the Global Security group within the IT Division at PACCAR and will be reporting directly to the Principal Engineer. You will provide security guidance to development teams, including secure code review and scanning, vulnerability assessments, and security testing to help application teams build and deploy secure applications and APIs. In this role, you will support security governance and help ensure adherence to application security controls and risk analysis across the organization's application portfolio throughout the SDLC. This includes internally developed applications, third-party developed applications, commercial off-the-shelf (COTS) solutions, and open-source software. You will utilize a risk-based methodology and "shift-left" approach to engage early in the software development lifecycle, working alongside engineering teams to help prevent security defects before they are introduced. You will contribute to a team culture that values openness, teamwork, continuous improvement, learning, commitment, and empathy. Job Functions / Responsibilities
Security Assessments & Testing
Perform source code reviews using manual analysis and Static Application Security Testing (SAST) tools to identify vulnerabilities. Execute web security assessments on websites, web applications, web services, and APIs using Dynamic Application Security Testing (DAST) tools. Review test results from automated security tools, ensure automated tests complete successfully, and identify and remove false positives from tool reports. Participate in developing and reviewing threat models to proactively identify security risks.
Developer Engagement & Remediation
Engage with development teams to provide vulnerability remediation support through consultation or hands-on assistance. Assist developers with understanding security defects, associated risk, and defining acceptable solutions to fix defects. Collaborate with teams to integrate secure coding practices and security tooling into CI/CD pipelines. Contribute to code reviews and design discussions with a security lens.
Security Governance & Standards
Support adherence to application security controls and contribute to risk analysis of applications across the SDLC. Participate in the creation, maintenance, and communication of PACCAR secure coding standards, guidelines, and examples. Support the implementation of secure design principles according to organizational policies, standards, and application security patterns. Assist in creating technical security documents including assessment reports and remediation guidance.
Training & Culture
Share application security knowledge with the engineering team through brown bags, secure