> Markdown version of [/jobs/ext/1914585-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1914585-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** SDH Systems LLC - **Location:** Rockville, MD, United States (Remote available) - **Experience:** Expert - **Contract:** Temporary to permanent - **Skills:** Java (Programming Language), JavaScript (Programming Language), Amazon Web Services, Software System Penetration Testing, User Authentication, Automation of Tests, Burp Suite, Cloud Computing Security, Static Program Analysis, Cyber Security, Computer Programming, Computer Engineering, Continuous Integration, DevOps, Python (Programming Language), Key Management, Network Security, Open Web Application Security, Secure Coding, Software Engineering, Systems Integration, Scripting, Software Security, Infrastructure as Code (IaC), Gitlab, Information Technology, Devsecops, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 4, 2026 - **Apply:** https://www.dice.com/job-detail/1131f246-daa9-4f6a-a39a-a0bdb96383f5 ## About the Role Bachelor''s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field. 5+ years of experience in cybersecurity with a strong focus on application security. Hands-on experience with SAST, DAST, IAST, and related application security testing methodologies and tools. Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles, and remediation strategies. Experience performing manual penetration testing and application vulnerability assessments. Proficiency in one or more programming or scripting languages such as Java, Python, or JavaScript. Experience integrating security tooling into CI/CD pipelines using platforms such as Jenkins and GitLab. Strong knowledge of security engineering concepts including authentication, authorization, cryptography, network security, and secure application architecture. Experience with AWS cloud security concepts, services, and configuration reviews. Excellent communication skills with the ability to collaborate effectively across engineering and security teams. Preferred Qualifications Background in software engineering or application development. Familiarity with GenAI-assisted security tooling and automated code analysis solutions. Experience with Infrastructure as Code (IaC) security scanning and secrets management tools. Experience conducting infrastructure or application-level vulnerability testing and security auditing., Experience supporting enterprise DevSecOps transformation initiatives. Technical Environment Application Security: SAST, DAST, IAST, Secure Code Review Cloud Platforms: AWS CI/CD Tools: Jenkins, GitLab Security Testing Tools: Burp Suite and related proxy/testing tools Programming Languages: Java, Python, JavaScript ## Description The Senior Application Security Engineer is responsible for designing, implementing, and advancing application security practices across the Software Development Life Cycle (SDLC). This role partners closely with engineering, DevOps, and security teams to identify vulnerabilities, support remediation efforts, evaluate security tooling, and strengthen secure development practices., Perform application security assessments, manual penetration testing, and vulnerability validation using tools such as Burp Suite and other proxy/security testing tools. Analyze and triage findings from SAST, DAST, IAST, IaC, and secrets detection tools to identify, prioritize, and support remediation of security vulnerabilities. Partner with engineering teams to integrate security controls and testing into CI/CD pipelines in support of DevSecOps initiatives. Conduct secure code reviews and leverage GenAI-enabled security tooling to improve scalability and efficiency of application security analysis. Evaluate, recommend, and implement application security tools and technologies, including emerging capabilities related to automated code analysis and cloud security. Perform AWS configuration and cloud security reviews to ensure adherence to security best practices and compliance standards. Develop and maintain documentation related to security findings, remediation activities, risk assessments, and compliance requirements. Contribute to the development, interpretation, and enforcement of application security policies, standards, and procedures. Support enterprise security compliance initiatives and participate in audit and risk management activities. Deliver security awareness training and educate developers and QA engineers on common application security risks, secure coding practices, and remediation techniques. Stay current on emerging threats, vulnerabilities, attack techniques, and security technologies to continuously improve the organization''s security posture. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)