Application Security (AppSec) Engineer

Info Dinamica Inc
Maryland Heights, MO, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Business Logic Software System Penetration Testing Microsoft Azure Cloud Computing Cyber Security Continuous Integration DevOps Github
+21 more
Systems Development Life Cycle Secure Coding Security Software Software Vulnerability Management Google Cloud Enterprise Software Applications Spring Cloud Software Security Gitlab Cloudformation GWAPT Containerization Kubernetes Graphql Api Design Terraform Devsecops Jenkins Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

Security in SDLC Microsoft Threat Modeler Backtrack Penetration Testing What are the top 3 skills required for this role? Application Security (AppSec) Secure SDLC / DevSecOps SAST, DAST, IAST, SCA Web, Mobile & API Security Testing Manual Penetration Testing & Business Logic Testing Threat Modelling Vulnerability Management Secure Code Review CI/CD Security Integration Job Description/ Responsibilities The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity. The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle., Application Security Engineering Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications. Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines. Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools. Enable continuous post-deployment security validation and risk monitoring. Security Testing & Validation Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities. Perform authenticated and unauthenticated security assessments of applications and APIs. Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services. Validate remediation effectiveness and secure deployment practices. DevSecOps Integration Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms. Automate vulnerability triage, prioritization, and remediation workflows. Develop security-as-code controls and policy enforcement mechanisms. Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives. Vulnerability Management Analyze findings from multiple security tools and eliminate false positives. Prioritize vulnerabilities based on business risk, exploitability, and application criticality. Track remediation efforts through SDLC and release cycles. Develop security metrics, dashboards, and executive reporting. Developer Enablement Conduct secure coding reviews and developer education sessions. Establish security champions programs across engineering teams. Provide remediation guidance and hands-on support during application releases. Drive adoption of secure development standards and best practices. Cloud & API Security Assess cloud-native applications deployed across AWS, Azure, Google Cloud Platform, Kubernetes, and container platforms. Secure REST, GraphQL, and microservice-based APIs. Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls. Support software supply chain security initiatives, including SBOM/SCA validation.

Requirements

8 15 years of experience in Application Security, DevSecOps, or Security Architecture. Experience securing large-scale enterprise applications across cloud and hybrid environments. Relevant certifications preferred: o CISSP o CSSLP o GWAPT o OSCP o CEH o Azure/AWS Security Certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

4:54 min

Implementing geographic salary tiers for compensation equity and fairness

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all