Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

3 months ago
Full-time
Senior
Software Development
GuidePoint Security

GuidePoint Security

GuidePoint Security is a trusted cybersecurity consulting firm that provides expertise, solutions, and services to help organizations make informed decisions and minimize risks. Their elite team of experts offers holistic perspectives on cybersecurity,...

Internet Software & Services
251-1K
Founded 2011

Description

  • Implement, operationalize, and troubleshoot SAST tools across application environments.
  • Work with CI/CD pipeline tools and processes to integrate security into delivery workflows.
  • Apply application security fundamentals, including OWASP Top 10, threat modeling, and secure coding practices across the SDLC.
  • Use scripting and automation to support security engineering tasks and improve efficiency.
  • Validate vulnerabilities and support remediation efforts for findings from application security tools.
  • Write or adapt custom SAST rules when needed.
  • Build and operate security tools within CI/CD pipelines.
  • Collaborate with development teams to proactively integrate security into the development process.
  • Communicate findings and recommendations clearly in written and verbal formats.

Requirements

  • Proficiency with SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode.
  • Understanding of CI/CD pipeline tools and processes such as GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI.
  • Experience in software engineering, ideally full stack development, with modern technologies and application architectures.
  • Strong scripting and automation experience using one or more programming languages.
  • Working knowledge of application security fundamentals, including the OWASP Top 10, threat modeling, and secure coding practices.
  • Excellent written and verbal communication skills.
  • Experience writing or adapting custom SAST rules, especially in Semgrep or CodeQL, preferred.
  • Familiarity with additional application security tools such as IAST, DAST, API security, and SCA, preferred.
  • Familiarity with API security tools such as NoName, Traceable, Salt, or Cequence, preferred.
  • Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite, preferred.
  • Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities from web application scanning tools, preferred.
  • Experience with automated security testing approaches and building security tools into CI/CD pipelines, preferred.
  • Past experience as an application security practitioner or software engineer, preferred.
  • Bachelor’s degree in a relevant discipline or equivalent experience.
  • 5-7 years of security engineering experience in the Information Security industry.

Benefits

  • Remote workforce primarily, with U.S.-based work and some travel or onsite requirements for certain roles.
  • Group medical insurance options with substantial employer premium contributions.
  • Group dental insurance with 100% employee premium coverage and 75% coverage for family plans.
  • 12 corporate holidays and a Flexible Time Off (FTO) program.
  • Healthy mobile phone and home internet allowance.
  • Eligibility for a retirement plan after 2 months at open enrollment.
  • Pet benefit option.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Mobile Software Engineer (iOS / Android), Identity & Security - India

JumpCloud 251-1K Internet Software & Services

JumpCloud is hiring a Senior Mobile Software Engineer to build secure native iOS and Android applications that protect enterprise identities through authentication, password management, and identity verification.

Android AWS CI/CD Encryption Espresso GCP GitHub Actions Go iOS Kotlin OpenID Connect REST API Swift WebSockets XCTest
2 hours, 8 minutes ago

Staff Application Security Engineer (R5949)

Bitly 51-250 Internet Software & Services

Shield AI is seeking a Staff Application Security Engineer to establish and scale a developer-centered secure software development and software supply-chain security program across its defense-technology engineering organization.

Burp Suite DevSecOps Kubernetes Microservices SonarQube
2 hours, 38 minutes ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
1 day, 1 hour ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
1 day, 2 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers