> Markdown version of [/jobs/ext/3005227-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3005227-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Connvertex Technologies Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $120,900.0 - $234,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Data Analysis, Architectural Patterns, Unit Testing, Bash Shell, Big Data, Continuous Integration, DevOps, Github, Mobile Application Software, Python (Programming Language), Security Software, Software Engineering, Multithreading, ReactJS, Software Security, Kubernetes, Teamcity, Api Design, Puppet, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 19, 2026 - **Apply:** https://www.careerjet.com/jobad/use42ca42a86c7e934de0abfe1f1547bcd ## About the Role * Must have: 5+ years software development experience using Python * Working with APIs, including but not limited to ReST * Unit testing frameworks * Multi-process and multi-thread architecture * Must have: 5+ years in linux, strong bash scripting skills. * Deep understanding of CI CD pipelines * Working knowledge of windows environment, simple scripting dos-batch etc. * Bachelor's degree with 10+ years of work experience in the IT field * Ability to process large datasets for reporting and analysis. Preferred Skills: * A self-starter, with a strong desire for learning new technologies and applying them to solve problems * Knowledge of SAST, OSS technologies * Ability to perform Python code reviews with minimal assistance * Expertise in monitoring, alerting, reporting, data analysis is desired. * Experience with application build environments like Jenkins, GitHub Actions, Teamcity etc. * DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc) is a plus * Experience with evaluation, integration and onboard of security tools such as DAST, RASP, WAF, vulnerability scanner results, container analyzers, opensource scanning is a plus ## Description Be part of a team of engineers to implement client specific security policies in the CI/CD security tools including but not limited to SAST, OSS and SCA applications. Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevSecOps processes. Define the security rules that needs to be adhered to at a code level in web and mobile applications written in .NET, Java, React, Python and other languages. With your development background and security knowledge, provide secure stable platform for enforcing application security controls. Support security standards, design & implement architectural patterns to increase the resiliency and scalability of security platform. Work with our partners to implement, manage, and optimize security measures within our GitHub repositories to continuously improve code integrity and protect against vulnerabilities. Roles and Responsibilities: * Be part of a team of engineers to implement client specific security policies in the CI/CD security tools including but not limited to SAST, OSS and SCA applications. * Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevSecOps processes. * Define the security rules that needs to be adhered to at a code level in web and mobile applications written in .NET, Java, React, Python and other languages. * With your development background and security knowledge, provide secure stable platform for enforcing application security controls. * Support security standards, design & implement architectural patterns to increase the resiliency and scalability of security platform. * Work with our partners to implement, manage, and optimize security measures within our GitHub repositories to continuously improve code integrity and protect against vulnerabilities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [The Memory Leak That Ate Our Cluster: A Postmortem](https://www.wearedevelopers.com/videos/2057-the-memory-leak-that-ate-our-cluster-a-postmortem) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)