Application Security Engineer (Remote in the U.S.)
Core
Run application security tools (SAST, DAST, SCA) to identify and remediate vulnerabilities in web applications and development pipelines.
Role type
Application Security Engineer
Builds
Secure software delivery pipelines and hardened web applications
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SAST/DAST/SCA tool operation, CI/CD pipeline integration, secure design guidance, manual vulnerability testing, source code review (JavaScript, Python, Java, C++, PHP, C++)
Preferred skills
None stated
Technologies
Invicti, Checkmarx, Burp Suite Pro, Azure DevOps, Jenkins, Bamboo, GitHub
Responsibilities
Run client SAST, DAST, and SCA tools and review outputs; Implement integrations for tools into pipelines and ticketing systems; Collaborate with developers to provide secure design guidance and remediation strategies; Manage, maintain, and operate application security tooling including configuration, tuning, and automation
Seniority
Mid-level (4+ years experience)