Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)
Core
Implementing, operationalizing, and troubleshooting Static Application Security Testing (SAST) tools within CI/CD pipelines to secure software development.
Role type
Mid-level Application Security Engineer
Builds
Secure software applications and CI/CD pipelines
Domain
Cybersecurity / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SAST tools (Semgrep, Snyk, CodeQL, Checkmarx, Veracode), CI/CD pipeline tools (GitHub Actions, GitLab, Azure DevOps, Jenkins, CircleCI), full stack software development, scripting and automation, OWASP Top 10, threat modeling, secure coding practices
Preferred skills
Custom SAST rule writing (Semgrep, CodeQL), IAST/DAST/API security tools, Burp Suite, vulnerability triaging and remediation, automated security testing approaches, building security tools in CI/CD
Technologies
Semgrep, Snyk, CodeQL, Checkmarx, Veracode, GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, CircleCI, Burp Suite, NoName, Traceable, Salt, Cequence
Responsibilities
Implement and troubleshoot SAST tools; Integrate security into CI/CD pipelines; Validate vulnerabilities and remediate technical issues; Apply secure coding practices throughout the SDLC
Seniority
Mid-level, hands-on IC