Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+11 more
Job description
-
Lead security remediation efforts across multiple VTS engineering teams.
-
Analyze findings from ArmorCode, Contrast, Snyk, SonarQube, and related security tools.
-
Prioritize, track, and drive closure of security vulnerabilities.
-
Perform hands-on coding and implement security fixes in Java/Spring Boot and Angular applications.
-
Conduct code reviews and recommend secure coding practices.
-
Develop reusable remediation patterns to reduce vulnerabilities across multiple applications.
-
Collaborate with engineering, architecture, and security teams.
-
Lead and mentor a 3-5 member security remediation team.
-
Provide status updates, dashboards, and executive-level reporting.
Requirements
-
10+ years of software engineering experience.
-
Strong hands-on expertise in Java, Spring Boot, Angular, JavaScript/TypeScript, REST APIs, and Microservices.
-
Experience working with GitHub, CI/CD pipelines, and modern software delivery practices.
-
Deep understanding of OWASP Top 10, Secure SDLC, DevSecOps, SAST, DAST, and vulnerability management.
-
Experience with security tools such as ArmorCode, Contrast Security, Snyk, Veracode, Checkmarx, or SonarQube.
-
Strong leadership, communication, and stakeholder management skills.
Must Have Skills:
Vulnerability Management & Healthcare Security
Governance Change
Management Software Security
Java / Spring Boot / Angular
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Walking Into The Era of Supply Chain Risks
Dev Digest 121 - AI goes offline
Dev Digest 120 - Apple and peers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.