> Markdown version of [/jobs/ext/1311619-ai-driven-application-security-triage-engineer](https://www.wearedevelopers.com/jobs/ext/1311619-ai-driven-application-security-triage-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI-Driven Application Security Triage Engineer - **Company:** Buckeye Global - **Location:** Canton, OH, United States (Remote available) - **Experience:** Experienced - **Salary:** $166,400.0 - $187,200.0 - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Code Review, Continuous Integration, Programming Tools, Open Source Technology, Package Management Systems, Data Processing, Scripting, Software Security, Model Validation, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ec2a9818ed66a72c ## About the Role * 3+ years of code scanning * 3+ years of open-source scanning * 3+ years of dynamic and static scanning, * Proven track record triaging SCA/SAST/DAST findings and driving high-severity escalations (threat intel and critical patch events) to remediation and closure. * Engineering background in scripting, automation, APIs, CI/CD workflows, developer tooling, or security platform integrations. * Hands-on familiarity with AI-enabled security tools, frontier models, coding assistants, prompt/tool orchestration, model evaluation, or AI governance. * Experience securing the software supply chain and developer tooling (IDEs, plugins/extensions, package managers, CI/CD integrations) from compromise and malicious code. * Ability to convert technical vulnerabilities into clear remediation steps, risk summaries, and prioritized recommendations for dev and security stakeholders. Proficiencies * Code Scanning * DAST * Open-source scanning * SAST * SCA * Dynamic and static scanning Tools & Technologies * CI/CD * Artificial Intelligence ## Description You start your morning scanning the latest SCA, SAST, and DAST findings. Critical and high-risk items are quickly validated, false positives are filtered out, and you document clear remediation guidance. When a PatchNow Critical event lands, you lead the scope analysis, route owners, and drive mitigation steps through to verified closure. If a threat intelligence escalation appears, you coordinate a fast, structured response. By midday, you're drafting concise briefs on newly disclosed and frontier-model-influenced vulnerabilities, translating technical details into action plans for development teams. In the afternoon, you're hands-on with AI-enabled security tooling-testing frontier-model capabilities for code reasoning, triage acceleration, and remediation recommendations while ensuring auditability, secure use controls, and human-in-the-loop review. Before you wrap, you reinforce our software supply chain security-from dependency hygiene (SBOM visibility, malicious package detection, policy enforcement) to safeguarding developer IDEs, plugins/extensions, code-assist tools, package managers, and CI integrations against compromised components and unsafe configurations. Core Responsibilities * Deliver unified triage across SCA/SAST/DAST findings: validate severity, assess exploitability, analyze false positives, and provide actionable fixes and escalations for production and business-critical apps. * Coordinate responses to threat intelligence escalations and PatchNow Critical events, including scoping, owner routing, mitigation guidance, tracking, and closure verification. * Monitor and analyze newly disclosed and novel vulnerabilities-especially those accelerated by frontier-model research-and produce actionable remediation briefs. * Engineer, test, and implement AI-assisted security tooling leveraging frontier models for vulnerability identification, code reasoning, triage acceleration, and analyst workflow automation with appropriate guardrails. * Support evaluation and onboarding of new AI capabilities: proof-of-value execution, security testing, control validation, data handling review, model output evaluation, success metrics, and governance documentation. * Strengthen software supply chain security: secure open-source dependency intake, SBOM and component visibility, malicious package detection, dependency health assessment, and policy enforcement across dev, pipeline, and artifact workflows. * Improve developer environment security: harden IDEs, plugins/extensions, package managers, code-assist tools, and CI integrations against malicious code and compromised components. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)