Application Security Engineer
New
G
GuidePoint SecurityCybersecurity
Location: Remote; U.S. based onlyFull-Time
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Required Skills
- CI/CDGitHub Actions
Requirements
- Demonstrate proficiency implementing, operationalizing, and troubleshooting SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode.
- Understand CI/CD pipeline tools and processes, such as GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI.
- Have software engineering experience, ideally in full-stack software development and modern application architectures.
- Have strong scripting and automation experience using one or more programming languages.
- Have working knowledge of application security fundamentals, including OWASP Top 10, threat modeling, and secure coding throughout the SDLC.
- Be able to communicate effectively in writing and verbally.
- Preferred: experience writing or adapting custom SAST rules using Semgrep or CodeQL.
- Preferred: familiarity with IAST, DAST, SCA, API security, and API security tools such as NoName, Traceable, Salt, or Cequence.
- Preferred: hands-on experience validating vulnerabilities and proficiency with Burp Suite.
- Preferred: experience with secure development lifecycles, vulnerability triage and remediation, automated security testing, and integrating security into CI/CD pipelines.
Responsibilities
- Implement, operationalize, and troubleshoot SAST platforms in client environments.
- Design and integrate automated security testing into CI/CD pipelines.
- Author and adapt custom SAST rules, and triage, validate, and guide remediation of identified vulnerabilities.
- Advise client development teams on OWASP Top 10, threat modeling, and secure coding practices throughout the SDLC.
- Use AI-assisted tooling to accelerate rule development, triage, and remediation guidance.
- Contribute reusable pipeline patterns, rule libraries, and delivery accelerators for the AppSec practice.
- Deliver client engagements across the Northeast/Mid-Atlantic region, with occasional on-site presence as needed.
View Full Description & ApplyYou'll be redirected to the employer's site