Title: Application Security Engineer Location: Brooklyn Park, MN | Hybrid or Remote Job Type: Contract (12 months) Compensation: $67.00 - $112.00 per hour (W2) Industry: Retail
About the Role
Our firm is partnering with a leading Fortune 100 retailer and technology-driven organization to identify an experienced Application Security Engineer. This company operates at enterprise scale, delivering innovative digital products, cloud-based services, and emerging AI-enabled solutions that support millions of customers and team members. In this role, you will help strengthen the security posture of modern applications and platforms by collaborating with software engineering, cybersecurity, and AI-focused teams. The ideal candidate brings a strong foundation in application security, secure software development practices, vulnerability management, and automated security testing, along with a passion for emerging technologies and AI security.
Job Description
As an Application Security Engineer, you will support enterprise application and AI security initiatives by evaluating security risks, implementing security best practices, and partnering with development teams throughout the software development lifecycle.
Key Responsibilities
- Collaborate with engineering, cybersecurity, and AI teams to evaluate and implement application and AI security controls, tools, and processes.
- Perform security-focused code reviews across applications, APIs, automation workflows, and AI-enabled services.
- Analyze and validate findings from DAST, SAST, SCA, and other security assessment platforms.
- Assess vulnerability impact, identify false positives, prioritize remediation efforts, and provide actionable guidance to engineering teams.
- Support the integration of automated application security testing within CI/CD pipelines.
- Research emerging AI/LLM security risks, testing methodologies, and vulnerability discovery tools.
- Participate in threat modeling and security design reviews for applications, cloud services, and machine learning systems.
- Drive secure software development lifecycle (SSDLC) and DevSecOps best practices across engineering teams.
- Create and maintain security standards, documentation, and repeatable processes related to application security and vulnerability management.
- Evaluate and pilot new security technologies through proof-of-concept testing and assessments.
- Communicate security findings and recommendations to technical and non-technical stakeholders.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or equivalent practical experience.
- 4+ years of experience in Application Security, Product Security, Cybersecurity Engineering, Software Engineering, or a related security-focused role.
- Hands-on experience conducting security-focused code reviews and identifying common application vulnerabilities.
- Experience analyzing and validating findings from automated application security tools, including vulnerability impact assessment and false-positive analysis.
- Experience with Dynamic Application Security Testing (DAST) tools and application vulnerability assessment methodologies.
- Familiarity with CI/CD pipelines and integrating automated security testing into the software development lifecycle.
- Strong understanding of: OWASP Top 10 API security risks Secure coding principles Secure Software Development Lifecycle (SSDLC) practices Common application security vulnerabilities Ability to effectively communicate security risks, findings, and remediation recommendations to engineering teams.
Required Technical Skills
- Application Security Testing
- Dynamic Application Security Testing (DAST)
- Vulnerability Assessment & Validation
- Secure Code Review
- CI/CD Security Integration
- Secure SDLC Practices
- OWASP Top 10 API Security
- DevSecOps Fundamentals
- Security Risk Analysis
- Vulnerability Management
Preferred Qualifications
- Experience working within enterprise-scale DevSecOps environments.
- Familiarity with AI security frameworks, AI/LLM security concepts, adversarial testing, or AI vulnerability discovery tools.
- Experience securing AI-enabled applications and assessing emerging AI security risks.
- Knowledge of cloud security practices across AWS, Azure, or Google Cloud Platform (GCP).
- Experience with:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Runtime Application Security tools
- Experience securing cloud-native, containerized, or Kubernetes-based applications.
- Industry certifications such as:
- CISSP
- CSSLP
- OSCP
- GSEC
- GIAC
- Application Security Certifications
- Preferred Technical Skills
- AI/LLM Security
- SAST
- Software Composition Analysis (SCA)
- Cloud Security (AWS, Azure, GCP)
- Kubernetes Security
- Container Security
- Threat Modeling
- Runtime Application Security
- Security Architecture Review
- Enterprise DevSecOps
Benefits
Dahl Consulting is proud to offer a comprehensive benefits package to eligible employees that will allow you to choose the best coverage to meet your family’s needs. For details, please review the DAHL Benefits Summary: https://www.dahlconsulting.com/benefits-w2fta/.
Equal Opportunity Statement
As an equal opportunity employer, Dahl Consulting welcomes candidates of all backgrounds and experiences to apply. If this position sounds like the right opportunity for you, we encourage you to take the next step and connect with us. We look forward to meeting you! #LI-LS1 #LI-Onsite