Cloud Application Software Security Engineer

Eliassen Group

St. Louis (MO)

Hybrid

Confidential

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401k with company matching
Life Insurance

Job summary

Eliassen Group in St. Louis, MO is seeking a Cloud Application Software Security Engineer to remediate vulnerabilities and mature SDLC pipelines. You will address KEVs, CVEs, and SBOM findings across custom code and IaC in AWS GovCloud, collaborating with development teams to reduce risk.

This hybrid role requires 3-5 years in application security or secure software development, with hands-on AWS security services experience, SAST/DAST, and secure coding practices. W2 benefits are provided.

Qualifications

  • 3 to 5 years in application security or software development with a security focus.
  • Proven experience with vulnerability assessment and remediation methodologies.
  • Proficiency with Python, SQL, and VB.NET or legacy .NET frameworks.
  • Experience with AWS CDK or similar IaC tools such as Terraform or CloudFormation.
  • Hands-on experience in AWS environments, preferably AWS GovCloud.
  • Experience with AWS security services such as GuardDuty, Security Hub, Inspector, and Config.
  • Understanding of CVE and KEV identification and remediation processes.
  • Knowledge of SBOM generation and analysis.
  • Experience with SAST, DAST, and penetration testing.
  • Strong analytical and problem-solving skills.
  • Strong written and verbal communication skills.
  • Preferred: Security certifications such as CISSP, CEH, GIAC GSEC, or AWS Security Specialty.
  • Knowledge of container security, CI/CD pipeline security, DevSecOps practices, SSDLC, and zero trust principles.

Responsibilities

  • Conduct security assessments using scanning tools and implement recommended remediations.
  • Evaluate and remediate Known Exploited Vulnerabilities (KEVs) and Common Vulnerabilities and Exposures (CVEs) in custom applications and infrastructure.
  • Support Security Assessment and Authorization (SA&A) processes, including documentation and evidence collection.
  • Analyze Software Bill of Materials (SBOM) findings to identify vulnerable dependencies and recommend updates or alternatives.
  • Review and remediate security vulnerabilities in VB.NET, SQL, and Python code.
  • Perform security analysis and hardening of AWS Cloud Development Kit (CDK) infrastructure as code.
  • Collaborate with development teams to implement secure coding practices and address identified vulnerabilities.
  • Maintain security documentation and track remediation efforts through completion.
  • Ensure compliance with federal security standards and frameworks such as NIST, FISMA, and FedRAMP within AWS GovCloud.
  • Participate in security scanning automation and continuous monitoring initiatives.

Skills

Security assessments
Vulnerability remediation
Python
SQL
VB.NET
AWS CDK
Terraform
CloudFormation
SAST
DAST
Penetration testing
SA&A
SBOM analysis
NIST

Education

Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field

Tools

AWS CDK
Terraform
CloudFormation
AWS GovCloud

Job description

Description

Hybrid 4 days on-site, 1 day work from home in St. Louis, MO

Our client seeks a Cloud Application Software Security Engineer to remediate vulnerabilities and mature SDLC pipelines. The role will focus on addressing findings from Mythos, CVE and Known Exploited Vulnerabilities, and open HVA and SA&A assessments. The engineer will collaborate with development and platform teams to reduce risk across custom application code and infrastructure as code in AWS.

Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $75.00 to $85.00/hr. w2


Responsibilities
  • Conduct security assessments using scanning tools and implement recommended remediations.
  • Evaluate and remediate Known Exploited Vulnerabilities (KEVs) and Common Vulnerabilities and Exposures (CVEs) in custom applications and infrastructure.
  • Support Security Assessment and Authorization (SA&A) processes, including documentation and evidence collection.
  • Analyze Software Bill of Materials (SBOM) findings to identify vulnerable dependencies and recommend updates or alternatives.
  • Review and remediate security vulnerabilities in VB.NET, SQL, and Python code.
  • Perform security analysis and hardening of AWS Cloud Development Kit (CDK) infrastructure as code.
  • Collaborate with development teams to implement secure coding practices and address identified vulnerabilities.
  • Maintain security documentation and track remediation efforts through completion.
  • Ensure compliance with federal security standards and frameworks such as NIST, FISMA, and FedRAMP within AWS GovCloud.
  • Participate in security scanning automation and continuous monitoring initiatives.

Experience Requirements
  • 3 to 5 years in application security or software development with a security focus.
  • Proven experience with vulnerability assessment and remediation methodologies.
  • Proficiency with Python, SQL, and VB.NET or legacy .NET frameworks.
  • Experience with AWS CDK or similar IaC tools such as Terraform or CloudFormation.
  • Hands-on experience in AWS environments, preferably AWS GovCloud.
  • Experience with AWS security services such as GuardDuty, Security Hub, Inspector, and Config.
  • Understanding of CVE and KEV identification and remediation processes.
  • Knowledge of SBOM generation and analysis.
  • Experience with SAST, DAST, and penetration testing.
  • Strong analytical and problem-solving skills.
  • Strong written and verbal communication skills.
  • Preferred: Security certifications such as CISSP, CEH, GIAC GSEC, or AWS Security Specialty. Knowledge of container security, CI/CD pipeline security, DevSecOps practices, SSDLC, and zero trust principles.

Education Requirements

Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field, or equivalent work experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Cloud App Security Engineer - AWS, SDLC Remediation
Hybrid Cloud App Security Engineer - AWS, SDLC Remediation

Eliassen Group • St. Louis (MO)

Hybrid
Confidential
Medical Insurance
Dental Insurance
Vision Insurance
+2
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Cloud Engineer
Cloud Engineer

Strategic Staffing Solutions • St. Louis (MO)

Hybrid
USD 120,000 - 160,000
Vulnerability Manager
Vulnerability Manager

Search Services • Houston (TX)

Hybrid
USD 110,000 - 170,000
Cloud Security Engineer
Cloud Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 170,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 145,000
Full Stack Application Security Auditor
Full Stack Application Security Auditor

IO Datasphere • Dimondale (MI)

Hybrid
USD 120,000 - 180,000
Application Security Engineer ( Only USC Or GC)
Application Security Engineer ( Only USC Or GC)

LinQ Global Group • Philadelphia

Hybrid
USD 110,000 - 160,000
Cloud Security Engineer
Cloud Security Engineer

US Corp2Corp • St. Louis (MO)

On-site
USD 110,000 - 150,000