Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
Insight Global is looking for an Application Security Engineer for one of our state/local government customers in a hybrid role out of Lansing, MI. This role serves as a key partner to software development teams, helping ensure that web, mobile, API, cloud, and container-based applications are designed, built, and deployed securely. On a day-to-day basis, the Senior Full Stack Application Development Security Auditor conducts application security assessments using SAST, DAST, SCA, and container/cloud scanning tools; reviews source code and application architectures for security vulnerabilities; and works directly with developers to remediate findings and implement secure coding practices. The role involves validating authentication and authorization mechanisms such as OAuth, OIDC, PKCE, and JWT, analyzing HTTP requests and responses, evaluating API security controls, and identifying risks related to OWASP Top 10 vulnerabilities including XSS, injection attacks, SSRF, and CSRF. Additionally, the individual collaborates with DevOps and engineering teams to integrate automated security testing into CI/CD pipelines, establish security standards and reusable security patterns, and support continuous compliance efforts across cloud and distributed application environments. Success in this role requires a blend of application development expertise, security knowledge, and the ability to communicate complex security concepts to technical teams while driving secure software development practices across the organization.
Requirements
- 5+ years of total IT related experience.
- 3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
- 3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
- 3+ years with networking, infrastructure, secure application development and security automation (DevSecOps)
- 3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications - Previous state or local government experience
Benefits & conditions
$40/hr to $60/hr : Exact compensation may vary based on several factors, including skills, experience, and education.
Benefit packages while on contract for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Walking Into The Era of Supply Chain Risks
Dev Digest 138 - Are you secure about this?
Is Software Engineering Over-Saturated?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again