Application Security Engineer

Insight Global
Lansing, MI, United States
1 day ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$83,200.0 - $124,800.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Cloud Computing Security Cross-Site Request Forgery DevOps Hypertext Transfer Protocols (HTTP) IBM Websphere Application Server Mobile Application Software WildFly (JBoss AS) Node.Js OAuth
+16 more
Open Source Technology OpenID Oracle (Applications) Open Web Application Security Secure Coding Software Engineering ReactJS Spring-boot Software Security Cross-Site Scripting (XSS) AngularJS Tenable Nessus Devsecops Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

Insight Global is looking for an Application Security Engineer for one of our state/local government customers in a hybrid role out of Lansing, MI. This role serves as a key partner to software development teams, helping ensure that web, mobile, API, cloud, and container-based applications are designed, built, and deployed securely. On a day-to-day basis, the Senior Full Stack Application Development Security Auditor conducts application security assessments using SAST, DAST, SCA, and container/cloud scanning tools; reviews source code and application architectures for security vulnerabilities; and works directly with developers to remediate findings and implement secure coding practices. The role involves validating authentication and authorization mechanisms such as OAuth, OIDC, PKCE, and JWT, analyzing HTTP requests and responses, evaluating API security controls, and identifying risks related to OWASP Top 10 vulnerabilities including XSS, injection attacks, SSRF, and CSRF. Additionally, the individual collaborates with DevOps and engineering teams to integrate automated security testing into CI/CD pipelines, establish security standards and reusable security patterns, and support continuous compliance efforts across cloud and distributed application environments. Success in this role requires a blend of application development expertise, security knowledge, and the ability to communicate complex security concepts to technical teams while driving secure software development practices across the organization.

Requirements

  • 5+ years of total IT related experience.
  • 3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
  • 3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
  • 3+ years with networking, infrastructure, secure application development and security automation (DevSecOps)
  • 3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications - Previous state or local government experience

Benefits & conditions

$40/hr to $60/hr : Exact compensation may vary based on several factors, including skills, experience, and education.

Benefit packages while on contract for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all