Application Security (AppSec) / DevSecOps Engineer

Zoho

United States

Remote

USD 83,000 - 152,000

Part time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fyerx is seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls into our automated software delivery frameworks.

The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

Qualifications

  • 4 to 8 years of core software engineering or cloud DevOps experience.
  • 3+ dedicated years actively designing, building and deploying application safety frameworks.
  • Strong mastery of automated testing engines and container security paradigms.

Responsibilities

  • Configure and manage application scanning frameworks (SAST/DAST/SCA).
  • Triage and remediate software vulnerabilities with dev teams.
  • Lead comprehensive threat modeling assessments for new apps and features.
  • Secure containerized workloads with Docker/Kubernetes checks.
  • Drive application security investigations and improve perimeters.

Skills

SAST tooling
DAST tooling
SCA tooling
OWASP Top 10
Container security
IaC hardening

Tools

Snyk
Checkmarx
Veracode
OWASP ZAP

Job description

Application Security (AppSec) / DevSecOps Engineer

Application Security (AppSec) / DevSecOps Engineer

  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
  • Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH
Job Summary

We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

  • Configure and manage application scanning frameworks, orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
  • Triage and remediate software vulnerabilities, analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
  • Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
  • Secure containerized application workloads, auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
  • Drive application layer incident investigations, analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.
Requirements
  • 4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
  • Strong technical mastery of automated testing engines (e.g., Snyk , Checkmarx , Veracode, OWASP ZAP ), container security paradigms, and infrastructure-as-code hardening.
  • Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
  • Mandatory certification: CASE, CDP, CSSLP, or CEH.
Preferred Qualifications
  • Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security
Application Security

Smart IT Frame LLC • Berkeley Heights (NJ)

On-site
USD 110,000 - 160,000
DevSecOps Lead Engineer
DevSecOps Lead Engineer

People Consultancy Services (PCS) • United States

On-site
USD 150,000 - 210,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
DevSecOps Lead
DevSecOps Lead

UniQtal Solutions LLC • New York (NY)

Remote
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

Talentify • Philadelphia

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Talentify • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000