Application Security Engineer

Talentify

Arlington (VA)

Hybrid

USD 120,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Talentify is seeking a Senior Security Engineer to collaborate with engineers to implement security policies in CI/CD tooling (SAST, DAST, SCA) and guide secure coding across web and mobile apps.

You will align DevOps and Security to automate security capabilities, define code-level rules, and provide ongoing security guidance to development teams, fostering a mature secure SDLC.

Qualifications

  • Bachelor's degree with minimum 8 years of work experience in the IT field.
  • 3+ years software development experience using Java, JavaScript.
  • 3+ years of experience in OWASP Secure Coding Practices, common web vulnerabilities, and application security scanning tools.

Responsibilities

  • Collaborate with engineers to implement security policies in CI/CD tools (SAST, DAST, SCA).
  • Work with DevOps and Security teams to automate security and compliance in DevOps processes.
  • Define security rules for code in web/mobile apps (Java, React, Objective C, SWIFT, Kotlin).
  • Provide security guidance to developers via secure coding standards.

Skills

Java
JavaScript
Python
CI/CD
OWASP
Application security

Education

Bachelor's degree

Tools

Jenkins
Burp Suite
Fortify
Checkmarx
Veracode

Job description

What You'll Do:
  • Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications.
  • Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevOps processes.
  • Define the security rules that needs to be adhered to at a code level in web and mobile applications written in Java, React, Objective C, SWIFT, Kotlin etc.
  • With your development background and security knowledge, provide security guidance to developers in the form secure coding standards and guidelines.
  • Support security standards, create templates and patterns to increase the efficiency and adoption of security program.
These skills will help you succeed in this role:
  • Bachelor's degree with minimum 8 years of work experience in the IT field
  • 3+ years software development experience using Java, JavaScript
  • 3+ years of experience in the following:
    • OWASP Secure Coding Practices
    • Common software and web application security vulnerabilities
    • Application security scanning tools
    • Continuous Integration/Continuous Deployment (CI/CD) processes and concepts using relevant technologies and tools (e.g., Jenkins)
    • Experience in Python scripting
Even Better If You Have
  • A degree in Cybersecurity or CISSP/CSSLP certification or keen desire to move to security field
  • Business acumen to support the implementation of SAST or DAST or IAST across the enterprise
  • Ability to perform code reviews with minimal assistance
  • A self-starter, with a strong desire for learning new technologies and applying them to solve problems
  • Experience with two or more of the application build environments like Jenkins, Gradle, Maven.
  • Familiarity with public cloud services a plus
  • Experience with two or more of the Secure SDLC tools like Burp Suite, Fortify, Checkmarx, AppSec SE, Veracode, WhiteSource, Sonatype
  • Experience with Threat Analysis.
  • Experience with DevSecOps, Secure SDLC.
  • DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc) is a plus
  • Experience with evaluation, integration and onboard of security tools such as RASP, WAF, vulnerability scanner results, container analyzers, open source scanning etc is a plus
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security
Application Security

Smart IT Frame LLC • Berkeley Heights (NJ)

On-site
USD 110,000 - 160,000
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • United States

Remote
USD 83,000 - 152,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

Infosys • Richardson (TX)

On-site
USD 110,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

SentinelOne, Inc. • United States

Remote
USD 140,000 - 230,000
Medical, dental, and vision coverage
Unlimited Time Off
Paid Holidays
+2
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Application Security Engineer
Application Security Engineer

Placements24 • United States

Remote
USD 90,000 - 130,000
Flexible remote work
Professional development opportunities
Security-focused culture
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Senior Application Security Analyst
Senior Application Security Analyst

O2 Technologies,Inc • New York (NY)

On-site
USD 120,000 - 180,000