Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

1 month, 3 weeks ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Implement, operationalize, and troubleshoot SAST tools across application environments.
  • Work with CI/CD pipeline tools and processes to integrate security into delivery workflows.
  • Apply application security fundamentals, including OWASP Top 10, threat modeling, and secure coding practices across the SDLC.
  • Use scripting and automation to support security engineering tasks and improve efficiency.
  • Validate vulnerabilities and support remediation efforts for findings from application security tools.
  • Write or adapt custom SAST rules when needed.
  • Build and operate security tools within CI/CD pipelines.
  • Collaborate with development teams to proactively integrate security into the development process.
  • Communicate findings and recommendations clearly in written and verbal formats.

Requirements

  • Proficiency with SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode.
  • Understanding of CI/CD pipeline tools and processes such as GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI.
  • Experience in software engineering, ideally full stack development, with modern technologies and application architectures.
  • Strong scripting and automation experience using one or more programming languages.
  • Working knowledge of application security fundamentals, including the OWASP Top 10, threat modeling, and secure coding practices.
  • Excellent written and verbal communication skills.
  • Experience writing or adapting custom SAST rules, especially in Semgrep or CodeQL, preferred.
  • Familiarity with additional application security tools such as IAST, DAST, API security, and SCA, preferred.
  • Familiarity with API security tools such as NoName, Traceable, Salt, or Cequence, preferred.
  • Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite, preferred.
  • Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities from web application scanning tools, preferred.
  • Experience with automated security testing approaches and building security tools into CI/CD pipelines, preferred.
  • Past experience as an application security practitioner or software engineer, preferred.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • 5-7 years of security engineering experience in the Information Security industry.

Benefits

  • Remote workforce primarily, with U.S.-based work and some travel or onsite requirements for certain roles.
  • Group medical insurance options with substantial employer premium contributions.
  • Group dental insurance with 100% employee premium coverage and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for a retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
16 hours, 18 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
17 hours, 3 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 16 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 17 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers