Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

1 month ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Implement, operationalize, and troubleshoot SAST tools across application environments.
  • Work with CI/CD pipeline tools and processes to integrate security into delivery workflows.
  • Apply application security fundamentals, including OWASP Top 10, threat modeling, and secure coding practices across the SDLC.
  • Use scripting and automation to support security engineering tasks and improve efficiency.
  • Validate vulnerabilities and support remediation efforts for findings from application security tools.
  • Write or adapt custom SAST rules when needed.
  • Build and operate security tools within CI/CD pipelines.
  • Collaborate with development teams to proactively integrate security into the development process.
  • Communicate findings and recommendations clearly in written and verbal formats.

Requirements

  • Proficiency with SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode.
  • Understanding of CI/CD pipeline tools and processes such as GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI.
  • Experience in software engineering, ideally full stack development, with modern technologies and application architectures.
  • Strong scripting and automation experience using one or more programming languages.
  • Working knowledge of application security fundamentals, including the OWASP Top 10, threat modeling, and secure coding practices.
  • Excellent written and verbal communication skills.
  • Experience writing or adapting custom SAST rules, especially in Semgrep or CodeQL, preferred.
  • Familiarity with additional application security tools such as IAST, DAST, API security, and SCA, preferred.
  • Familiarity with API security tools such as NoName, Traceable, Salt, or Cequence, preferred.
  • Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite, preferred.
  • Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities from web application scanning tools, preferred.
  • Experience with automated security testing approaches and building security tools into CI/CD pipelines, preferred.
  • Past experience as an application security practitioner or software engineer, preferred.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • 5-7 years of security engineering experience in the Information Security industry.

Benefits

  • Remote workforce primarily, with U.S.-based work and some travel or onsite requirements for certain roles.
  • Group medical insurance options with substantial employer premium contributions.
  • Group dental insurance with 100% employee premium coverage and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for a retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevSecOps

Cato Networks 251-1K Diversified Telecommunication Services

Cato Networks is hiring an Application Security Engineer (DevSecOps) to embed security across its cloud-based software development lifecycle and help R&D teams deliver secure applications at scale.

Agile AWS CI/CD DevSecOps Docker Go Java Kubernetes Microservices Network Security Python Terraform
1 day, 12 hours ago

Manager, Product Research

Huntress 251-1K Professional Services

Huntress is hiring a remote US Product Research Manager to lead cybersecurity research efforts that improve threat detection and prevention for customers.

Cybersecurity
4 days, 14 hours ago

Lead Application Security Engineer

Zeta Global 1K-5K Media

Zeta Global is hiring a Lead Application Security Engineer to strengthen application and platform security across its AI-powered marketing platforms through automated, AI-native security practices and cross-functional security engineering.

AWS Azure Burp Suite CI/CD Cybersecurity DevSecOps Django Docker FastAPI GCP JWT Kubernetes Microservices Node.js OAuth OpenID Connect React SonarQube
5 days, 12 hours ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architecture IC to define and drive secure-by-design architecture across its enterprise planning platform and AI products.

Encryption Machine Learning OWASP
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers