We are seeking a Senior Application Security Engineer / DevSecOps Engineer to support and strengthen the execution of our Application Security Program.
The ideal candidate will have strong hands-on experience integrating application security practices into the software development lifecycle, working closely with development teams, and implementing security controls within CI/CD pipelines.
This is a hands-on role focused on application security testing, vulnerability analysis and remediation, DevSecOps integration, and collaboration with application development teams.
Key Responsibilities
- Configure, execute, monitor, administer, and troubleshoot application security platforms ( SAST, DAST, and SCA), including working with vendors to resolve platform issues and manage supports ticket.
- Analyze and manage application security vulnerabilities, including false positives, identifying duplicates, assessing exploitability, and assist with prioritization, remediation, vulnerability exception documentation, and risk asessment.
- Provide developers with actionable remediation guidance and support the verification of implemented fixes
- Build, integrate, maintain, and report on application security controls and activities, GitLab and Jenkins CI/CD pipelines/integrations, security metrics, vulnerability dashboards, weekly status reporting, and monthly management reporting.
- Support the implementation and improvement of Secure Software Development Lifecycle (Secure SDLC) practices.
- Collaborate closely with software development teams to identify and remediate application security vulnerabilities, support secure coding practices, validate implemented fixes, and facilitate vulnerability closure.
- Support and engage with Security Champions across application development teams.
- Maintain accurate vulnerability records, remediation status, supporting evidence, and risk or exception information. Prepare application security reports, metrics, and status updates for technical and business stakeholders.
- Help identify opportunities to automate and improve application security processes.
- Work with security and engineering teams to ensure security requirements are incorporated throughout the development lifecycle.
Required Qualifications
- 5+ years of experience in Application Security, Product Security, DevSecOps, or a related cybersecurity discipline.
- Hands-on experience configuring, operating, and troubleshooting SAST, DAST, and SCA tools and methodologies.
- Strong understanding of application vulnerabilities, vulnerability assesment, prioritization, and remediation.
- Hands-on experience integrating security tools into GitLab CI/CD pipelines.
- Strong understanding of DevSecOps principles and Secure SDLC practices.
- Experience working directly with software developers and engineering teams.
- Knowledge of OWASP Top 10 and common web application security vulnerabilities.
- Experience with the application security reporting and vulnerability/remediation tracking.
- Strong communication and collaboration skills.
Preferred Qualifications
- Experience implementing or supporting a Security Champions Program.
- Experience with Veracode and GitLab security capabilities and application security pipeline controls.
- Experience using APIs and scripting languages such as Python, PowerShell, Bash, or similar technologies to automate security processes.
- Familiarity with cloud environments such as AWS
- Familiarity with container security, Infrastructure as Code scanning, secrets detection, and API security testing.
- Relevant cybersecurity certifications such as GWAPT, GWEB, OSCP, CSSLP, Security+, or equivalent experience.
Technical Skills
Application Security
- SAST
- DAST
- SCA
- OWASP Top 10
- Vulnerability Management
- Secure Coding
- Secure SDLC
DevSecOps
- GitLab
- CI/CD Security Integration
- Security Automation
- DevSecOps Practices
Location:
Remote (LATAM closed to AST)
Engagement:
6-Month Contract (Renewable)
Position: 2
Languages
Fully Bilingual (Spanish/English)