Application Security Analyst

Stellantis

Auburn Hills (MI)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Stellantis in Auburn Hills, MI seeks an on-site Application Security Engineer to harden software across the SDLC. You will run SAST/DAST/IAST, lead remediation efforts, and collaborate with DevOps and development teams to embed secure coding practices.

You will deploy and optimize WAF policies, participate in threat modeling, and train teams on secure development and testing techniques, with a strong focus on cross-functional enablement.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or related field.
  • 3+ years of hands-on experience in application security, security testing, and DevSecOps.
  • Strong understanding of web/mobile APIs, SDLC, and modern languages (Java, C#, Python).
  • Experience with SAST, DAST, IAST, SCA, and mobile security testing tools.
  • Secure code review in Java/C#/Python and development background (web/mobile).
  • Familiarity with OWASP Top 10 and security frameworks (NIST, ISO 27001, NIST SSDF).
  • WAF technologies (Akamai, Cloudflare, AWS WAF, Azure Front Door).
  • Cloud platforms (AWS, Azure, GCP) and containers (Docker, Kubernetes).
  • Programming/scripting knowledge: Java, JavaScript, SQL, HTML; Python, Bash preferred.

Responsibilities

  • Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing
  • Analyze vulnerabilities and recommend secure coding fixes
  • Demonstrate vulnerabilities to development teams
  • Drive remediation efforts to closure
  • Lead WAF deployment and security policy enforcement
  • Integrate security controls into CI/CD pipelines
  • Collaborate with development, platform, and supplier teams to enable secure coding
  • Develop training materials and provide remediation guidance
  • Conduct security assessments and track risks, milestones, deliverables, and status updates

Skills

Application security
DevSecOps
Security testing
Threat modeling
Communication

Education

Bachelor's degree in CS/IT or related field

Tools

Jenkins
GitHub Actions
Checkmarx
Burp Suite
GitHub Advanced Security

Job description

This role focuses on identifying, analyzing, and mitigating application security vulnerabilities throughout the SDLC. It supports a broader "Shift Left" cybersecurity strategy, ensuring security is integrated early in development and reinforced through DevSecOps practices.

Key Responsibilities:
Application Security & Testing
  • Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing
  • Analyze vulnerabilities and recommend secure coding fixes
  • Demonstrate vulnerabilities to development teams
  • Drive remediation efforts to closure
DevSecOps & Tooling
  • Work within CI/CD pipelines using tools such as:
    • Jenkins, GitLab, GitHub Actions, TeamCity
    • Checkmarx, GitHub Advanced Security, Burp Suite
  • Integrate security controls into development workflows
WAF & Security Controls
  • Lead Web Application Firewall (WAF) deployment for new and existing apps
  • Implement application security policies, controls, and standards
Collaboration & Enablement
  • Partner with development, platform, and supplier teams
  • Provide clear remediation guidance
  • Train teams on secure coding and application security practices
  • Develop training materials
Assessment & Reporting
  • Conduct security assessments using standard tools
  • Track and report:
    • Risks
    • Milestones
    • Deliverables
    • Status updates
  • Recommend strategies based on application risk posture

This role is based in Auburn Hills, MI and is required to be on-site in our HQ building 5 days per week.

Basic Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, or related field
  • 3+ years of hands‑on experience in application security, security testing, and DevSecOps
  • Strong understanding of:
    • Application architectures (web, mobile, APIs)
    • Software development methodologies (Agile, SDLC)
    • Modern programming languages (Java, C#, Python)
  • Experience performing and interpreting results from:
    • SAST, DAST, IAST, SCA, and mobile security testing tools
  • Hands‑on experience with secure code review in common languages (Java, C#, Python preferred)
  • Prior background in application development, including:
    • Compiled code
    • Web applications / services
    • Mobile app development
  • Knowledge of security frameworks and standards:
    • NIST, ISO 27001
    • NIST SSDF or similar secure development frameworks
  • Strong understanding of:
    • OWASP Top 10 vulnerabilities and mitigation techniques
    • Common attack vectors (web exploits, DDoS, bot attacks)
  • Experience with WAF technologies:
    • Akamai, Cloudflare, AWS WAF, Azure Front Door
  • Familiarity with cloud platforms and modern environments:
    • AWS, Azure, GCP
    • Containers (Docker, Kubernetes)
  • Working knowledge of:
    • Programming/scripting: Java, JavaScript, SQL, HTML
    • Scripting languages (Python, Bash preferred)
  • Strong analytical, problem‑solving, and communication skills
    • Ability to explain technical risks to non-technical audiences
    • Experience writing security reports and documentation
  • Ability to work independently and cross‑functionally
Preferred Qualifications:
  • Industry certifications:
    • GIAC GWEB
    • ISC2 CSSLP
    • EC-Council CASE
    • Or equivalent AppSec certifications

At Stellantis, we assess candidates based on qualifications, merit, and business needs. We welcome applications from all people without regard to sex, age, ethnicity, nationality, religion, sexual orientation, disability, or any characteristic protected by law. We believe that diverse teams reflect our identity as a global company, enabling us to better address the evolving needs of our customers and care for our future.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Application Security Analyst - DevSecOps & WAF Champion
Application Security Analyst - DevSecOps & WAF Champion

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Application Security Analyst
Application Security Analyst

Myconsumers • Lake Forest (IL)

Hybrid
USD 67,000 - 109,000
Medical insurance
Dental insurance
Vision insurance
+2
AppSec & DevSecOps Specialist
AppSec & DevSecOps Specialist

Stellantis • Auburn Hills (MI)

On-site
USD 110,000 - 140,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

Hybrid
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Cybersecurity Engineer IV – Application Security
Cybersecurity Engineer IV – Application Security

Jobtailor • Illinois

On-site
USD 140,000 - 180,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security (AppSec) Engineer/Architect
Application Security (AppSec) Engineer/Architect

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000