Senior Application Security Engineer

TekStream Solutions

United States

On-site

USD 110,000 - 170,000

Full time

17 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TekStream Solutions is seeking an Application Security Engineer to bridge the gap between InfoSec and development teams. You will act as a security ambassador, helping developers understand vulnerabilities, automating security into CI/CD pipelines, and driving remediation to ensure secure-by-design software.

Consulting experience and west coast hours for client work are preferred. Join a team focused on DevSecOps integration, remediation analysis, risk reviews, and architecture assessments to

Qualifications

  • Solid understanding of cybersecurity principles and threats.
  • Proficiency in software development, notably Microsoft .NET/C# code bases.
  • Familiarity with testing tools and techniques for both on-premises and cloud environments.
  • Experience with security testing tools: GitGuardian, Veracode, SonarQube, Qualys DAST, Wiz.

Responsibilities

  • Guide developers in understanding vulnerabilities and remediation options.
  • Collaborate with developers to enforce security best practices during development cycles.
  • Use SAST/DAST tools for security testing and validate remediation outcomes.
  • Recommend efficient fixes to streamline remediation processes.

Skills

Cybersecurity Knowledge
Development Experience
Cloud & On-Premises Familiarity
Languages

Tools

GitGuardian
Veracode
SonarQube
Qualys DAST
Wiz

Job description

TekStream, a Digital Resilience Consulting company, is seeking a skilled and collaborative Application Security Engineer to bridge the gap between our Information Security (InfoSec) team and development personnel. In this role, you will act as a security ambassador, helping developers understand vulnerabilities, automating security into our CI/CD pipelines, and driving remediation efforts to ensure our software is secure by design. The ideal candidate has consulting experience and is open to working west coast hours for our client.

Key Responsibilities
  • Guide and assist development personnel in understanding security vulnerabilities and implementing remediation options.
  • Collaborate with developers to ensure adherence to security best practices during development cycles.
  • Utilize SAST and DAST tools for thorough security testing and validation of remediation efforts.
  • Recommend efficient solutions for fixes to streamline the overall remediation process.
DevSecOps Integration
  • Build out capabilities of the DevSecOps Team, actively contributing to integrating security practices into CI/CD pipelines.
  • Automate manual processes to improve the efficiency and speed of development workflows.
Vulnerability & Penetration Test Remediation
  • Analyze findings from penetration tests and propose concrete remediation tasks.
  • Support assigned teams with the technical aspects of the remediation process.
  • Monitor and track progress on remediation tasks to ensure timely completion.
Security Reviews & Assessments
  • Review False Positive (FP) submissions, providing clear guidance on resolution and ensuring proper justification and documentation.
  • Evaluate Risk Acceptance Requests (RARs), providing mitigation recommendations and identifying cases requiring further review.
  • Participate in architecture reviews of security products and architectures to identify potential improvements.
  • Support security assessments, including scoping, report reviews, and remediation planning.
Process Improvement
  • Research and recommend optimization opportunities related to the team's organization, processes, procedures, and tools to improve efficiency and maturity.
Role Requirements & Qualifications
Technical & Development Experience
  • Cybersecurity Knowledge: Solid understanding of cybersecurity principles, including common threats and vulnerabilities.
  • Development Experience: Proficiency in software development, preferably within a Microsoft .NET/C# code base.
  • Cloud & On-Premises Familiarity: Familiarity with testing tools and techniques for both on-premises and cloud environments is highly valued.
  • Tooling Proficiency: Experience with or knowledge of the following tools:
  • SAST/DAST/Secrets: GitGuardian, Veracode, SonarQube, Qualys DAST, Wiz
  • Languages: .NET, C#
Core Competencies
  • Analytical Skills: Ability to analyze risks associated with vulnerabilities and recommend appropriate resolutions or risk reduction strategies.
  • Communication Skills: Excellent oral and written communication skills, with the ability to effectively translate technical details to both technical and non-technical stakeholders in a consulting capacity.
  • Coordination & Collaboration: Proven ability to collaborate with various resources across IT and vendor populations to achieve security objectives while acting as a supportive team member.
  • Documentation & Compliance: Proficient in collecting and synthesizing information into an accurate format suitable for audits. High attention to detail is essential.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer — DevSecOps & Secure CI/CD
Senior Application Security Engineer — DevSecOps & Secure CI/CD

TekStream Solutions • United States

On-site
USD 110,000 - 170,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

Infosys • Richardson (TX)

On-site
USD 110,000 - 170,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

SMX Services & Consulting, Inc. • United States

Remote
USD 112,000 - 156,000
Remote work
Contract renewal possibilities
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Texas City (TX)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Sr. Software Engineer (Security Specialist)
Sr. Software Engineer (Security Specialist)

BAMM • United States

Remote
USD 140,000 - 200,000
Remote work
Competitive salary