> Markdown version of [/jobs/ext/1812207-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1812207-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Automatic Data Processing, Inc. - **Location:** Roseland, NJ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, DevOps, Python (Programming Language), Node.Js, Open Source Technology, Open Web Application Security, Systems Development Life Cycle, Prometheus, Standard Sql, SQL Databases, Software Vulnerability Management, Sonatype, Software Security, Sonatype Nexus, Kubernetes, Information Technology, Tenable Nessus, Free and Open-Source Software, Npm(Software), Artifactory - **Published:** July 2, 2026 - **Apply:** https://dejobs.org/x/x/0E32B31A71FD415D9C09F977C8EB672B/job/ ## About the Role * 7+ years of experience in cybersecurity, application security, or software supply chain security. * Hands-on experience with SBOMs, OSS scanning tools, and vulnerability management. * Experience with JFrog or Sonatype artifact repository platforms. * Strong background in cloud-native security and automation. * Primary qualification: Python, AWS + Kubernetes + SQL + Security certifications (CISSP, CSSLP, etc.) are a plus TO SUCCEED IN THIS ROLE: * You'll have a bachelor's degree in computer science, Information Security, or related field (or equivalent experience). Skills & Technologies * Programming: Python; npm / Node.js ecosystems * Cloud & Platforms: AWS, Kubernetes, SQL * OSS & Supply Chain: JFrog Artifactory/Xray, Sonatype Nexus/Lifecycle * Reporting & Monitoring: Amazon QuickSight, Prometheus, * Knowledge of OWASP, NIST, and secure SDLC practices. * Strong communication and cross-functional collaboration skills. * Security certifications (CISSP, CSSLP, etc.) are a plus., * Have courageous team collaboration. Courage comes from how associates are willing to have difficult conversations, speak up, be an owner, and challenge one another's ideas to net out the best solution. ## Description We are seeking a Senior Application Security Engineer to secure our software supply chain by assessing, governing, and mitigating risks associated with open-source software. This role partners closely with engineering, DevOps, and security teams to drive secure OSS adoption at scale. What You'll Do * Generate and analyze SBOMs and conduct OSS security assessments using tools like Snyk and Syft. * Evaluate and onboard security tools through POCs. * Build and operate cloud-based data pipelines to identify vulnerabilities, license risks, and supply chain threats. * Develop dashboards and reports to communicate security risk to engineering teams and leadership. * Design and integrate OSS security tooling, including JFrog Artifactory/Xray or Sonatype Nexus/Lifecycle. * Partner with engineering teams to guide secure open-source usage and remediation. * Support incident response efforts, including zero-day vulnerability management. * Create OSS security standards, documentation, and training materials. ## Related Videos - [Open sourcing a library: how hard can that be?](https://www.wearedevelopers.com/videos/1058-open-sourcing-a-library-how-hard-can-that-be) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)