Application Security Engineer

N2 Services Inc
United States
2 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Spring Security Agile Methodology Amazon Web Services Apache Tomcat Applications Architecture Software System Penetration Testing User Authentication Microsoft Azure Burp Suite Cloud Computing
+37 more
Cloud Computing Security Configuration Management Cyber Security Computer Programming Continuous Integration Linux DevOps Java Platform Enterprise Edition (J2EE) Identity and Access Management JSON JQuery Python (Programming Language) Network Security Systems Development Life Cycle Salesforce.Com Secure Coding Software Engineering TCP/IP Software Vulnerability Management Web Applications Pega Data Logging Scripting Google Cloud ReactJS Spring-boot Software Security Technical Debt Information Technology Web Technologies Dynatrace Devsecops Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Programming Languages Dynamic Application Security Testing

Job description

  • Triage and remediate findings from SAST, DAST, SCA, vulnerability assessments, and bug bounty reports
  • Partner with development teams to implement secure coding practices
  • Provide guidance on application architecture, API security, IAM, authentication, authorization, and logging
  • Integrate security testing into CI/CD pipelines
  • Support DevSecOps, cloud security, and security automation
  • Identify and address software supply-chain and SBOM risks
  • Assist teams with technical debt, application upgrades, and vulnerability remediation
  • Perform or support penetration testing and security assessments
  • Translate technical security risks into clear, prioritized business actions
  • Collaborate with engineering, cybersecurity, platform, and business stakeholders
  • Support cybersecurity risk, compliance, and governance activities

Requirements

We are looking for a Senior Application Security Engineer with strong hands-on experience in software development, application security, cloud security, and DevSecOps. The ideal candidate will work closely with development, cybersecurity, DevOps, and business teams to identify, prioritize, and remediate application security risks.

The candidate should be comfortable working across the full software development lifecycle and have practical coding experience. This role requires someone who can understand developers’’ challenges while applying strong cybersecurity and risk-management principles., * Bachelor’’s Degree Required

  • 6+ years of IT experience
  • 4+ years of software development experience
  • Strong hands-on application security experience
  • SAST, DAST, SCA
  • Vulnerability assessment and remediation
  • Secure coding
  • API Security
  • IAM
  • Application security architecture
  • CI/CD security and DevSecOps
  • AWS, Azure, or Google Cloud Platform
  • Cloud Security
  • Security automation and scripting
  • Software Development Lifecycle (SDLC)
  • Hands-on programming experience in at least 1-2 programming languages
  • Web applications and web technologies
  • Cybersecurity and information security
  • Troubleshooting and problem-solving
  • Strong communication and stakeholder management

Preferred Skills

  • Java, JavaScript, Python
  • Spring Boot / Spring Security
  • React / jQuery
  • J2EE
  • Burp Suite
  • Penetration Testing
  • Linux
  • JSON
  • Network Security / TCP/IP
  • Salesforce / Pega
  • Dynatrace
  • Apache Tomcat
  • SBOM / Software Supply Chain Security
  • Risk Management / Risk Assessment
  • ISO 27001
  • CISSP, CISA, CISM or other security certifications
  • Cloud Infrastructure
  • Solution Architecture
  • Security Compliance
  • Kanban / Agile
  • Change and Configuration Management

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

Videos

See all

Related articles

See all