Application Security Auditor / DevSecOps Security Engineer
Xcelo Group Inc
Windsor charter Township, MI, United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Kubernetes Security
Java (Programming Language)
.NET Framework
Application Programming Interfaces (APIs)
Advanced Linux Sound Architecture
Amazon Web Services
Applications Architecture
User Authentication
Microsoft Azure
Cloud Computing
Cloud Computing Security
Cloud Engineering
+41 more
Cross-Site Request Forgery
Programming Tools
Distributed Systems
Firefox
Hypertext Transfer Protocols (HTTP)
IBM Websphere Application Server
Mobile Application Software
WildFly (JBoss AS)
Node.Js
OAuth
OpenID
Oracle (Applications)
Open Web Application Security
Programming Environments
Systems Development Life Cycle
Openid Connect
Fortify (Software)
Secure Coding
Software Engineering
Data Streaming
Software Vulnerability Management
Web Applications
Extensible Markup Language (XML)
Computer Networking Systems
Google Cloud
Enterprise Software Applications
ReactJS
Spring-boot
Software Security
Cross-Site Scripting (XSS)
Backend
Containerization
AngularJS
Information Technology
Front End Software Development
Restful APIs
Devsecops
Security Orchestration, Automation & Response
Static Application Security Testing
Vulnerability Analysis
Dynamic Application Security Testing
Job description
We are seeking a highly experienced Senior Application Security Auditor with strong expertise in application security testing, secure software development, DevSecOps, API security, vulnerability assessment, and secure coding practices.
This is not a traditional SOC-focused role. The position will work directly with software engineering teams to identify and remediate security vulnerabilities across front-end, back-end, API, cloud, containerized, and distributed applications., + Cloud Security
- Strong understanding of HTTP request/response headers for web applications and REST APIs.
- Deep understanding of the OWASP Top 10, including the ability to explain vulnerabilities, attack vectors, and remediation approaches.
- Experience identifying and mitigating vulnerabilities such as:
- Cross-Site Scripting (XSS)
- Injection attacks
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- XML External Entity (XXE)
- Authentication and authorization vulnerabilities
- API security vulnerabilities
- Experience implementing secure coding standards and security guidance including:
- OWASP Top 10
- SANS
- CERT Secure Coding
- CWE Top 25
- CIS Critical Security Controls
- Cloud Security Alliance
- SAFECode
- Strong understanding of secure software development practices across technologies such as:
- Angular
- React
- Node.js
- Java
- Spring Boot
- IBM WebSphere Application Server
- Oracle
- JBoss
- .NET
- Experience with both compiled and interpreted programming environments., * Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) across enterprise applications.
- Conduct security assessments of web, mobile, API, cloud, and distributed applications.
- Work closely with development teams to identify vulnerabilities and recommend secure coding remediation strategies.
- Review application architecture, code, APIs, authentication, authorization, and data flows from a security perspective.
- Guide developers on secure coding standards, OWASP vulnerabilities, threat mitigation, and secure SDLC practices.
- Partner with front-end, back-end, API, cloud, and platform engineering teams to integrate security throughout the software development lifecycle.
- Implement and promote reusable application security patterns and secure development practices.
- Integrate security scanning and validation into DevSecOps and CI/CD pipelines.
- Automate secure configuration validation, compliance checks, application security testing, and authorization processes.
- Evaluate REST APIs for authentication, authorization, token management, JWT, OAuth/OIDC, replay attacks, and common API vulnerabilities.
- Analyze HTTP requests and responses to identify security weaknesses.
- Help mature the organization’s Secure Software Development Lifecycle (SSDLC).
- Support continuous compliance and application risk mitigation initiatives.
- Collaborate with distributed engineering teams to improve how applications are designed, developed, secured, deployed, and operated.
- Provide technical guidance on vulnerability remediation and security best practices.
Requirements
- 7+ years of overall IT / Application Security experience preferred
- Minimum 5+ years of total IT experience
- At least 3+ years of hands-on Application Security, Secure Coding, and DevSecOps experience, The ideal candidate should have hands-on experience with SAST, DAST, SCA, ASOC, API security, OWASP vulnerabilities, secure coding frameworks, and security automation., * Experience with:
- Secure application development
- Networking infrastructure
- Security automation
- DevSecOps
- Secure SDLC
- Hands-on experience designing, developing, assessing, or securing distributed web and mobile applications.
- Ability to use browser developer tools such as Chrome, Firefox, and Microsoft Edge DevTools to analyze requests, responses, headers, cookies, and application behavior.
Preferred Skills
- Experience with security tools such as:
- Coverity
- Black Duck
- Fortify
- SRM
- Strong knowledge of API Security.
- Experience with:
- JWT
- OAuth 2.0
- OpenID Connect (OIDC)
- PKCE
- API replay attack prevention
- Understanding of container technologies and container security.
- Cloud development or security experience with:
- Microsoft Azure
- AWS
- Google Cloud Platform (Google Cloud Platform)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
Fully Remote Software Engineer Jobs
over 2 years ago