Senior Information Security Engineer

Jobtailor

Arizona

On-site

USD 120,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced Application Security Engineer to lead automation, tooling integration, and SSDLC maturation within our CI/CD ecosystem.

You will drive security controls across tools, support audits, and collaborate with cybersecurity leadership to design and implement new controls, including AI-assisted workflows and governance considerations.

Qualifications

  • 4+ years in Information Security Engineering or equivalent.
  • SAST, DAST, SCA, secrets management, and IaC expertise.
  • Strong experience integrating SAST/DAST/SCA into SDLC workflows and source code repositories.
  • Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems.
  • Strong understanding of OWASP standards and MITRE CVE/CWE frameworks.
  • Experience implementing SSDLC practices across Agile/custom development frameworks.
  • Familiarity with AI/LLM-enabled development tooling and governance considerations.
  • 4+ years of development in more than one language; 3+ years using IaC to configure, build, and deploy; 2+ years of DevSecOps/Automation.
  • Hands-on with Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, and Qualys.
  • Proven experience with GHAS, including secret scanning; API development experience; AI-assisted development/tools knowledge.
  • Ability to account for model limitations, security risks, and operational considerations; AI usage aligned with security, compliance, privacy, and ethics.

Responsibilities

  • Design and implement repeatable, scalable, and automated AppSec processes.
  • Provide hands-on technical leadership in tooling, automation, and process execution.
  • Integrate AppSec controls across enterprise tools and CI/CD pipelines.
  • Support reporting of AppSec processes, status, and outcomes.
  • Collaborate with control management and cybersecurity leadership on new controls.

Skills

Technical Leadership
Collaboration
Communication
DevSecOps Automation
SSDLC Practices

Tools

GitHub
Jira
ServiceNow
Jenkins
Harness
Checkmarx
Blackduck
Prisma
Trufflehog
Synk
Socket
Invicti
Qualys
GitHub Advanced Security
GitHub Copilot

Job description

  • Design and implement repeatable, scalable, and automated Application Security processes
  • Provide hands-on technical leadership in tooling integration, automation, and process execution
  • Implement product enhancements and fine-tune rules to improve identification and prioritization of application security defects
  • Manage upgrades, resiliency, continuity, and compliance with enterprise standards
  • Recommend mitigation strategies for application security risks
  • Represent Application Security in cross-functional governance and technical forums
  • Integrate Application Security controls across enterprise tools and CI/CD pipelines
  • Support reporting of Application Security processes, execution status, and outcomes
  • Collaborate with control management and cybersecurity leadership to design new security controls
  • Support internal and external audits, regulatory reviews, and third-party assessments
  • Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
  • Validate and integrate AI-assisted outputs into solutions
Requirements
  • 4+ years of Information Security Engineering experience, or equivalent demonstrated through work experience, training, military experience, or education
  • Expertise across SAST, DAST, SCA, secrets management and detection, and Infrastructure as Code (IaC)
  • Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories
  • Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems
  • Strong understanding of OWASP standards and MITRE CVE/CWE frameworks
  • Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom development frameworks
  • Familiarity with AI/LLM-enabled development tooling, auto-remediation capabilities using AI, and governance considerations
  • Position is not eligible for Visa sponsorship
  • 4+ years of development experience in more than one language
  • 3+ years of using IaC to configure, build, and deploy
  • 2+ years of DevSecOps / Automation experience
  • Hands-on experience with Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, and Qualys
  • Proven experience with GitHub Advanced Security (GHAS), including secret scanning capabilities
  • Experience in API development and custom services
  • Proficiency using AI-assisted development and analysis tools, including GitHub Copilot and approved code-centric agents
  • Ability to account for model limitations, security risks, and operational considerations
  • Ability to apply AI responsibly in development and production environments
  • AI usage must align with security, compliance, privacy, and ethical standards
Core Competencies

Demonstrates expertise in Application Security processes, integrating security controls within CI/CD pipelines, and implementing Secure Software Development Lifecycle (SSDLC) practices. Proficient in leveraging AI for development and security enhancements while ensuring compliance with industry standards.

Highest-signal resume keywords
  • Application Security Process Design
  • SAST, DAST, SCA Integration
  • Secure Software Development Lifecycle (SSDLC)
  • AI-Assisted Development Tools
  • DevSecOps Automation
Hard Skills
  • Information Security Engineering
  • Infrastructure as Code (IaC)
  • API Development
  • GitHub Advanced Security (GHAS)
  • OWASP Standards
  • MITRE CVE/CWE Frameworks
  • Secure Coding Practices
  • Automation Techniques
  • AI Model Limitations Awareness
  • Secret Management
Soft Skills
  • Technical Leadership
  • Collaboration
  • Communication
Industry Keywords
  • Application Security
  • Compliance
  • Cybersecurity
  • Governance
  • Regulatory Reviews
Tools & Technologies
  • GitHub
  • Jira
  • ServiceNow
  • Jenkins
  • Harness
  • Checkmarx
  • Blackduck
  • Prisma
  • Trufflehog
  • Qualys
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Staff Product Security Engineer – AI
Senior Staff Product Security Engineer – AI

Jobtailor • Illinois

On-site
USD 140,000 - 220,000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Principal, Product Security
Principal, Product Security

Jobtailor • Illinois

On-site
USD 140,000 - 200,000
Cyber Security Web Application Research Engineer
Cyber Security Web Application Research Engineer

Jobtailor • Arizona

Hybrid
USD 90,000 - 130,000
Security Engineer, Application Security
Security Engineer, Application Security

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
IT Security Auditor
IT Security Auditor

Jobtailor • Missouri

On-site
USD 120,000 - 180,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Technical Lead, Security Embedded Engineering
Technical Lead, Security Embedded Engineering

Jobtailor • Plano (TX)

On-site
USD 140,000 - 180,000
Senior DevSecOps Engineer II
Senior DevSecOps Engineer II

Jobtailor • Reston (VA)

On-site
USD 150,000 - 210,000