> Markdown version of [/jobs/ext/2618931-middle-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2618931-middle-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Middle Application Security Engineer - **Company:** AgileEngine, LLC - **Location:** Baltimore, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Computer Programming, Continuous Integration, Python (Programming Language), Secure Coding, Software Engineering, Software Vulnerability Management, Scripting, Software Security, Tenable Nessus, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 7, 2026 - **Apply:** https://www.dice.com/job-detail/64b5aad2-615c-4d15-9269-e0594d7dffb9 ## About the Role If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!, You must be authorized to work for ANY employer in the US (e.g., s, TN visa holders, U4U with EAD), as we are unable to sponsor or take over employment visa sponsorship at this time; - 3-5 years of commercial experience blending software engineering and DevSecOps/AppSec; - Solid coding proficiency in Python for automation and scripting; - Ability to comfortably read and navigate Java source code; - Working knowledge of modern CI/CD orchestration tools; - Practical experience interacting with vulnerability scoring frameworks; - Ability to operate with minimal supervision on day-to-day execution and reliably complete complex scripting and integration tasks; - Upper-intermediate English level. NICE TO HAVES - Hands-on experience with CNAPP or ASPM platforms such as Wiz; - Basic understanding of application threat modeling. ## Description We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated hardened baseline deployment within a large-scale financial services security program. You will write Python scripts to integrate SAST, DAST, and SCA gates into CI/CD pipelines, tune scanning tools to reduce false positives, and provide code-level remediation guidance to Java and Python development teams. The role requires 3-5 years of combined software engineering and AppSec experience. WHAT YOU WILL DO - Write and maintain the scripts necessary to integrate security gates such as SAST, DAST, and SCA into CI/CD pipelines; - Continuously tune and configure existing security scanning tools to eliminate false positives and deliver high-confidence alerts; - Assist in coding and deploying automated hardened baselines and secure coding patterns; - Work directly with product development teams to provide actionable, code-level remediation guidance in Java and Python. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)