Security Engineer - SAST & SCA (Application Security)

Intone Networks
San Jose, CA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Java (Programming Language) JavaScript (Programming Language) JIRA Microsoft Azure Bash Shell C++ (Programming Language) Cloud Engineering Continuous Integration Github Issue Tracking Systems Python (Programming Language)
+16 more
Open Web Application Security Windows PowerShell Fortify (Software) Secure Coding Software Vulnerability Management Scripting Software Security Veracode GWAPT Gitlab-ci Tenable Nessus Checkmarx Terraform Devsecops Jenkins Static Application Security Testing

Requirements

Required Qualifications Experience * 3-6+ years in Application Security, DevSecOps, or Secure Development * Hands-on experience with: o SAST and/or SCA tools in enterprise environments * Experience working closely with development teams and CI/CD pipelines Technical Skills * Strong knowledge of: OWASP Top 10 Secure coding practices (Java, Python, C/C++, JavaScript, etc.) * Experience with SAST tools such as: Checkmarx, Fortify, Veracode, CodeQL * Experience with SCA tools such as: Snyk, Black Duck, Mend, Dependabot DevSecOps & Automation * Familiarity with: CI/CD tools (GitHub Actions, Jenkins, GitLab CI, Azure DevOps) * Experience with: Scripting (Python, Bash, PowerShell) * Ability to: Automate workflows and integrate security into pipelines Vulnerability Management * Understanding of: CVSS scoring and risk prioritization Vulnerability tracking and remediation processes * Experience with: Jira or similar ticketing systems Preferred Qualifications * Certifications: CSSLP, GWAPT, OSCP (optional but valuable) Experience with: SBOM frameworks (CycloneDX, SPDX) Container security and dependency scanning Cloud-native application security * Familiarity with: Secrets scanning, IaC scanning tools (e.g., Terraform security)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all