Application Security Engineer

Indotronix Avani Group
Houston, TX, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Java (Programming Language) Application Programming Interfaces (APIs) Microsoft Azure Burp Suite Cloud Computing Security Code Review Computer Programming Github Python (Programming Language) Open Source Technology Open Web Application Security
+19 more
Systems Development Life Cycle Fortify (Software) Secure Coding SonarQube Web Applications Scripting Software Security Veracode GWAPT Kubernetes Checkmarx Burpsuite Devsecops Docker Jenkins Static Application Security Testing Vulnerability Analysis Microservices Dynamic Application Security Testing

Job description

Application Security Engineer (SAST/DAST Focus)OverviewWe are seeking an Application Security Engineer to support Chevron’s secure software development initiatives This role will focus on implementing and managing SAST/DAST tooling, integrating security into the SDLC, and improving application-level risk postureKey Responsibilities* Implement, Manage, and optimize SAST and DAST tools across application environments* Integrate security testing into CI/CD pipelines (DevSecOps practices)* Perform code reviews and vulnerability assessments* Identify, triage, and remediate application vulnerabilities (OWASP Top 10)* Partner with development teams to embed secure coding practices* Support threat modeling and security design reviews* Monitor and report on application security posture and risk trends* Assis, Checkmarx, veracode, Fortify, SonarQube)o DAST tools (eg, BurpSuite, OWASP ZAP)* Solid understanding of:o OWASP Top 10 / secure coding practiceso Web application architecture (APIs

Requirements

microservices)* Experience integrating security into:o CI/CD pipelines (Azure DevOps, GitHub, Jenkins, etc)* Familiarity with:o Container security (Docker, Kubernetes)o Open-source scanning (SCA tools)* Programming/scripting knowledge (Java, Python, NET, or similar)* Experience working with developers in an agile environmentNice to Have* Cloud security exposure (Azure preferred)* Experience with IaC security scanning* Certifications (eg, CSSLP, GWAPT, Security+)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.iic.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all