Application Security Engineer
Core
Junior Application Security Engineer supporting inline code testing, reporting, and CI/CD integration to identify and remediate vulnerabilities in software development.
Role type
Junior IC application security engineer (DevSecOps)
Builds
Application security tooling (SAST, DAST, IAST, SCA, ASPM) integrated into CI/CD pipelines
Domain
Software development lifecycle security, DevSecOps, cloud environments
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Application security testing (SAST/DAST/IAST/SCA), CI/CD pipeline integration, secure coding practices (Java, Node.js), vulnerability triage (OWASP Top 10, CWE), security tool administration, technical reporting, secure software design principles
Preferred skills
Application security posture management consolidation, Snyk and Endor Labs administration, CSPM integration, Python scripting for automation, DevSecOps logging, risk management interface
Technologies
SAST, DAST, IAST, SCA, ASPM, Snyk, Endor Labs, CSPM, Java, Node.js, Python, CI/CD pipelines
Responsibilities
Implement and maintain AST tools to identify code and dependency vulnerabilities; Integrate security tooling with CI/CD pipelines; Act as first line of support for resolving false positives and evaluating security exceptions; Develop detailed reports on security findings and remediation efforts; Triage security risks at scale across disparate application environments; Coach and support the development of junior engineers
Seniority
Junior, hands-on IC