Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.
Corps Team is seeking a Senior Application Security Engineer for a 6 month, fully onsite contract in Jacksonville, FL. The role focuses on designing, implementing, and optimizing static and dynamic application security testing across the software development lifecycle.
Responsibilities include configuring SAST/DAST/SCA platforms, managing SonarQube, and integrating security testing into CI/CD pipelines, with reporting for technical and executive stakeholders.
Our client, a diversified financial services company providing banking and investing services, is seeking a Senior Application Security Engineer for a 6 month contract role ocated in Jacksonville, FL. This role is fully onsite.
Own and optimize application security testing capabilities across the software development lifecycle, with emphasis on SAST, DAST, SCA, SonarQube, scanning configuration, vulnerability triage, and actionable reporting.
The Senior Application Security Engineer is responsible for designing, implementing, and optimizing application security capabilities across the software development lifecycle. Working under limited supervision, this individual contributor partners with development, DevOps, architecture, risk, and cybersecurity teams to integrate security testing into delivery processes, identify application vulnerabilities, and improve secure development practices. The role provides technical expertise for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secure code review, and code quality analysis. The engineer configures and tunes scanning technologies, validates findings, supports remediation, and develops meaningful reporting for technical and executive stakeholders.
Bachelor’s degree in Information Security, Computer Science, Software Engineering, or a related field preferred, or equivalent relevant experience. 5 or more years of cybersecurity, software engineering, DevSecOps, vulnerability management, or application security experience. 3 or more years of direct experience operating, administering, or integrating application security scanning technologies. Hands-on experience with SAST and DAST scanning configuration, execution, tuning, triage, and reporting. Working knowledge of SCA, secure code review, vulnerability management, and remediation practices. Experience with SonarQube or a comparable code quality and security analysis platform. Understanding of modern application architectures, APIs, containers, microservices, and cloud-native delivery patterns. Familiarity with CI/CD platforms, source code management, build automation, and DevSecOps processes. Ability to communicate technical risk and remediation guidance clearly to developers, engineers, managers, and nontechnical stakeholders.
7 or more years of cybersecurity, software security, software engineering, or application security experience. Advanced experience with SonarQube administration, custom rule profiles, quality gates, project onboarding, integration, and reporting. Experience with commercial application security technologies such as Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or comparable platforms. Experience integrating security testing into GitHub, GitLab, Azure DevOps, Jenkins, or similar CI/CD platforms. Knowledge of OWASP Top 10, OWASP ASVS, NIST SSDF, secure SDLC practices, and common application weakness classifications. Experience producing operational dashboards, executive metrics, key risk indicators, and trend reporting. Experience working in regulated financial services or another highly regulated enterprise environment. Experience supporting FFIEC, OCC, SOX, PCI DSS, or comparable audit and regulatory requirements. Experience automating application security workflows and reporting through PowerShell, Python, APIs, or vendor scripting.