Full-Stack Application Security Auditor

Stellar Professionals
Dimondale, MI, United States
1 day ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Advanced Linux Sound Architecture Amazon Web Services User Authentication Microsoft Azure Software as a Service Cloud Computing Code Review Cyber Security Cross-Site Request Forgery
+33 more
Programming Tools IBM Websphere Application Server Information Systems Security Architecture Professional WildFly (JBoss AS) Node.Js OAuth OpenID Open Web Application Security Openid Connect Secure Coding Web Application Security Software Engineering SQL Injection Systems Integration Web Applications Google Cloud ReactJS Spring-boot Software Security Cross-Site Scripting (XSS) Containerization AngularJS Information Technology Tenable Nessus Cloud Integration CIS Benchmarks Restful APIs Micro Focus Fortify Devsecops Docker Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

We are seeking a Senior Full-Stack Application Security Auditor to join the State of Michigan’s Cyber Security team in Dimondale, MI. Unlike a traditional SOC role, this position focuses directly on embedded application security-partnering with development teams to review code, run AppSec tools (SAST/DAST/SCA), enforce DevSecOps automation, and audit secure application designs for web and mobile platforms.

  • Client: State of Michigan - Cyber Security / Critical Infrastructure Protection (CIP)
  • Location: Dimondale, MI 48821 (7150 Harris Dr)
  • Work Arrangement: Hybrid (2 days required onsite per week: Wednesdays & Thursdays; candidates MUST reside within 90-100 miles of Dimondale, MI at time of submission)
  • Role Type: Contract (10/05/2026 - 10/05/2027, 1-year contract with extension potential)
  • Interview Process: 1st Round MS Teams Virtual Interview, followed by mandatory 2nd Round IN-PERSON Interview in Dimondale, MI
  • Special Requirements: Candidate-written cover letter and completed prescreening questionnaire required at submission; candidate must be able to pass a CJIS background check., * Application Security Auditing: Partner with software engineering teams to evaluate application security, secure coding practices, and runtime configurations across full-stack systems (.NET, Java, Node.js, Angular, React).
  • Vulnerability Assessments & Scanning: Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Application Security Orchestration and Correlation (ASOC) scanning.
  • API & Web Security: Inspect HTTP Request/Response headers via browser developer tools; evaluate API security protocols (OAuth, OIDC, PKCE, JWT) and mitigate web/API replay threats.
  • Threat Mitigation & Code Review: Perform root-cause analysis and provide remediation guidance for OWASP Top 10 vulnerabilities (XSS, SQL Injection, SSRF, CSRF, XXE).
  • DevSecOps & Cloud Integration: Embed security patterns and automated compliance verification into CI/CD pipelines, container environments, and cloud platforms (Azure, AWS, Google Cloud Platform).

Requirements

  • Overall IT Experience: 5+ years of total IT experience with a strong background in software development.
  • AppSec Scanning Tools: Direct experience executing SAST, DAST, SCA, and ASOC assessments for web and containerized applications.
  • Secure Coding Standards: 3+ years applying secure coding frameworks (OWASP Top 10, CWE Top 25, SANS, CERT, CIS Controls, SAFECode).
  • Software Development Stack: 3+ years of experience with compiled and interpreted technologies (Java, Spring Boot, Angular, React, Node.js, .NET, WebSphere/JBoss).
  • DevSecOps & Secure Architecture: 3+ years integrating application security automation into CI/CD pipelines and infrastructure environments.
  • Web & API Security: Demonstrated capability inspecting HTTP headers, securing RESTful APIs, and auditing web application traffic., * Enterprise AppSec Tools: Hands-on experience with tools like Coverity, Black Duck, Synopsys SRM, or Micro Focus Fortify.
  • Identity & Authentication Standards: Deep familiarity with OAuth, OpenID Connect (OIDC), PKCE, and JWT token management.
  • Cloud & Containerization: Practical knowledge of Docker/Kubernetes container security and cloud application architectures (Azure, AWS, or Google Cloud Platform).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all