> Markdown version of [/jobs/ext/2705526-full-stack-application-security-auditor](https://www.wearedevelopers.com/jobs/ext/2705526-full-stack-application-security-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Full-Stack Application Security Auditor - **Company:** Stellar Professionals - **Location:** Dimondale, MI, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Advanced Linux Sound Architecture, Amazon Web Services, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Code Review, Cyber Security, Cross-Site Request Forgery, Programming Tools, IBM Websphere Application Server, Information Systems Security Architecture Professional, WildFly (JBoss AS), Node.Js, OAuth, OpenID, Open Web Application Security, Openid Connect, Secure Coding, Web Application Security, Software Engineering, SQL Injection, Systems Integration, Web Applications, Google Cloud, ReactJS, Spring-boot, Software Security, Cross-Site Scripting (XSS), Containerization, AngularJS, Information Technology, Tenable Nessus, Cloud Integration, CIS Benchmarks, Restful APIs, Micro Focus Fortify, Devsecops, Docker, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/344f9965-cc09-4259-823f-6da019770b00 ## About the Role * Overall IT Experience: 5+ years of total IT experience with a strong background in software development. * AppSec Scanning Tools: Direct experience executing SAST, DAST, SCA, and ASOC assessments for web and containerized applications. * Secure Coding Standards: 3+ years applying secure coding frameworks (OWASP Top 10, CWE Top 25, SANS, CERT, CIS Controls, SAFECode). * Software Development Stack: 3+ years of experience with compiled and interpreted technologies (Java, Spring Boot, Angular, React, Node.js, .NET, WebSphere/JBoss). * DevSecOps & Secure Architecture: 3+ years integrating application security automation into CI/CD pipelines and infrastructure environments. * Web & API Security: Demonstrated capability inspecting HTTP headers, securing RESTful APIs, and auditing web application traffic., * Enterprise AppSec Tools: Hands-on experience with tools like Coverity, Black Duck, Synopsys SRM, or Micro Focus Fortify. * Identity & Authentication Standards: Deep familiarity with OAuth, OpenID Connect (OIDC), PKCE, and JWT token management. * Cloud & Containerization: Practical knowledge of Docker/Kubernetes container security and cloud application architectures (Azure, AWS, or Google Cloud Platform). ## Description We are seeking a Senior Full-Stack Application Security Auditor to join the State of Michigan's Cyber Security team in Dimondale, MI. Unlike a traditional SOC role, this position focuses directly on embedded application security-partnering with development teams to review code, run AppSec tools (SAST/DAST/SCA), enforce DevSecOps automation, and audit secure application designs for web and mobile platforms. * Client: State of Michigan - Cyber Security / Critical Infrastructure Protection (CIP) * Location: Dimondale, MI 48821 (7150 Harris Dr) * Work Arrangement: Hybrid (2 days required onsite per week: Wednesdays & Thursdays; candidates MUST reside within 90-100 miles of Dimondale, MI at time of submission) * Role Type: Contract (10/05/2026 - 10/05/2027, 1-year contract with extension potential) * Interview Process: 1st Round MS Teams Virtual Interview, followed by mandatory 2nd Round IN-PERSON Interview in Dimondale, MI * Special Requirements: Candidate-written cover letter and completed prescreening questionnaire required at submission; candidate must be able to pass a CJIS background check., * Application Security Auditing: Partner with software engineering teams to evaluate application security, secure coding practices, and runtime configurations across full-stack systems (.NET, Java, Node.js, Angular, React). * Vulnerability Assessments & Scanning: Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Application Security Orchestration and Correlation (ASOC) scanning. * API & Web Security: Inspect HTTP Request/Response headers via browser developer tools; evaluate API security protocols (OAuth, OIDC, PKCE, JWT) and mitigate web/API replay threats. * Threat Mitigation & Code Review: Perform root-cause analysis and provide remediation guidance for OWASP Top 10 vulnerabilities (XSS, SQL Injection, SSRF, CSRF, XXE). * DevSecOps & Cloud Integration: Embed security patterns and automated compliance verification into CI/CD pipelines, container environments, and cloud platforms (Azure, AWS, Google Cloud Platform). ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)