> Markdown version of [/jobs/ext/2565601-application-security-engineer-68257](https://www.wearedevelopers.com/jobs/ext/2565601-application-security-engineer-68257). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer-68257 - **Company:** Hitachi, Ltd. - **Location:** Dallas, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Burp Suite, C Sharp (Programming Language), Cloud Computing Security, Cloud Engineering, Computer Programming, Continuous Integration, Cursor (Graphical User Interface Elements), Github, Python (Programming Language), Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Fortify (Software), Secure Coding, Software Engineering, SonarQube, Software Vulnerability Management, Scripting, Spring Cloud, GitHub Copilot, Large Language Models, Software Security, Veracode, Cloudformation, Gitlab-ci, Tenable Nessus, Bicep, Checkmarx, Terraform, Devsecops, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 2, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17795638?backUrl=%2Fcareer%2F17795638%2FApplication-Security-Engineer-68257-Texas-Dallas ## About the Role Hitachi Digital Services is seeking an Application Security Engineer to support application security, DevSecOps, secure software development, and AI-enabled security initiatives. The ideal candidate should have hands-on experience with application security testing, CI/CD security, vulnerability management, secure code reviews, and OWASP-based security practices., * Minimum 2 years of experience in Application Security, DevSecOps, Secure Development, or Software Security. * Strong understanding of: + OWASP Top 10 + Secure SDLC + Threat Modeling + Secure Code Review + API Security Fundamentals * Familiarity with CI/CD platforms such as: + Azure DevOps + GitHub Actions + Jenkins + GitLab CI/CD * Hands-on experience with one or more: + SAST: Checkmarx, Veracode, Fortify, SonarQube + DAST: Burp Suite, OWASP ZAP + SCA: Snyk, Mend, Black Duck * Knowledge of containers and Kubernetes security fundamentals. * Basic scripting/programming skills (Python, PowerShell, JavaScript, Java, C#, etc.). Preferred Qualifications * Experience with Azure and/or AWS cloud environments. * Knowledge of DevSecOps automation and Infrastructure-as-Code security (Terraform, Bicep, ARM, CloudFormation). * Experience securing containerized and cloud-native applications. * Familiarity with AI-assisted development tools (GitHub Copilot, Amazon Q, Cursor, etc.). * Understanding of AI/LLM security concepts, including prompt injection, sensitive data exposure, model misuse, and OWASP Top 10 for LLM Applications. * Experience with vulnerability management and application security governance programs. Preferred Certifications * Security+ * SSCP * CySA+ * CEH * CSSLP * AZ-500 * AWS Certified Security - Specialty * Relevant Application Security, DevSecOps, or Cloud Security certifications ## Description * Perform application security assessments for web, API, cloud-native, and AI-enabled applications. * Conduct secure code reviews and support vulnerability remediation efforts. * Integrate security controls into CI/CD pipelines and DevSecOps workflows. * Analyze findings from SAST, DAST, SCA, container security, and secret scanning tools. * Participate in threat modeling and application security design reviews. * Provide guidance on secure coding practices, OWASP Top 10, and OWASP API Security Top 10. * Collaborate with development teams to improve security posture and adopt secure-by-design principles. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)