> Markdown version of [/jobs/ext/1925536-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1925536-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Infosys - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, Microsoft Azure, Burp Suite, Continuous Integration, Open Web Application Security, Systems Development Life Cycle, Power BI, Fortify (Software), Secure Coding, SonarQube, Software Vulnerability Management, Software Security, Mitre Att&ck, Mttr, Sonatype Nexus, GWAPT, Appscan, Devsecops, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 5, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/senior-application-security-engineer-wisconsin-usa-58800685 ## About the Role effectiveness * Support security governance, risk assessments, threat modeling, secure design reviews, and compliance activities * Create security dashboards and metrics (vulnerability trends, SLAs, MTTR, testing coverage) and communicate risks to stakeholders Tasks * 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related disciplines * Strong hands-on with SAST, DAST, SCA, penetration testing, API security testing, and manual assessments * Extensive experience with Burp Suite; familiarity with HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools) * Deep understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, and risk-based prioritization * Experience collaborating with development teams to drive remediation and security maturity * Strong written and verbal communication with stakeholders * Preferred: Azure Cloud & Azure DevOps, ServiceNow, Power BI, and governance frameworks (NIST, MITRE ATT&CK, CIS) * Certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP/OSWE, Security+, AZ-500 are a plus Key requirements * ## Description Experteer Overview In this role you will lead application security testing and governance to strengthen software security across web, API, and cloud apps. You will drive vulnerability management, collaborate with development teams to embed secure practices in the SDLC, and contribute to risk-based security reporting. You will work within a security-focused function that partners with cross-functional teams to scale secure development and compliance. This is a chance to shape security maturity in a global consulting environment. Compensation / Benefits * Perform SAST, DAST, SCA, penetration testing, API security testing and manual security reviews across web, API, cloud and enterprise apps * Validate findings, analyze false positives, and retest to verify remediation effectiveness * Lead vulnerability management activities including prioritization, remediation tracking, and reporting * Advise development teams on secure coding, remediation strategies, and secure SDLC integration in CI/CD/DevSecOps * Support security governance, risk assessments, threat modeling, secure design reviews, and compliance activities * Create security dashboards and metrics (vulnerability trends, SLAs, MTTR, testing coverage) and communicate risks to stakeholders Tasks * 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related disciplines * Strong hands-on with SAST, DAST, SCA, penetration testing, API security testing, and manual assessments * Extensive experience with Burp Suite; familiarity with HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools) * Deep understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, and risk-based prioritization * Experience collaborating with development teams to drive remediation and security maturity * Strong written and verbal communication with stakeholders * Preferred: Azure Cloud & Azure DevOps, ServiceNow, Power BI, and governance frameworks (NIST, MITRE ATT&CK, CIS) * Certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP/OSWE, Security+, AZ-500 are a plus Key requirements * ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)