> Markdown version of [/jobs/ext/1212306-security-engineer-sast-sca-application-security](https://www.wearedevelopers.com/jobs/ext/1212306-security-engineer-sast-sca-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - SAST & SCA (Application Security) - **Company:** Intone Networks - **Location:** San Jose, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), JIRA, Microsoft Azure, Bash Shell, C++ (Programming Language), Cloud Engineering, Continuous Integration, Github, Issue Tracking Systems, Python (Programming Language), Open Web Application Security, Windows PowerShell, Fortify (Software), Secure Coding, Software Vulnerability Management, Scripting, Software Security, Veracode, GWAPT, Gitlab-ci, Tenable Nessus, Checkmarx, Terraform, Devsecops, Jenkins, Static Application Security Testing - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2fd6beeaeb282ede ## About the Role Required Qualifications Experience * 3-6+ years in Application Security, DevSecOps, or Secure Development * Hands-on experience with: o SAST and/or SCA tools in enterprise environments * Experience working closely with development teams and CI/CD pipelines Technical Skills * Strong knowledge of: OWASP Top 10 Secure coding practices (Java, Python, C/C++, JavaScript, etc.) * Experience with SAST tools such as: Checkmarx, Fortify, Veracode, CodeQL * Experience with SCA tools such as: Snyk, Black Duck, Mend, Dependabot DevSecOps & Automation * Familiarity with: CI/CD tools (GitHub Actions, Jenkins, GitLab CI, Azure DevOps) * Experience with: Scripting (Python, Bash, PowerShell) * Ability to: Automate workflows and integrate security into pipelines Vulnerability Management * Understanding of: CVSS scoring and risk prioritization Vulnerability tracking and remediation processes * Experience with: Jira or similar ticketing systems Preferred Qualifications * Certifications: CSSLP, GWAPT, OSCP (optional but valuable) Experience with: SBOM frameworks (CycloneDX, SPDX) Container security and dependency scanning Cloud-native application security * Familiarity with: Secrets scanning, IaC scanning tools (e.g., Terraform security) ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)