> Markdown version of [/jobs/ext/1957588-application-security-appsec-engineer](https://www.wearedevelopers.com/jobs/ext/1957588-application-security-appsec-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security (AppSec) Engineer - **Company:** ICONMA LLC - **Location:** St. Louis, MO, United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Business Logic, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cyber Security, Continuous Integration, DevOps, Systems Development Life Cycle, Secure Coding, Security Software, Software Vulnerability Management, Google Cloud, Enterprise Software Applications, Spring Cloud, Delivery Pipeline, Software Security, Gitlab, Cloudformation, GWAPT, Containerization, Kubernetes, Graphql, Api Design, Terraform, Devsecops, Jenkins, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 6, 2026 - **Apply:** https://www.careerjet.com/job/use500e25ead86ca563185b31c3132c817/eaa ## About the Role * What are the top 3 skills required for this role * Application Security (AppSec) * Secure SDLC / DevSecOps * SAST, DAST, IAST, SCA * Web, Mobile & API Security Testing * Manual Penetration Testing & Business Logic Testing * Threat Modelling * Vulnerability Management * Secure Code Review * CI/CD Security Integration * 8-15 years of experience in Application Security, DevSecOps, or Security Architecture. * Experience securing large-scale enterprise applications across cloud and hybrid environments. * Relevant certifications preferred: * CISSP * CSSLP * GWAPT * OSCP * CEH * Azure/AWS Security Certifications * Years of Experience: 12.00 Years of Experience ## Description * The role focuses on embedding security testing, vulnerability management, and business logic validation directly intCI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity. * The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing timprove application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle. Application Security Engineering * Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications. * Integrate security controls and testing activities intAgile, DevOps, and CI/CD pipelines. * Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools. * Enable continuous post-deployment security validation and risk monitoring. * Security Testing & Validation * Conduct manual penetration testing and business logic testing tidentify vulnerabilities beyond automated scanning capabilities. * Perform authenticated and unauthenticated security assessments of applications and APIs. * Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services. * Validate remediation effectiveness and secure deployment practices. * DevSecOps Integration * Embed security testing intGitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms. * Automate vulnerability triage, prioritization, and remediation workflows. * Develop security-as-code controls and policy enforcement mechanisms. * Collaborate with engineering teams timplement secure coding practices and shift-left security initiatives. * Vulnerability Management * Analyze findings from multiple security tools and eliminate false positives. * Prioritize vulnerabilities based on business risk, exploitability, and application criticality. * Track remediation efforts through SDLC and release cycles. * Develop security metrics, dashboards, and executive reporting. * Developer Enablement * Conduct secure coding reviews and developer education sessions. * Establish security champions programs across engineering teams. * Provide remediation guidance and hands-on support during application releases. * Drive adoption of secure development standards and best practices. * Cloud & API Security * Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms. * Secure REST, GraphQL, and microservice-based APIs. * Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls. * Support software supply chain security initiatives, including SBOM/SCA validation. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)