> Markdown version of [/jobs/ext/2068101-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2068101-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** DKMRBH Inc. - **Location:** Albany, NY, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Software System Penetration Testing, Static Program Analysis, Code Review, Cyber Security, Continuous Integration, Web Development, WildFly (JBoss AS), Network Security, Systems Development Life Cycle, Red Hat Enterprise Linux, Fortify (Software), Secure Coding, Service-Oriented Architecture, Software Engineering, SonarQube, Systems Integration, Software Vulnerability Management, Web Applications, Software Security, Cyber Threat Analysis, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 15, 2026 - **Apply:** https://www.dice.com/job-detail/3b927663-c2c5-4ff4-a41a-6cb6788c87fc ## About the Role We are seeking an experienced Application Security Engineer with a strong background in application security, software development, secure coding, vulnerability assessment, penetration testing, and DevSecOps. The ideal candidate will have hands-on experience working with development teams to identify and remediate application security vulnerabilities, review source code and architecture changes, perform application security testing, and integrate security tools into CI/CD pipelines. This position supports a large-scale healthcare technology environment built on Java, web applications, Service-Oriented Architecture (SOA), RHEL, JBoss, and COTS products., * 8+ years of Information Technology experience. * 5+ years of software development experience as a Developer or Architect. * 3+ years of Application Security Engineering experience. * Strong Java / Web Development background. * Strong secure coding experience. * Experience with RHEL / Red Hat Enterprise Linux and JBoss. * Experience with Application Security Assessment and Penetration Testing. * Hands-on experience with SAST / Static Application Security Testing. * Hands-on experience with DAST / Dynamic Application Security Testing. * Experience with Fortify and/or SonarQube. * Experience reviewing source code, code commits, pull requests, and architecture changes. * Experience identifying and remediating application vulnerabilities and security risks. * Experience integrating security/code analysis tools into CI/CD pipelines. * Hands-on experience with AI-driven code analysis platforms. * Experience with DevSecOps and SDLC security. * Experience prioritizing security findings and managing vulnerability remediation. * Experience preparing risk reports and security updates for technical leadership. Education Bachelor's degree in Computer Science or a related technical field, or an equivalent combination of education and professional experience. Preferred Certifications * CISSP * CEH * CISA * OSCP * OSCE * OSWE Required Professional Skills * Excellent verbal and written communication skills. * Ability to explain complex application security and technical concepts to developers, technical teams, and management. * Strong collaboration and teaching abilities. * Strong analytical and critical-thinking skills. * Strong problem-solving and troubleshooting abilities. * Ability to gather and analyze information and develop alternative solutions. * Ability to work effectively with developers, architects, security teams, and leadership. Work Requirements * Albany, NY area candidates preferred. * Must be available for onsite training. * Must be available to work onsite when required. * W2 employment required. * , , or Valid Visa required., The strongest candidates will be Application Security Engineers, Application Security Developers, DevSecOps Engineers, Product Security Engineers, or Security-focused Software Engineers with a genuine software development background. This is not a general cybersecurity, SOC, network security, or GRC role. Candidates should have hands-on experience with Java/web applications, secure coding, application security testing, SAST/DAST, Fortify, SonarQube, code review, vulnerability remediation, penetration testing, and CI/CD security. ## Description * Work closely with software development teams to identify, document, prioritize, and remediate application security vulnerabilities. * Establish appropriate application security checkpoints throughout the SDLC. * Perform risk-based application security assessments and penetration testing. * Conduct SAST and DAST using application security tools such as Fortify and SonarQube. * Review code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks. * Evaluate application designs and provide recommendations related to security architecture, vulnerabilities, and remediation. * Consult with development leadership regarding secure coding and application security practices. * Integrate AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment. * Develop repeatable processes for prioritizing security findings, issue dispositions, and remediation activities. * Provide concise security status updates, risk assessments, and remediation reports to leadership and stakeholders. * Research emerging attack vectors, application vulnerabilities, cybersecurity threats, and industry trends. * Develop security training materials and provide application security guidance to development teams. * Support compliance with applicable industry security standards and best practices. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)