We are seeking a Senior Application Security Engineer to help strengthen application security across the software development lifecycle. This is a hands‑on technical role focused on application security testing, vulnerability management, DevSecOps integration, and partnering directly with development teams to improve secure development practices.
The ideal candidate has experience administering and optimizing SAST, DAST, and SCA technologies, integrating security testing into CI/CD pipelines, and helping development teams understand and remediate application vulnerabilities.
Key Responsibilities
- Administer, configure, tune, and optimize SAST, DAST, and SCA security scanning platforms
- Manage SonarQube or comparable code quality/security analysis tools, including scanning configurations, quality gates, integrations, and reporting
- Integrate application security testing into CI/CD and DevSecOps workflows
- Analyze and validate security findings, reduce false positives, and help prioritize vulnerabilities
- Partner directly with developers and engineering teams to drive vulnerability remediation
- Provide secure coding guidance and support application security best practices
- Develop security metrics, dashboards, and reporting around vulnerabilities, remediation, and scanning effectiveness
- Identify recurring vulnerability patterns and recommend improvements to tools, processes, and development practices
- Support application architecture reviews, secure design discussions, and targeted code reviews
- Assist with security documentation, risk assessments, and audit‑related requests
- Automate security workflows and reporting where appropriate
Required Experience
- 5+ years of experience across application security, cybersecurity, software engineering, DevSecOps, or vulnerability management
- 3+ years of hands‑on experience with application security scanning technologies
- Strong experience with SAST and DAST, including configuration, execution, tuning, triage, and reporting
- Experience with SCA and vulnerability remediation
- Experience administering SonarQube or a comparable platform
- Experience integrating security controls into CI/CD pipelines
- Strong understanding of application vulnerabilities and secure development practices
- Experience working directly with developers to investigate and remediate security findings
- Familiarity with APIs, microservices, containers, and modern application architectures
Preferred Experience
- Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or similar AppSec platforms
- OWASP and secure SDLC practices
- Python, PowerShell, APIs, or other security automation/scripting
- Security dashboards, metrics, and executive reporting
- Experience within banking, financial services, or another regulated enterprise environment
- CISSP, CSSLP, GIAC, OSWE, cloud security, or similar security certifications