We are looking for an Application Security Engineer to work for our client. The ideal candidate aligns with the responsibilities and qualifications outlined below.
This is a strong opportunity for a security engineer who enjoys working shoulder to shoulder with developers, helping teams ship safer software without slowing them down, in a remote role open to candidates located in Ohio.
Responsibilities
- Secure web applications, APIs, and mobile applications at every stage of the software development lifecycle
- Run static and dynamic application security testing (SAST/DAST), then help development teams triage and remediate what turns up
- Apply knowledge of OWASP Top 10, CWE, and common vulnerability patterns to guide secure design and coding decisions
- Strengthen the security of applications hosted in Microsoft Azure and similar enterprise cloud environments
- Build automated security testing and controls into CI/CD pipelines as part of a DevSecOps approach
- Advise engineering teams on secure architecture, vulnerability fixes, and application security best practices
- Track emerging threats and tooling, bringing practical improvements back to the team
- Contribute to the growth and maturity of the organization's application security program
Qualifications
- Hands-on experience securing web applications, APIs, and/or mobile applications across the SDLC
- Experience with SAST and DAST tools and a history of helping developers resolve findings
- Strong working knowledge of OWASP Top 10, CWE, and secure coding practices
- Experience securing applications in Microsoft Azure or comparable enterprise cloud platforms
- Experience embedding security testing and controls into CI/CD pipelines
- Collaborative communication style, with the ability to partner directly with software engineers
- Must be located in Ohio
What Our Client Offers
- Remote work for Ohio-based candidates, with no daily commute
- A genuine partnership with engineering, where security input is sought early rather than at the end
- Azure-centered work that goes beyond scanning reports into real design conversations
- Room to influence how DevSecOps practices take shape as the program grows
- A culture that treats secure code as a shared goal, not a gatekeeping exercise