AI-Driven Application Security Triage Engineer

Buckeye Global
Canton, OH, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$166,400.0 - $187,200.0
Working hours
Shift work
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Code Review Continuous Integration Programming Tools Open Source Technology Package Management Systems Data Processing Scripting Software Security Model Validation Static Application Security Testing
+1 more
Dynamic Application Security Testing

Job description

You start your morning scanning the latest SCA, SAST, and DAST findings. Critical and high-risk items are quickly validated, false positives are filtered out, and you document clear remediation guidance. When a PatchNow Critical event lands, you lead the scope analysis, route owners, and drive mitigation steps through to verified closure. If a threat intelligence escalation appears, you coordinate a fast, structured response.

By midday, you’re drafting concise briefs on newly disclosed and frontier-model-influenced vulnerabilities, translating technical details into action plans for development teams. In the afternoon, you’re hands-on with AI-enabled security tooling-testing frontier-model capabilities for code reasoning, triage acceleration, and remediation recommendations while ensuring auditability, secure use controls, and human-in-the-loop review.

Before you wrap, you reinforce our software supply chain security-from dependency hygiene (SBOM visibility, malicious package detection, policy enforcement) to safeguarding developer IDEs, plugins/extensions, code-assist tools, package managers, and CI integrations against compromised components and unsafe configurations.

Core Responsibilities

  • Deliver unified triage across SCA/SAST/DAST findings: validate severity, assess exploitability, analyze false positives, and provide actionable fixes and escalations for production and business-critical apps.
  • Coordinate responses to threat intelligence escalations and PatchNow Critical events, including scoping, owner routing, mitigation guidance, tracking, and closure verification.
  • Monitor and analyze newly disclosed and novel vulnerabilities-especially those accelerated by frontier-model research-and produce actionable remediation briefs.
  • Engineer, test, and implement AI-assisted security tooling leveraging frontier models for vulnerability identification, code reasoning, triage acceleration, and analyst workflow automation with appropriate guardrails.
  • Support evaluation and onboarding of new AI capabilities: proof-of-value execution, security testing, control validation, data handling review, model output evaluation, success metrics, and governance documentation.
  • Strengthen software supply chain security: secure open-source dependency intake, SBOM and component visibility, malicious package detection, dependency health assessment, and policy enforcement across dev, pipeline, and artifact workflows.
  • Improve developer environment security: harden IDEs, plugins/extensions, package managers, code-assist tools, and CI integrations against malicious code and compromised components.

Requirements

  • 3+ years of code scanning
  • 3+ years of open-source scanning
  • 3+ years of dynamic and static scanning, * Proven track record triaging SCA/SAST/DAST findings and driving high-severity escalations (threat intel and critical patch events) to remediation and closure.
  • Engineering background in scripting, automation, APIs, CI/CD workflows, developer tooling, or security platform integrations.
  • Hands-on familiarity with AI-enabled security tools, frontier models, coding assistants, prompt/tool orchestration, model evaluation, or AI governance.
  • Experience securing the software supply chain and developer tooling (IDEs, plugins/extensions, package managers, CI/CD integrations) from compromise and malicious code.
  • Ability to convert technical vulnerabilities into clear remediation steps, risk summaries, and prioritized recommendations for dev and security stakeholders.

Proficiencies

  • Code Scanning
  • DAST
  • Open-source scanning
  • SAST
  • SCA
  • Dynamic and static scanning

Tools & Technologies

  • CI/CD
  • Artificial Intelligence

Benefits & conditions

$80 - $90 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

2:10 min

Defining stream data processing versus standard event processing

Soroosh Khodami Soroosh Khodami · World Congress 2024

2:08 min

Automating pull request triaging and real-time infrastructure scanning

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all