Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
WorkForce Unlimited is seeking an experienced Application Security Engineer to strengthen our client’s security posture in Azure development environments. You will partner with development and IT teams to embed security into software life cycles, pipelines, and releases, while coordinating assessments and remediation efforts.
This role supports a hybrid model with 2 days onsite in Salem, VA. The ideal candidate has 7+ years in application security or related fields, a Bachelor’s degree, and
Our client is seeking an experienced Application Security Engineer to support ongoing application security and technology initiatives. This is a long term contract opportunity with potential eligibility for future conversion.
Secure Microsoft Azure development environments, including projects, resource groups, hosting, identity and access, pipelines, configurations, and security controls.
Partner with development and IT teams to integrate application security into software development, build, deployment, and release processes.
Support DevSecOps processes and help ensure development teams follow required application security standards and procedures.
Coordinate application security assessments and testing, including SAST, DAST, software composition analysis, and penetration testing, often with third party partners.
Identify, prioritize, track, remediate, and validate application vulnerabilities, security weaknesses, and process gaps.
Evaluate third party applications, software components, open source dependencies, and AI integrations for security risk.
Maintain assessment records, remediation status, exceptions, and supporting documentation for governance, audit, and continuous improvement.
7 years of experience in application security, cybersecurity, software development, or a related discipline.
Bachelor’s degree in a related technical field, or equivalent education and work experience.
Experience with Microsoft Azure development environments and application security controls.
Strong understanding of the software development lifecycle and DevSecOps. Coding is not required, but you must understand how applications are developed, built, and deployed.
Experience with application security testing, vulnerability assessment, penetration testing, or security remediation.
Ability to work effectively with development teams, application owners, security partners, suppliers, and third party providers.
Knowledge of application security frameworks and standards such as NIST SP 800 171, CRA, or SOC 2 is preferred.