> Markdown version of [/jobs/ext/3143258-security-engineer](https://www.wearedevelopers.com/jobs/ext/3143258-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Verizon Communications Inc. - **Location:** United States (Remote available) - **Salary:** $72,000.0 - $129,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Bash Shell, Burp Suite, Software Debugging, Linux, Dynamic Program Analysis, Mobile Application Software, Python (Programming Language), Open Web Application Security, Systems Integration, Web Applications, Software Security, Gitlab-ci, Graphql, Devsecops, Docker, Jenkins, Dynamic Application Security Testing - **Published:** September 29, 2026 - **Apply:** https://www.dice.com/job-detail/79d03896-43de-413a-bf4b-bbeb5ddbf629 ## About the Role * Bachelor's degree or one or more years of work experience., * 2+ years of hands-on experience in Application Security, Penetration Testing, or a DevSecOps engineering role. * Deep understanding of web application architecture, APIs (REST/GraphQL), and mobile application security. * Comprehensive knowledge of the OWASP Top 10, CWEs, CVSS scoring, and how to manually validate and exploit these vulnerabilities. * Proficiency operating and configuring industry-standard dynamic analysis tools, specifically Burp Suite Professional and OWASP ZAP. * Proven experience integrating security tools into modern CI/CD pipelines using Jenkins and GitLab CI. * Strong ability to read, write, and maintain automation scripts in Python and Bash. * Hands-on experience working with Docker containers and deploying/managing applications in AWS (experience with EC2s/Linux is a plus). * Ability to clearly explain complex security vulnerabilities (and why remediating them is important) to software engineers who may not have a security background. * Experience using AI assistants (ideally Gemini or Claude Code) for scripting, debugging code, or day to day productivity improvements. ## Description Our Dynamic Application Security Testing (DAST) team is a group of talented, creative thinkers who 'act like the enemy.' We focus on ensuring our web applications, mobile applications, and APIs are secure by performing ethical hacking and penetration testing on Verizon's internal and external defenses. In this role, you will operate at the intersection of cybersecurity and automation. You won't just find vulnerabilities; you will build, maintain, and support the suite of tools and automated processes that empower our application teams to independently scan for, identify, and remediate OWASP Top 10 vulnerabilities. Additionally, you will leverage your offensive security skills to support Verizon's critical incident response and bug bounty programs. Responsibilities include: * Integrating dynamic analysis tools (OWASP ZAP, Burp Suite) directly into Jenkins and GitLab CI/CD pipelines to ensure continuous security testing. * Writing and maintaining custom automation scripts using Python, Java, and Bash to scale our security efforts and eliminate manual bottlenecks. * Utilizing AI to build new testing capabilities, streamline the triage of bug bounty submissions, and troubleshoot code across our tech stack. * Deploying, hosting, and maintaining containerized security testing environments using Docker and AWS. * Partnering with engineering teams to guide them through identifying and remediating OWASP Top 10 vulnerabilities. * Leveraging your offensive expertise to triage incoming bug bounty submissions and support Verizon's critical incident response efforts. * Performing ethical hacking and penetration testing against web applications, mobile apps, and APIs to uncover vulnerabilities before malicious actors do. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [GitLab CI pipelines for a whole company](https://www.wearedevelopers.com/videos/143-gitlab-ci-pipelines-for-a-whole-company) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)