> Markdown version of [/jobs/ext/2032874-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2032874-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Solventum Corporation - **Location:** Maplewood, MN, United States - **Experience:** Experienced - **Salary:** $125,600.0 - $172,700.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software Applications, Microsoft Azure, Python (Programming Language), Open Web Application Security, Swagger, Software Vulnerability Management, Web Applications, Postman, Software Security, Restful APIs, Qualys, Dynamic Application Security Testing - **Published:** August 12, 2026 - **Apply:** https://www.disabledperson.com/jobs/74190998-application-security-engineer ## About the Role * Bachelor's Degree & 7 years of experience application security * 3 years' experience administering, running, and analyzing DAST tools * Knowledgeable with AWS or Azure cloud environments * Familiarity with best practice software security requirements in industry standard compliance programs (NIST, HITRUST, FedRAMP, etc.) * Experience developing or testing RESTful APIs with an understanding of Postman and/or Swagger files * Ability to obtain and maintain a Public Trust clearance Additional qualifications that could help you succeed even further in this role include: * Experience administering Qualys or Tenable vulnerability management and application security modules * Experience in working across multiple teams and disciplines * Strong attention to detail and analytical skills. * Risk-based prioritization and sound judgment. ## Description * Authoring automation scripts for reoccurring tasks (Python preferred) * Setup and execute authenticated and unauthenticated dynamic application security testing (DAST) scans against web applications and APIs using approved tools. * Manage scan scheduling, configuration, and coverage across application security tool environments. * Tune scanning profiles to reduce false positives and improve detection accuracy. * Ensure DAST scanning aligns with release cycles and risk-based scanning requirements * Validate DAST findings to confirm exploitability and business impact. * Categorize vulnerabilities using industry standards (e.g., OWASP Top 10). * Prioritize findings based on risk, application criticality, and exposure. * Eliminate false positives and duplicate findings prior to developer handoff. * Partner with development and platform teams to explain DAST findings and remediation expectations. * Track remediation progress and verify fixes through re-scanning or targeted validation. * Maintain accurate vulnerability records in enterprise tracking systems. * Escalate overdue or high-risk vulnerabilities in accordance with policy. * Working with application teams to validate that software applications meet security guidelines and compliance standards such as HIPPA, SOC II, GDPR, NIST 800-53, FedRAMP, etc. * Building solutions that collect and present vulnerability and compliance data to Solventum's leadership., Onboarding Requirement: To improve the onboarding experience, you will have an opportunity to meet with your manager and other new employees as part of the Solventum new employee orientation. As a result, new employees hired for this position will be required to travel to a designated company location for on-site onboarding during their initial days of employment. Travel arrangements and related expenses will be coordinated and paid for by the company in accordance with its travel policy. Applies to new hires with a start date of October 1st 2025 or later. ## Related Videos - [Are Your APIs Ready for AI Agents](https://www.wearedevelopers.com/videos/2004-are-your-apis-ready-for-ai-agents) - [Using code generation for test automation – the fancy way](https://www.wearedevelopers.com/videos/230-using-code-generation-for-test-automation-the-fancy-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [1, 2, 3... Fastify!](https://www.wearedevelopers.com/videos/325-1-2-3-fastify) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Quarkus. A Bliss for developers](https://www.wearedevelopers.com/videos/385-quarkus-a-bliss-for-developers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)