Application Security Engineer (iast/dast)
Remote
The Application Security Engineer is responsible for integrating security throughout the Software Development Lifecycle (SDLC) and ensuring applications are designed, developed, tested, and deployed in accordance with organizational security standards and best practices. This role partners closely with Software Development, Architecture, DevOps, and Cybersecurity teams to identify, assess, prioritize, and remediate application security risks while promoting a secure development culture across the organization.
The ideal candidate possesses hands-on experience with application security testing tools, secure coding principles, vulnerability management, and DevSecOps practices.
Key Responsibilities
Perform application security assessments for internally developed and third-party applications.
Conduct and review Static Application Security Testing (SAST), Software Composition Analysis (SCA), and API security scan results and validate findings.
Support development teams by providing vulnerability remediation guidance and secure coding recommendations.
Perform risk-based triage, prioritization, and tracking of application security vulnerabilities.
Participate in threat modeling exercises and secure design reviews for new applications and major system enhancements.
Assist with defining security requirements during project initiation, planning, and application design phases.
Review open-source software usage and support software composition governance activities.
Validate remediation efforts through security testing, verification, and retesting activities.
Collaborate with DevOps teams to integrate security controls, testing, and automation into CI/CD pipelines.
Support compliance and audit initiatives related to secure software development and application security assurance programs.
Develop, maintain, and enhance application security standards, procedures, and documentation.
Track identified security findings and report on remediation progress against established service level agreements (SLAs).
Promote security awareness and secure development best practices across engineering teams.
Required Qualifications
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or a related field, or equivalent work experience.
3+ years of experience in Application Security, Cybersecurity, Software Development, DevSecOps, or a related discipline.
Experience performing application security assessments and vulnerability management activities.
Knowledge of secure software development lifecycle (SSDLC) methodologies and secure coding practices.
Experience working with development teams in Agile and DevOps environments.
Understanding of modern web, API, cloud, and microservices architectures.
Strong analytical, problem-solving, and communication skills.
Required Technical Skills
Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
API Security Testing
Vulnerability Assessment and Validation
Secure Code Review
Threat Modeling
OWASP Top 10 and Secure Coding Practices
Vulnerability Management and Risk Prioritization
CI/CD Security Integration
DevSecOps Concepts and Methodologies
Preferred Qualifications
Experience with Interactive Application Security Testing (IAST).
Experience with Dynamic Application Security Testing (DAST).
Familiarity with container and cloud security technologies.
Experience integrating security tools into CI/CD platforms.
Knowledge of software supply chain security concepts.
Security certifications such as CSSLP, GWAPT, GSEC, Security+, CISSP, or equivalent.
Experience supporting regulated or compliance-driven environments.
Medical, dental, and vision insurance are available to qualified candidates who meet eligibility requirements.