> Markdown version of [/jobs/ext/1216872-application-security-specialist](https://www.wearedevelopers.com/jobs/ext/1216872-application-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Specialist - **Company:** I8IS INC. - **Location:** Irving, TX, United States - **Experience:** Experienced - **Salary:** $114,400.0 - $124,800.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Confluence, JIRA, Microsoft Azure, Static Program Analysis, Continuous Integration, DevOps, Github, Network Security, Scrum Methodology, Power BI, Secure Coding, Software Vulnerability Management, Grafana, Software Security, GWAPT, Gitlab-ci, Kubernetes, Patch Management, Nessus, Splunk, Jenkins, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=41d05a8d51e64129 ## About the Role * Security Gates * Pipeline Security * Compliance Automation * Security Controls * Continuous Security Testing Security Testing Tools * SAST * DAST * SCA * Static Analysis * Dynamic Testing * Software Composition Analysis * Vulnerability Management Governance & Metrics * Security Metrics * KPIs * Dashboards * Compliance Reporting * Risk Management * Risk Register * Governance * Security Controls Collaboration * Cross-Functional Leadership * Stakeholder Management * Program Management * Change Management * Community of Practice (CoP) * Security Champion Program, * Mend (WhiteSource) CI/CD * Jenkins * GitHub Actions * GitLab CI/CD * Azure DevOps Dashboards * Power BI * Grafana * Splunk Collaboration * ServiceNow * Confluence * Jira * Microsoft Teams ## Description Job Description: Look for someone who has Application Security experience, has worked closely with software developers, conducted threat modeling and secure coding activities, integrated security tools into CI/CD pipelines, and ideally built or led a Security Champions Program or Community of Practice. Leadership, enablement, training, and influencing engineering teams are more important than deep penetration testing or network security experience., SOC Operations Not a fit. Pure Vulnerability Management Only: Nessus scans Patch management Server vulnerability remediation Not enough AppSec depth. Pure Penetration Tester Only: Ethical hacking Red teaming Bug bounty May lack program leadership and developer enablement. Pure DevOps Engineer Only: Kubernetes Terraform AWS deployment Need AppSec ownership and security leadership. 6. Certifications to Prioritize Strong: CSSLP CISSP CRISC Good: GWAPT GWEB CASE Security+ Nice to Have: Scrum Master SAFe PMP ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)