Application Security Engineer

DKMRBH Inc.
Albany, NY, United States
21 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Software System Penetration Testing Static Program Analysis Code Review Cyber Security Continuous Integration Web Development WildFly (JBoss AS) Network Security Systems Development Life Cycle Red Hat Enterprise Linux
+15 more
Fortify (Software) Secure Coding Service-Oriented Architecture Software Engineering SonarQube Systems Integration Software Vulnerability Management Web Applications Software Security Cyber Threat Analysis Information Technology Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Work closely with software development teams to identify, document, prioritize, and remediate application security vulnerabilities.
  • Establish appropriate application security checkpoints throughout the SDLC.
  • Perform risk-based application security assessments and penetration testing.
  • Conduct SAST and DAST using application security tools such as Fortify and SonarQube.
  • Review code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks.
  • Evaluate application designs and provide recommendations related to security architecture, vulnerabilities, and remediation.
  • Consult with development leadership regarding secure coding and application security practices.
  • Integrate AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment.
  • Develop repeatable processes for prioritizing security findings, issue dispositions, and remediation activities.
  • Provide concise security status updates, risk assessments, and remediation reports to leadership and stakeholders.
  • Research emerging attack vectors, application vulnerabilities, cybersecurity threats, and industry trends.
  • Develop security training materials and provide application security guidance to development teams.
  • Support compliance with applicable industry security standards and best practices.

Requirements

We are seeking an experienced Application Security Engineer with a strong background in application security, software development, secure coding, vulnerability assessment, penetration testing, and DevSecOps.

The ideal candidate will have hands-on experience working with development teams to identify and remediate application security vulnerabilities, review source code and architecture changes, perform application security testing, and integrate security tools into CI/CD pipelines.

This position supports a large-scale healthcare technology environment built on Java, web applications, Service-Oriented Architecture (SOA), RHEL, JBoss, and COTS products., * 8+ years of Information Technology experience.

  • 5+ years of software development experience as a Developer or Architect.
  • 3+ years of Application Security Engineering experience.
  • Strong Java / Web Development background.
  • Strong secure coding experience.
  • Experience with RHEL / Red Hat Enterprise Linux and JBoss.
  • Experience with Application Security Assessment and Penetration Testing.
  • Hands-on experience with SAST / Static Application Security Testing.
  • Hands-on experience with DAST / Dynamic Application Security Testing.
  • Experience with Fortify and/or SonarQube.
  • Experience reviewing source code, code commits, pull requests, and architecture changes.
  • Experience identifying and remediating application vulnerabilities and security risks.
  • Experience integrating security/code analysis tools into CI/CD pipelines.
  • Hands-on experience with AI-driven code analysis platforms.
  • Experience with DevSecOps and SDLC security.
  • Experience prioritizing security findings and managing vulnerability remediation.
  • Experience preparing risk reports and security updates for technical leadership.

Education

Bachelor’s degree in Computer Science or a related technical field, or an equivalent combination of education and professional experience.

Preferred Certifications

  • CISSP
  • CEH
  • CISA
  • OSCP
  • OSCE
  • OSWE

Required Professional Skills

  • Excellent verbal and written communication skills.
  • Ability to explain complex application security and technical concepts to developers, technical teams, and management.
  • Strong collaboration and teaching abilities.
  • Strong analytical and critical-thinking skills.
  • Strong problem-solving and troubleshooting abilities.
  • Ability to gather and analyze information and develop alternative solutions.
  • Ability to work effectively with developers, architects, security teams, and leadership.

Work Requirements

  • Albany, NY area candidates preferred.
  • Must be available for onsite training.
  • Must be available to work onsite when required.
  • W2 employment required.
  • , , or Valid Visa required., The strongest candidates will be Application Security Engineers, Application Security Developers, DevSecOps Engineers, Product Security Engineers, or Security-focused Software Engineers with a genuine software development background.

This is not a general cybersecurity, SOC, network security, or GRC role. Candidates should have hands-on experience with Java/web applications, secure coding, application security testing, SAST/DAST, Fortify, SonarQube, code review, vulnerability remediation, penetration testing, and CI/CD security.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes Ā· World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

3:23 min

Building and installing the compiled custom rule extension

Daniel Strmečki +1 Ā· World Congress 2022

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho Ā· World Congress 2026 Europe

4:58 min

Scaling security teams through developer advocates

Tanya Janca Ā· World Congress 2021

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia Ā· LIVE

Videos

See all

Related articles

See all