Application Security (AppSec) Engineer - W2 Only

Saransh Inc

Maryland Heights (MO)

On-site

USD 110,000 - 160,000

Full time

14 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Saransh Inc. in Maryland Heights, MO is seeking an Application Security Engineer to embed security testing, vulnerability management, and business logic validation into CI/CD pipelines and post-deployment processes while maintaining engineering velocity.

The ideal candidate combines expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual testing to improve application security posture across web, mobile, and microservices architectures.

Qualifications

  • 8-15 years of experience in Application Security, DevSecOps, or Security Architecture.
  • Experience securing large-scale enterprise applications across cloud and hybrid environments.
  • Knowledge of secure SDLC, automated security testing, and threat modeling.
  • Certifications such as CISSP, CSSLP, GWAPT, OSCP, CEH, or cloud security certs preferred.

Responsibilities

  • Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
  • Integrate security controls and testing into Agile, DevOps, and CI/CD pipelines.
  • Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
  • Enable continuous post-deployment security validation and risk monitoring.
  • Automate vulnerability triage, prioritization, and remediation workflows.
  • Develop security-as-code controls and policy enforcement mechanisms.
  • Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
  • Provide remediation guidance during application releases.
  • Drive adoption of secure development standards and best practices.
  • Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes.
  • Secure REST, GraphQL, and microservice-based APIs.
  • Evaluate infrastructure-as-code and container security controls.
  • Support software supply chain security initiatives, including SBOM/SCA validation.

Skills

AppSec
DevSecOps
SAST/DAST/IAST/SCA
Web/Mobile/API Security
Penetration Testing
Threat Modeling
Vulnerability Management
Secure Code Review
CI/CD Security
Cloud & API Security

Tools

Microsoft Threat Modeler
Backtrack Penetration Testing

Job description

Role: Application Security (AppSec) Engineer
Location: Maryland Heights, MO
W2 Position
Name

CxSAST

Application Security

Security in SDLC

Microsoft Threat Modeler

Backtrack Penetration Testing

What are the top 3 skills required for this role?

Application Security (AppSec)

Secure SDLC / DevSecOps

SAST, DAST, IAST, SCA

Web, Mobile & API Security Testing

Manual Penetration Testing & Business Logic Testing

Threat Modelling

Vulnerability Management

Secure Code Review

CI/CD Security Integration

Job Description/ Responsibilities

The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity.

The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle.

________________________________________

Key Responsibilities

Application Security Engineering

Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.

Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.

Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.

Enable continuous post-deployment security validation and risk monitoring.

Security Testing & Validation

Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.

Perform authenticated and unauthenticated security assessments of applications and APIs.

Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.

Validate remediation effectiveness and secure deployment practices.

DevSecOps Integration

Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.

Automate vulnerability triage, prioritization, and remediation workflows.

Develop security-as-code controls and policy enforcement mechanisms.

Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.

Vulnerability Management

Analyze findings from multiple security tools and eliminate false positives.

Prioritize vulnerabilities based on business risk, exploitability, and application criticality.

Track remediation efforts through SDLC and release cycles.

Develop security metrics, dashboards, and executive reporting.

Developer Enablement

Conduct secure coding reviews and developer education sessions.

Establish security champions programs across engineering teams.

Provide remediation guidance and hands-on support during application releases.

Drive adoption of secure development standards and best practices.

Cloud & API Security

Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.

Secure REST, GraphQL, and microservice-based APIs.

Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.

Support software supply chain security initiatives, including SBOM/SCA validation.

8 15 years of experience in Application Security, DevSecOps, or Security Architecture.

Experience securing large-scale enterprise applications across cloud and hybrid environments.

Relevant Certifications Preferred
  • CISSP
  • CSSLP
  • GWAPT
  • OSCP
  • CEH
  • Azure/AWS Security Certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Engineer ( Only USC Or GC)
Application Security Engineer ( Only USC Or GC)

LinQ Global Group • Philadelphia

Hybrid
USD 110,000 - 160,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

WorkForce Unlimited • Salem (VA)

Hybrid
USD 110,000 - 150,000
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

Accylerate • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Security Engineer – SAST & SCA (Application Security)
Security Engineer – SAST & SCA (Application Security)

US staffing Inc • San Jose (CA)

On-site
USD 150,000 - 210,000