Code Security Engineer

Coforge

Cincinnati (OH)

On-site

USD 110,000 - 160,000

Full time

38 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Coforge is seeking a Code Security Engineer to own SAST, SCA, and API security across the software development lifecycle. You will partner with engineering teams to integrate security tooling, automate workflows, and build dashboards for visibility and decisions.

Responsibilities include configuring platforms, supporting remediation efforts, and providing end-user guidance to reduce risk while improving security operations and developer enablement.

Qualifications

  • Experience with API security, SAST, SCA tooling and remediation workflows.
  • Ability to configure, monitor, and optimize security platforms and dashboards.
  • Strong understanding of SSDLC and secure development practices.

Responsibilities

  • Administer and support SAST, SCA, and API Security platforms.
  • Configure, maintain, and optimize security scanning and runtime monitoring capabilities.
  • Analyze security findings and assist development teams with remediation and risk reduction.
  • Provide end-user support and onboarding for security tools.
  • Monitor platform health, scan coverage, and performance metrics.
  • Design and develop integrations between security platforms and CI/CD pipelines.
  • Build automation to improve security workflows and reduce overhead.
  • Use IaC practices to deploy tooling and infrastructure.
  • Develop dashboards and reporting for security visibility.
  • Collaborate with development, DevOps, and security teams to integrate security into workflows.
  • Contribute to roadmaps and operational improvements.

Skills

API security
SAST
SCA
Troubleshooting
SSDLC
Communication
Automation

Tools

Terraform
CI/CD pipelines
AWS
Power BI

Job description

Mode of Hire: Full Time

JOB DESCRIPTION

The Code Security Engineer is responsible for the administration, operation, and continuous improvement of the organization's code security capabilities, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), and API Security platforms. This role supports security tooling operations, runtime monitoring, developer enablement, and end-user support while partnering with engineering teams to develop integrations, automation, reporting, and processes that improve security visibility and operational efficiency across the software development lifecycle.

Responsibilities
  • Administer and support SAST, SCA, and API Security platforms.
  • Configure, maintain, and optimize security scanning and runtime monitoring capabilities.
  • Analyze security findings and assist development teams with vulnerability remediation and risk reduction.
  • Provide end-user support, troubleshooting, and onboarding assistance for security tools and related processes.
  • Monitor platform health, scan coverage, performance metrics, and operational effectiveness.
  • Design and develop integrations between security platforms, CI/CD pipelines, reporting systems, and other enterprise tools.
  • Build automation and one-off solutions to improve security workflows and reduce operational overhead.
  • Utilize Infrastructure as Code (IaC) practices to deploy and manage tooling and supporting infrastructure.
  • Develop dashboards, metrics, and reporting to support security program visibility and decision-making.
  • Collaborate with development, DevOps, and security teams to integrate security into engineering workflows.
  • Contribute to security tooling roadmaps, enhancement efforts, and operational improvements.
Skills Required:
  • Experience with: API Security, Software Composition Analysis (SCA), Static Application Security Testing (SAST).
  • Experience providing end-user support and troubleshooting technical issues.
  • Experience with Terraform or similar Infrastructure as Code technologies.
  • Experience developing automation, integrations, or operational tooling.
  • Understanding of secure software development lifecycle (SSDLC) principles and application security practices.
  • Strong analytical, troubleshooting, and communication skills.
Preferred Skillset
  • Unit testing experience.
  • Experience writing one-off automation and data-processing scripts.
  • Amazon Web Services (AWS) experience.
  • Power BI experience.
  • Familiarity with CI/CD pipelines, API gateways, and DevOps practices.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
DevSecOps Engineer
DevSecOps Engineer

Intellect Solutions LLC • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 180,000
Sr Security Architect Vulnerability Management
Sr Security Architect Vulnerability Management

Francisco Partners • United States

On-site
USD 140,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Sr. IT Application Solutions Architect/ Sr DevSecOps Engineer
Sr. IT Application Solutions Architect/ Sr DevSecOps Engineer

Govserviceshub • Washington

On-site
USD 140,000 - 180,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
DevSecOps Engineer
DevSecOps Engineer

Yugal Tech Academy • United States

Remote
USD 100,000 - 130,000
Application Security Analyst
Application Security Analyst

IVID TEK INC • Plano (TX)

Hybrid
USD 130,000