> Markdown version of [/jobs/ext/2773242-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2773242-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Insight Global - **Location:** Lansing, MI, United States - **Experience:** Expert - **Salary:** $83,200.0 - $124,800.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Cloud Computing Security, Cross-Site Request Forgery, DevOps, Hypertext Transfer Protocols (HTTP), IBM Websphere Application Server, Mobile Application Software, WildFly (JBoss AS), Node.Js, OAuth, Open Source Technology, OpenID, Oracle (Applications), Open Web Application Security, Secure Coding, Software Engineering, ReactJS, Spring-boot, Software Security, Cross-Site Scripting (XSS), AngularJS, Tenable Nessus, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 7, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3381146776&tx=JT10193UTI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * 5+ years of total IT related experience. * 3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.) * 3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks * 3+ years with networking, infrastructure, secure application development and security automation (DevSecOps) * 3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications - Previous state or local government experience ## Description Insight Global is looking for an Application Security Engineer for one of our state/local government customers in a hybrid role out of Lansing, MI. This role serves as a key partner to software development teams, helping ensure that web, mobile, API, cloud, and container-based applications are designed, built, and deployed securely. On a day-to-day basis, the Senior Full Stack Application Development Security Auditor conducts application security assessments using SAST, DAST, SCA, and container/cloud scanning tools; reviews source code and application architectures for security vulnerabilities; and works directly with developers to remediate findings and implement secure coding practices. The role involves validating authentication and authorization mechanisms such as OAuth, OIDC, PKCE, and JWT, analyzing HTTP requests and responses, evaluating API security controls, and identifying risks related to OWASP Top 10 vulnerabilities including XSS, injection attacks, SSRF, and CSRF. Additionally, the individual collaborates with DevOps and engineering teams to integrate automated security testing into CI/CD pipelines, establish security standards and reusable security patterns, and support continuous compliance efforts across cloud and distributed application environments. Success in this role requires a blend of application development expertise, security knowledge, and the ability to communicate complex security concepts to technical teams while driving secure software development practices across the organization. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)