> Markdown version of [/jobs/ext/1205653-application-security-specialist](https://www.wearedevelopers.com/jobs/ext/1205653-application-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Specialist - **Company:** TalentOla View all jobs - **Location:** Irvington, NJ, United States - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Confluence, JIRA, Microsoft Azure, Burp Suite, Static Program Analysis, Cyber Security, Continuous Integration, DevOps, Github, Intrusion Detection Systems, Virtual Private Networks (VPN), Network Security, Scrum Methodology, Systems Development Life Cycle, Power BI, Secure Coding, SonarQube, Software Vulnerability Management, Webinspect, Grafana, Software Security, Veracode, Firewalls (Computer Science), GWAPT, Kubernetes, Patch Management, Nessus, Appscan, Terraform, Splunk, Devsecops, Jenkins, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 8, 2026 - **Apply:** https://www.careerjet.com/jobad/us3e829e4f8b41a9a32b9700c0e5ba3d7f ## About the Role Need AppSec ownership and security leadership. 6. Certifications to Prioritize Strong: * CSSLP * CISSP * CRISC Good: * GWAPT * GWEB * CASE * Security+ Nice to Have: * Scrum Master * SAFe * PMP ## Description Job Description: Look for someone who has Application Security experience, has worked closely with software developers, conducted threat modeling and secure coding activities, integrated security tools into CI/CD pipelines, and ideally built or led a Security Champions Program or Community of Practice. Leadership, enablement, training, and influencing engineering teams are more important than deep penetration testing or network security experience. Here are some key points that can help you spot a difference between a good candidate for this role: Must-Have Experience Areas You can confirm the candidate has experience in at least 4 5 areas of these: Area Required Application Security Yes Threat Modeling Yes Secure Coding Yes Developer Coaching Yes Security Testing Tools Yes CI/CD Security Yes Security Governance Preferred Security Champion Program Strongly Preferred Compliance Reporting Preferred Metrics & Dashboards Preferred 1. Must-Have Resume Keywords A strong resume should contain several of these terms: Application Security Application Security (AppSec) Secure SDLC (SSDLC) Secure Development Lifecycle DevSecOps Secure Design Secure Coding Security Architecture Security Review Threat Modeling & Developer Coaching Threat Modeling STRIDE Security Champions Developer Enablement Security Training Secure Coding Training Security Awareness Coaching Developers Security Workshops CI/CD & Automation CI/CD Security DevSecOps Security Gates Pipeline Security Compliance Automation Security Controls Continuous Security Testing Security Testing Tools SAST DAST SCA Static Analysis Dynamic Testing Software Composition Analysis Vulnerability Management Governance & Metrics Security Metrics KPIs Dashboards Compliance Reporting Risk Management Risk Register Governance Security Controls Collaboration Cross-Functional Leadership Stakeholder Management Program Management Change Management Community of Practice (CoP) Security Champion Program 2. Tools That Should Appear on Resume Look for at least some of these: SAST Checkmarx Veracode Fortify SonarQube Coverity DAST Burp Suite AppScan WebInspect SCA Black Duck Snyk Mend (WhiteSource) CI/CD Jenkins GitHub Actions GitLab CI/CD Azure DevOps Dashboards Power BI Grafana Splunk Collaboration ServiceNow Confluence Jira Microsoft Teams 3. High-Value Phrases These are the phrases that should immediately catch a your attention: "Built Security Champion Program" "Led Application Security Community of Practice" "Coached development teams on secure coding" "Conducted threat modeling sessions" "Integrated security controls into CI/CD pipelines" "Established AppSec KPIs and dashboards" "Drove security adoption across engineering teams" "Partnered with application owners to remediate vulnerabilities" "Performed secure code reviews" "Developed AppSec training curriculum" "Enabled security adoption across multiple business units" "Acted as liaison between development and security teams" 5. Red Flags (Reject or Lower Priority) Pure Infrastructure Security Resume focused mainly on: * Firewalls * Network Security * VPN * IDS/IPS * SOC Operations Not a fit. Pure Vulnerability Management Only: * Nessus scans * Patch management * Server vulnerability remediation Not enough AppSec depth. Pure Penetration Tester Only: * Ethical hacking * Red teaming * Bug bounty May lack program leadership and developer enablement. Pure DevOps Engineer Only: * Kubernetes * Terraform * AWS deployment ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)