IT Security Auditor Full Stack Application Security
Location: Dimondale, MI
Job Description
We are seeking a Senior Full Stack Application Security Auditor to help strengthen secure software development practices across applications and platforms.
This position is focused on Application Security, Secure Coding, DevSecOps, Security Assessments, and vulnerability management. The selected candidate will work closely with front-end, back-end, cloud, and development teams to identify security risks, implement security patterns, improve secure coding practices, and support continuous compliance and risk mitigation.
This is not a Security Operations Center (SOC) position.
Key Responsibilities
- Perform and support application security assessments using SAST, DAST, SCA, ASOC, Container, and Cloud security tools.
- Partner with software development teams to implement secure coding practices.
- Identify and assess application vulnerabilities and security risks.
- Help implement security patterns, practices, automation, and orchestration.
- Support secure configuration, verification, compliance, and authorization processes.
- Review web applications and APIs for security vulnerabilities.
- Analyze HTTP request/response headers using Chrome, Firefox, or Edge Developer Tools.
- Assess RESTful APIs and web application security.
- Explain and remediate OWASP Top 10 vulnerabilities.
- Work with development teams across front-end, back-end, and cloud environments.
- Support DevSecOps and security automation initiatives.
- Contribute to the maturity of secure software development practices.
- Help ensure continuous compliance and risk mitigation across application environments.
Required Skills
- 5+ years of total IT experience
- 3+ years of experience implementing/utilizing security guidance and secure coding practices
- Strong knowledge of:
- OWASP Top 10
- SANS
- CERT
- CWE Top 25
- Critical Security Controls
- Cloud Security Alliance
- SafeCode
- Hands-on experience with SAST, DAST, SCA, ASOC, Container/Cloud security scanning
- Strong understanding of:
- Cross-Site Scripting (XSS)
- Injection attacks
- SSRF
- CSRF
- XML External Entity (XXE)
- API Security
- Experience with:
- JWT
- OAuth
- OIDC
- PKCE
- Web/API replay attacks
- Knowledge of HTTP request/response headers and RESTful APIs.
- Experience with DevSecOps, security automation, networking, infrastructure, and secure application development.
- 3+ years of experience with compiled and interpreted languages/technology stacks such as:
- Angular
- React
- Node.js
- Java
- Spring Boot
- IBM WebSphere
- Oracle JBoss
- .NET
- 3+ years of hands-on experience building and deploying secure complex web and/or mobile applications.
- Cloud development experience with AWS, Azure, or GCP.
- High-level understanding of container technologies.
Preferred Skills
Experience with:
- Coverity
- Black Duck
- SRM
- Fortify
- Container Security
- Cloud Security
- Security Automation
- Secure Software Development Lifecycle
- Application Security Architecture
Candidate Requirements
- Must be located within 90 100 miles of Dimondale, MI at the time of submission.
- Must be willing to work hybrid, onsite 2 days per week.
- Wednesday and Thursday are mandatory onsite days.
- Must be available for an in-person second-round interview in Dimondale, MI.
- Must be able to pass a CJIS background check.
- Strong LinkedIn profile required.
- No remote-only option.
Ideal Candidate
The ideal candidate will have a strong Application Security / Product Security / DevSecOps background combined with software development knowledge. Candidates who have hands-on experience with application security scanning, OWASP vulnerabilities, API security, cloud security, secure coding, and security automation are strongly encouraged to apply.