> Markdown version of [/jobs/ext/245379-application-security-engineer-vulnerability-operations-mid-level](https://www.wearedevelopers.com/jobs/ext/245379-application-security-engineer-vulnerability-operations-mid-level). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer Vulnerability Operations (Mid-Level) - **Company:** Saransh Inc - **Location:** Charlotte, NC, United States - **Experience:** Experienced - **Salary:** $93,600.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, JIRA, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Continuous Integration, DevOps, Issue Tracking Systems, Python (Programming Language), Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Scripting, Software Security, GWAPT, Information Technology, Tenable Nessus, 3-tier Architectures, Servicenow, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** May 14, 2026 - **Apply:** https://www.careerjet.com/jobad/us7369c783494d30ec92efca2eb427ef41 ## About the Role Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience. 4 6 years of experience in Application Security, Vulnerability Management, or secure software development. Working knowledge of modern vulnerability classes (OWASP Top 10, API Security Top 10, supply chain risks). Hands-on experience with SAST, DAST, SCA, or related security scanning tools integrated into CI/CD pipelines. Familiarity with SDLC processes and secure coding principles. Experience using workflow/ticketing systems (ServiceNow, JIRA). Strong interpersonal and communication skills for working with engineering teams and AppSec Champions. Preferred Qualifications: Experience with ServiceNow AVR automation or dashboarding. Scripting experience (Python, Bash, PowerShell) for automation and tooling improvements. Background in cloud-native environments (AWS, Azure, or GCP). Certifications such as GWAPT, CSSLP, Security+, or equivalent. ## Description The Application Security Engineer supports and enhances enterprise-wide vulnerability management and secure-development processes. This role works closely with engineering teams and the Application Security Champion community to operationalize AppSec controls, improve scan coverage, triage vulnerabilities, and guide remediation across applications. The engineer also contributes to automation, governance workflows, and continuous improvement initiatives within the Vulnerability Operations program., Application Security Operations Execute and improve SAST, DAST, SCA, and secrets-scanning workflows across CI/CD pipelines. Analyze and triage vulnerabilities; coordinate remediation with product teams and Application Security Champions. Ensure accurate tracking and SLA adherence using ServiceNow AVR workflows. AppSec Champion & Engineering Coordination Partner with the Application Security Champion team to share best practices, communicate emerging vulnerabilities, and strengthen decentralized security maturity. Support Champions in understanding new control requirements and tool adoption. Automation & CI/CD Integration Implement and refine CI/CD pipeline integrations for application security scanning tools. Contribute to policy-as-code rules, scanning templates, and automation scripts to improve efficiency. Assist in enabling Tier 3 gating (merge prevention/build failures) for high-risk policy violations. Governance, Reporting & Visibility Maintain dashboards, risk indicators, and quarterly migration trackers. Provide weekly operational summaries and support preparation of executive-level reports. Participate in risk review discussions, providing clear documentation of impacts and mitigations., As a Senior DevOps Engineer, you will play a crucial role in shaping the future of AI systems by designing and maintaining scalable infrastructure solutions. Your expertise will di… + 7 hours ago + Apply easily ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)