Application Security Engineer

GIANT LLC
St. Louis, MO, United States
1 day ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Cloud Computing Cloud Computing Security Cyber Security Continuous Delivery Continuous Integration Data Security Linux DevOps
+27 more
Node.Js OAuth Open Web Application Security Ruby on Rails Regression Testing JSON Web Token Secure Coding Software Engineering SonarQube TypeScript WordPress Express.js Spring-boot Sonatype Software Security Technical Debt Veracode Generative AI Kubernetes Checkmarx Restful APIs Multiplatform Devsecops Docker Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

Seeking a Java / Node.js Engineer focused on application security remediation, technical debt reduction, and automated vulnerability fixes across multiple platforms. This role partners closely with InfoSec, QA, DevOps, and engineering teams to improve security posture using automation and GenAI-driven solutions., * Triage and remediate vulnerabilities from SAST, DAST, and SCA tools

  • Secure Java, Node.js, Ruby on Rails, and WordPress applications against common OWASP risks
  • Patch and upgrade third-party dependencies and harden application configurations
  • Validate fixes through regression testing and user flow checks
  • Integrate automated security and remediation into CI/CD pipelines
  • Build GenAI-assisted remediation workflows using AWS Bedrock or similar tools
  • Reduce technical debt, modernize legacy components, and harden cloud, container, and OS environments
  • Collaborate with InfoSec and QA teams to close security findings and rescans

Requirements

  • Strong hands-on experience with Java, Spring Boot, REST APIs, and secure coding
  • Proficiency in Node.js, Express.js, JavaScript/TypeScript
  • Working knowledge of Ruby on Rails and WordPress security
  • Experience with Veracode, Checkmarx, SonarQube, Snyk, or similar tools
  • Strong understanding of OWASP vulnerabilities and mitigation techniques
  • Experience with OAuth2/JWT, API security, Docker, Kubernetes, Linux, and AWS
  • Hands-on experience integrating security into CI/CD pipelines
  • Exposure to GenAI tools such as AWS Bedrock or CodeWhisperer

Preferred Qualifications

  • Experience with microservices, cloud-native security, and DevSecOps
  • Familiarity with OWASP ASVS and threat modeling
  • Security certifications (CEH, CSSLP, OSCP) a plus

Skills: Amazon Web Services (AWS), Application Programming Interface (API), Applications Security, Automation, CEH - Certified Ethical Hacker, Cloud Computing, Computer Security, Continuous Deployment/Delivery, Continuous Integration, DevOps, Docker, Express.js, Information/Data Security (InfoSec), Java, JavaScript, Linux Operating System, Microservices, Multiplatform/Cross-Platform, Node.js, OAuth, Operating Systems, Quality Assurance, REST (Representational State Transfer), Regression Testing, Ruby on Rails, Secure Coding, Software Engineering, Threat Modeling, Wordpress

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all