Junior Application Security Engineer
Core
Implement and maintain application security testing (SAST, DAST, IAST, SCA) and posture management tools within CI/CD pipelines to identify and remediate vulnerabilities in software development.
Role type
Junior Application Security Engineer (DevSecOps)
Builds
Automated security testing pipelines and consolidated security reporting dashboards
Domain
Software Development / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Application security testing (SAST/DAST/IAST/SCA), CI/CD integration, Secure coding practices (Java, Node.js), Vulnerability triage (OWASP Top 10, CWE), Security tool administration, Technical reporting
Preferred skills
Snyk and Endor Labs administration, Cloud Security Posture Management (CSPM) integration, Python scripting for automation, DevSecOps pipeline logging
Responsibilities
Implement and maintain AST and ASPM tools, Integrate security tooling with CI/CD pipelines, Triage security risks and resolve false positives, Develop detailed reports on security findings, Support developers in mitigating test findings, Coach and support junior engineers
Seniority
Junior, hands-on IC