IT Security Auditor

Talent Portus

Michigan

Hybrid

USD 110,000 - 160,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Talent Portus is seeking a Senior Full Stack Application Security Auditor to strengthen secure software development across applications and platforms. The role focuses on Application Security, Secure Coding, DevSecOps, security assessments, and vulnerability management, collaborating with front-end, back-end, cloud, and development teams.

The candidate will perform security assessments, remediate OWASP Top 10 vulnerabilities, and help advance secure patterns and automation across environments in

Qualifications

  • 5+ years of total IT experience.
  • 3+ years implementing security guidance and secure coding practices.
  • Strong knowledge of OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode.
  • Hands-on experience with SAST, DAST, SCA, ASOC, Container/Cloud security scanning.
  • Knowledge of HTTP headers and RESTful APIs; experience with JWT, OAuth, OIDC, PKCE.

Responsibilities

  • Perform and support application security assessments using SAST, DAST, SCA, ASOC, Container, and Cloud security tools.
  • Partner with software development teams to implement secure coding practices.
  • Identify and assess application vulnerabilities and security risks.
  • Help implement security patterns, practices, automation, and orchestration.
  • Support secure configuration, verification, compliance, and authorization processes.
  • Review web applications and APIs for security vulnerabilities.
  • Explain and remediate OWASP Top 10 vulnerabilities.
  • Work with development teams across front-end, back-end, and cloud environments.
  • Support DevSecOps and security automation initiatives.
  • Contribute to the maturity of secure software development practices.

Skills

IT security experience
OWASP Top 10
SAST/DAST/SCA
Cloud security
Secure coding practices
DevSecOps
RESTful APIs
AWS/Azure/GCP
Team collaboration

Tools

Coverity
Fortify
Black Duck

Job description

IT Security Auditor Full Stack Application Security

Location: Dimondale, MI

Job Description

We are seeking a Senior Full Stack Application Security Auditor to help strengthen secure software development practices across applications and platforms.

This position is focused on Application Security, Secure Coding, DevSecOps, Security Assessments, and vulnerability management. The selected candidate will work closely with front-end, back-end, cloud, and development teams to identify security risks, implement security patterns, improve secure coding practices, and support continuous compliance and risk mitigation.

This is not a Security Operations Center (SOC) position.

Key Responsibilities
  • Perform and support application security assessments using SAST, DAST, SCA, ASOC, Container, and Cloud security tools.
  • Partner with software development teams to implement secure coding practices.
  • Identify and assess application vulnerabilities and security risks.
  • Help implement security patterns, practices, automation, and orchestration.
  • Support secure configuration, verification, compliance, and authorization processes.
  • Review web applications and APIs for security vulnerabilities.
  • Analyze HTTP request/response headers using Chrome, Firefox, or Edge Developer Tools.
  • Assess RESTful APIs and web application security.
  • Explain and remediate OWASP Top 10 vulnerabilities.
  • Work with development teams across front-end, back-end, and cloud environments.
  • Support DevSecOps and security automation initiatives.
  • Contribute to the maturity of secure software development practices.
  • Help ensure continuous compliance and risk mitigation across application environments.
Required Skills
  • 5+ years of total IT experience
  • 3+ years of experience implementing/utilizing security guidance and secure coding practices
  • Strong knowledge of:
    • OWASP Top 10
    • SANS
    • CERT
    • CWE Top 25
    • Critical Security Controls
    • Cloud Security Alliance
    • SafeCode
  • Hands-on experience with SAST, DAST, SCA, ASOC, Container/Cloud security scanning
  • Strong understanding of:
    • Cross-Site Scripting (XSS)
    • Injection attacks
    • SSRF
    • CSRF
    • XML External Entity (XXE)
    • API Security
  • Experience with:
    • JWT
    • OAuth
    • OIDC
    • PKCE
    • Web/API replay attacks
  • Knowledge of HTTP request/response headers and RESTful APIs.
  • Experience with DevSecOps, security automation, networking, infrastructure, and secure application development.
  • 3+ years of experience with compiled and interpreted languages/technology stacks such as:
    • Angular
    • React
    • Node.js
    • Java
    • Spring Boot
    • IBM WebSphere
    • Oracle JBoss
    • .NET
  • 3+ years of hands-on experience building and deploying secure complex web and/or mobile applications.
  • Cloud development experience with AWS, Azure, or GCP.
  • High-level understanding of container technologies.
Preferred Skills

Experience with:

  • Coverity
  • Black Duck
  • SRM
  • Fortify
  • Container Security
  • Cloud Security
  • Security Automation
  • Secure Software Development Lifecycle
  • Application Security Architecture
Candidate Requirements
  • Must be located within 90 100 miles of Dimondale, MI at the time of submission.
  • Must be willing to work hybrid, onsite 2 days per week.
  • Wednesday and Thursday are mandatory onsite days.
  • Must be available for an in-person second-round interview in Dimondale, MI.
  • Must be able to pass a CJIS background check.
  • Strong LinkedIn profile required.
  • No remote-only option.
Ideal Candidate

The ideal candidate will have a strong Application Security / Product Security / DevSecOps background combined with software development knowledge. Candidates who have hands-on experience with application security scanning, OWASP vulnerabilities, API security, cloud security, secure coding, and security automation are strongly encouraged to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Auditor
IT Security Auditor

Shree Narayani Networking Solutions Pvt Ltd • Dimondale (MI)

Hybrid
USD 90,000 - 120,000
ITSecurityAuditor
ITSecurityAuditor

JPC TECHNO INC • Dimondale (MI)

On-site
USD 90,000 - 140,000
IT Security Auditor
IT Security Auditor

Accord Technologies Inc. • Dimondale (MI)

On-site
USD 90,000 - 130,000
IT Security Auditor
IT Security Auditor

UniQtal Solutions LLC • Dimondale (MI)

On-site
USD 110,000 - 160,000
Application Development Security Auditor - Dimondale, MI
Application Development Security Auditor - Dimondale, MI

Digital Technology International • Dimondale (MI)

On-site
USD 120,000 - 150,000
Competitive salary
IT Security Auditor
IT Security Auditor

Jobtailor • Missouri

On-site
USD 120,000 - 180,000
Senior Application Security & DevSecOps Auditor
Senior Application Security & DevSecOps Auditor

Digital Technology International • Dimondale (MI)

On-site
USD 120,000 - 150,000
Competitive salary
IT Security Auditor
IT Security Auditor

TekWissen LLC • Dimondale (MI)

Hybrid
USD 95,000 - 130,000
IT Security Auditor
IT Security Auditor

vTech Solution • Michigan

Hybrid
USD 90,000 - 130,000
Senior Application Security Engineer
Senior Application Security Engineer

Quantam Solutions • Town of Lansing (NY)

Hybrid
USD 120,000 - 160,000
Health benefits
Paid time off
401(k) plan
+1