> Markdown version of [/jobs/ext/1995319-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1995319-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Indotronix Avani Group - **Location:** Houston, TX, United States - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Microsoft Azure, Burp Suite, Cloud Computing Security, Code Review, Computer Programming, Github, Python (Programming Language), Open Source Technology, Open Web Application Security, Systems Development Life Cycle, Fortify (Software), Secure Coding, SonarQube, Web Applications, Scripting, Software Security, Veracode, GWAPT, Kubernetes, Checkmarx, Burpsuite, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** August 8, 2026 - **Apply:** https://www.iic.com/submit-resume/ ## About the Role microservices)* Experience integrating security into:o CI/CD pipelines (Azure DevOps, GitHub, Jenkins, etc)* Familiarity with:o Container security (Docker, Kubernetes)o Open-source scanning (SCA tools)* Programming/scripting knowledge (Java, Python, NET, or similar)* Experience working with developers in an agile environmentNice to Have* Cloud security exposure (Azure preferred)* Experience with IaC security scanning* Certifications (eg, CSSLP, GWAPT, Security+) ## Description Application Security Engineer (SAST/DAST Focus)OverviewWe are seeking an Application Security Engineer to support Chevron's secure software development initiatives This role will focus on implementing and managing SAST/DAST tooling, integrating security into the SDLC, and improving application-level risk postureKey Responsibilities* Implement, Manage, and optimize SAST and DAST tools across application environments* Integrate security testing into CI/CD pipelines (DevSecOps practices)* Perform code reviews and vulnerability assessments* Identify, triage, and remediate application vulnerabilities (OWASP Top 10)* Partner with development teams to embed secure coding practices* Support threat modeling and security design reviews* Monitor and report on application security posture and risk trends* Assis, Checkmarx, veracode, Fortify, SonarQube)o DAST tools (eg, BurpSuite, OWASP ZAP)* Solid understanding of:o OWASP Top 10 / secure coding practiceso Web application architecture (APIs ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)