Senior Application Security Engineer / DevSecOps Engineer

SMX Services & Consulting, Inc.

United States

Remote

USD 112,000 - 156,000

Full time

14 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Remote work
Contract renewal possibilities

Job summary

SMX Services & Consulting, Inc. is seeking a Senior Application Security Engineer / DevSecOps to strengthen its application security program. This hands-on role focuses on security testing, vulnerability analysis, and CI/CD integration.

Responsibilities include managing SAST/DAST/SCA, remediation guidance, and secure SDLC practices while collaborating with development teams. The position is remote (LATAM region) and a 6-month contract with renewal; bilingual in Spanish/English.

Qualifications

  • 5+ years of experience in Application Security, DevSecOps, or related cybersecurity discipline.
  • Hands-on experience with SAST, DAST, and SCA tools.
  • Experience integrating security into GitLab CI/CD.
  • Knowledge of OWASP Top 10 and web app vulnerabilities.
  • Strong communication and collaboration skills.

Responsibilities

  • Configure and operate SAST, DAST, and SCA security platforms and resolve platform issues.
  • Analyze vulnerabilities, prioritize fixes, and document risk.
  • Provide remediation guidance to developers and verify fixes.
  • Develop and report on security controls, dashboards, and metrics in CI/CD.
  • Promote Secure SDLC practices and collaboration with development teams.
  • Engage Security Champions across teams.
  • Maintain vulnerability records and evidence for stakeholders.
  • Identify opportunities to automate security processes.
  • Ensure security requirements are integrated throughout the SDLC.

Skills

Application Security
DevSecOps
GitLab CI/CD
SAST
DAST
SCA
Vulnerability Assessment
Security Communication

Tools

SAST
DAST
SCA

Job description

We are seeking a Senior Application Security Engineer / DevSecOps Engineer to support and strengthen the execution of our Application Security Program.

The ideal candidate will have strong hands-on experience integrating application security practices into the software development lifecycle, working closely with development teams, and implementing security controls within CI/CD pipelines.

This is a hands-on role focused on application security testing, vulnerability analysis and remediation, DevSecOps integration, and collaboration with application development teams.

Key Responsibilities
  • Configure, execute, monitor, administer, and troubleshoot application security platforms ( SAST, DAST, and SCA), including working with vendors to resolve platform issues and manage supports ticket.
  • Analyze and manage application security vulnerabilities, including false positives, identifying duplicates, assessing exploitability, and assist with prioritization, remediation, vulnerability exception documentation, and risk asessment.
  • Provide developers with actionable remediation guidance and support the verification of implemented fixes
  • Build, integrate, maintain, and report on application security controls and activities, GitLab and Jenkins CI/CD pipelines/integrations, security metrics, vulnerability dashboards, weekly status reporting, and monthly management reporting.
  • Support the implementation and improvement of Secure Software Development Lifecycle (Secure SDLC) practices.
  • Collaborate closely with software development teams to identify and remediate application security vulnerabilities, support secure coding practices, validate implemented fixes, and facilitate vulnerability closure.
  • Support and engage with Security Champions across application development teams.
  • Maintain accurate vulnerability records, remediation status, supporting evidence, and risk or exception information. Prepare application security reports, metrics, and status updates for technical and business stakeholders.
  • Help identify opportunities to automate and improve application security processes.
  • Work with security and engineering teams to ensure security requirements are incorporated throughout the development lifecycle.
Required Qualifications
  • 5+ years of experience in Application Security, Product Security, DevSecOps, or a related cybersecurity discipline.
  • Hands-on experience configuring, operating, and troubleshooting SAST, DAST, and SCA tools and methodologies.
  • Strong understanding of application vulnerabilities, vulnerability assesment, prioritization, and remediation.
  • Hands-on experience integrating security tools into GitLab CI/CD pipelines.
  • Strong understanding of DevSecOps principles and Secure SDLC practices.
  • Experience working directly with software developers and engineering teams.
  • Knowledge of OWASP Top 10 and common web application security vulnerabilities.
  • Experience with the application security reporting and vulnerability/remediation tracking.
  • Strong communication and collaboration skills.
Preferred Qualifications
  • Experience implementing or supporting a Security Champions Program.
  • Experience with Veracode and GitLab security capabilities and application security pipeline controls.
  • Experience using APIs and scripting languages such as Python, PowerShell, Bash, or similar technologies to automate security processes.
  • Familiarity with cloud environments such as AWS
  • Familiarity with container security, Infrastructure as Code scanning, secrets detection, and API security testing.
  • Relevant cybersecurity certifications such as GWAPT, GWEB, OSCP, CSSLP, Security+, or equivalent experience.
Technical Skills
Application Security
  • SAST
  • DAST
  • SCA
  • OWASP Top 10
  • Vulnerability Management
  • Secure Coding
  • Secure SDLC
DevSecOps
  • GitLab
  • CI/CD Security Integration
  • Security Automation
  • DevSecOps Practices
Location:

Remote (LATAM closed to AST)

Engagement:

6-Month Contract (Renewable)

Position: 2
Languages

Fully Bilingual (Spanish/English)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Prediktive • New York (NY)

Remote
USD 130,000 - 190,000
Application Security
Application Security

Smart IT Frame LLC • Berkeley Heights (NJ)

On-site
USD 110,000 - 160,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

On-site
USD 100,000 - 130,000
Security Engineer – SAST & SCA (Application Security)
Security Engineer – SAST & SCA (Application Security)

US staffing Inc • San Jose (CA)

On-site
USD 150,000 - 210,000
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • United States

Remote
USD 83,000 - 152,000
Senior Application Security Engineer
Senior Application Security Engineer

Gsc Llc • Maryland

On-site
USD 120,000 - 150,000
Remote Senior Application Security Engineer (DevSecOps)
Remote Senior Application Security Engineer (DevSecOps)

SMX Services & Consulting, Inc. • United States

Remote
USD 112,000 - 156,000
Remote work
Contract renewal possibilities
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Texas City (TX)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Miami (FL)

On-site
USD 120,000 - 180,000
Professional growth
Competitive compensation
Fortune 500 projects
+1