> Markdown version of [/jobs/ext/3122117-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3122117-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** GIANT LLC - **Location:** St. Louis, MO, United States - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Delivery, Continuous Integration, Data Security, Linux, DevOps, Node.Js, OAuth, Open Web Application Security, Ruby on Rails, Regression Testing, JSON Web Token, Secure Coding, Software Engineering, SonarQube, TypeScript, WordPress, Express.js, Spring-boot, Sonatype, Software Security, Technical Debt, Veracode, Generative AI, Kubernetes, Checkmarx, Restful APIs, Multiplatform, Devsecops, Docker, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 28, 2026 - **Apply:** https://www.careerbuilder.com/job-details/application-security-engineer-java-node-js-saint-louis-mo--ae2acbd4-956a-4049-8788-6c65d29eeb0d ## About the Role * Strong hands-on experience with Java, Spring Boot, REST APIs, and secure coding * Proficiency in Node.js, Express.js, JavaScript/TypeScript * Working knowledge of Ruby on Rails and WordPress security * Experience with Veracode, Checkmarx, SonarQube, Snyk, or similar tools * Strong understanding of OWASP vulnerabilities and mitigation techniques * Experience with OAuth2/JWT, API security, Docker, Kubernetes, Linux, and AWS * Hands-on experience integrating security into CI/CD pipelines * Exposure to GenAI tools such as AWS Bedrock or CodeWhisperer Preferred Qualifications * Experience with microservices, cloud-native security, and DevSecOps * Familiarity with OWASP ASVS and threat modeling * Security certifications (CEH, CSSLP, OSCP) a plus Skills: Amazon Web Services (AWS), Application Programming Interface (API), Applications Security, Automation, CEH - Certified Ethical Hacker, Cloud Computing, Computer Security, Continuous Deployment/Delivery, Continuous Integration, DevOps, Docker, Express.js, Information/Data Security (InfoSec), Java, JavaScript, Linux Operating System, Microservices, Multiplatform/Cross-Platform, Node.js, OAuth, Operating Systems, Quality Assurance, REST (Representational State Transfer), Regression Testing, Ruby on Rails, Secure Coding, Software Engineering, Threat Modeling, Wordpress ## Description Seeking a Java / Node.js Engineer focused on application security remediation, technical debt reduction, and automated vulnerability fixes across multiple platforms. This role partners closely with InfoSec, QA, DevOps, and engineering teams to improve security posture using automation and GenAI-driven solutions., * Triage and remediate vulnerabilities from SAST, DAST, and SCA tools * Secure Java, Node.js, Ruby on Rails, and WordPress applications against common OWASP risks * Patch and upgrade third-party dependencies and harden application configurations * Validate fixes through regression testing and user flow checks * Integrate automated security and remediation into CI/CD pipelines * Build GenAI-assisted remediation workflows using AWS Bedrock or similar tools * Reduce technical debt, modernize legacy components, and harden cloud, container, and OS environments * Collaborate with InfoSec and QA teams to close security findings and rescans ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)