Application Security Engineer
Core
Operate and tune application security scanning tools (SAST/SCA/Secret/DAST/API) to identify and remediate vulnerabilities in enterprise applications and APIs.
Role type
Application Security Engineer (IC)
Builds
Secure enterprise applications and APIs via automated scanning and manual triage
Domain
Application Security / Software Supply Chain
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SAST/SCA/Secret scanning, DAST/API scanning, vulnerability triage, CI/CD integration, backend automation scripting, OWASP Top 10/API Top 10 knowledge, code review (Java/JS/TS/Python/Go/C#), centralized vulnerability management platforms, cloud/container basics (AWS/Azure/GCP/Docker/K8s), REST APIs/webhooks, secure credential handling
Preferred skills
Mobile application security tooling and triage, advanced mobile security concepts
Technologies
Burp Suite, Postman, MobSF, curl, GitHub, GitLab, Azure DevOps, Jenkins, Python, Go, PowerShell, AWS, Azure, GCP, Docker, Kubernetes
Responsibilities
Operate and support SAST/SCA/Secret/DAST and API security scanning tools; Review, validate, and manually triage security findings, identify false positives, and reproduce issues; Perform targeted web application and API security reviews; Assist with configuring and tuning scanning rules, policies, and exclusions; Support integration of security tools into CI/CD and developer workflows; Contribute to backend scanning automation for scan initiation, monitoring, and result processing; Process findings through centralized vulnerability-management platforms; Provide developers with remediation guidance and support validation; Monitor scan execution health and troubleshoot integration issues; Support mobile security finding triage and tooling as needed; Document findings, remediation guidance, and operational procedures; Support team incident rotation including on-call hours
Seniority
Junior to Mid-level, hands-on IC