Application Security Engineer

IPolarity LLC

Whippany (NJ)

On-site

USD 146,136,000 - 197,713,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

IPolarity LLC is seeking an experienced Application Security Engineer to embed security testing across CI/CD for web, mobile, and API-based applications. You will drive risk reduction through automated gates (SAST/DAST/IAST/SCA) and hands-on security validation in fast-paced engineering teams.

The role requires strong DevSecOps expertise, cloud experience, and the ability to partner with developers to improve secure coding practices while maintaining velocity.

Qualifications

  • 8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
  • Experience securing large-scale enterprise apps across cloud and hybrid environments.
  • Certifications preferred: CISSP, CSSLP, GWAPT, OSCP, CEH, Azure/AWS Security Certifications.

Responsibilities

  • Design and implement enterprise-wide Application Security programs for web, mobile, and API-based apps.
  • Embed security into Agile, DevOps, and CI/CD pipelines with automated gates.
  • Conduct manual pentesting and business-logic testing to find issues beyond automated scans.
  • Perform threat modeling, attack-path analysis, and architecture reviews.
  • Validate remediation effectiveness and secure deployment practices.
  • Collaborate with engineering to shift-left security and promote secure coding.

Skills

Application Security
Secure SDLC / DevSecOps
SAST
DAST
IAST
SCA
Web Security
Mobile Security
API Security
Threat Modelling
Vulnerability Management
Secure Code Review
CI/CD Security

Tools

GitHub Actions
Azure DevOps
Jenkins
GitLab
Terraform
CloudFormation

Job description

Application Security (AppSec) Engineer $60/hr W2 Onsite - Maryland Heights, MO

Cog Kit BGV must be cleared to start

What are the top 3 skills required for this role?
  • Application Security (AppSec)
  • Secure SDLC / DevSecOps
  • SAST, DAST, IAST, SCA
  • Web, Mobile & API Security Testing
  • Manual Penetration Testing & Business Logic Testing
  • Threat Modelling
  • Vulnerability Management
  • Secure Code Review
  • CI/CD Security Integration
Job Description/ Responsibilities

The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity. The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle.

Key Responsibilities
Application Security Engineering
  • Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
  • Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
  • Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
  • Enable continuous post-deployment security validation and risk monitoring.
Security Testing & Validation
  • Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
  • Perform authenticated and unauthenticated security assessments of applications and APIs.
  • Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
  • Validate remediation effectiveness and secure deployment practices.
DevSecOps Integration
  • Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
  • Automate vulnerability triage, prioritization, and remediation workflows.
  • Develop security-as-code controls and policy enforcement mechanisms.
  • Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
Vulnerability Management
  • Analyze findings from multiple security tools and eliminate false positives.
  • Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
  • Track remediation efforts through SDLC and release cycles.
  • Develop security metrics, dashboards, and executive reporting.
Developer Enablement
  • Conduct secure coding reviews and developer education sessions.
  • Establish security champions programs across engineering teams.
  • Provide remediation guidance and hands-on support during application releases.
  • Drive adoption of secure development standards and best practices.
Cloud & API Security
  • Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
  • Secure REST, GraphQL, and microservice-based APIs.
  • Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
  • Support software supply chain security initiatives, including SBOM/SCA validation.
Qualifications
  • 8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
  • Experience securing large-scale enterprise applications across cloud and hybrid environments.
  • Relevant certifications preferred:
    • CISSP
    • CSSLP
    • GWAPT
    • OSCP
    • CEH
    • Azure/AWS Security Certifications
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • United States

Remote
USD 83,000 - 152,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

WorkForce Unlimited • Salem (VA)

On-site
USD 110,000 - 150,000
Senior Application Security Specialist
Senior Application Security Specialist

A-Line Staffing Solutions • Charlotte (NC)

Hybrid
USD 56,000 - 94,000
Application Security Engineer
Application Security Engineer

Talentify • Philadelphia

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
Senior Application Security Specialist
Senior Application Security Specialist

CLS Group • Woodbridge Township (NJ)

On-site
USD 140,000 - 180,000