
Application Security Engineer
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in Illinois.
• Integrate comprehensive security measures throughout the secure Software Development Life Cycle (SDLC), from design to deployment.
• Implement static (SAST) and dynamic (DAST) application security testing utilizing enterprise tools.
• Spearhead and assist in penetration testing initiatives.
• Provide guidance to developers for actionable remediation strategies.
• Perform SAST using Fortify on designated applications.
• Carry out continuous analysis of code quality and security with SonarQube.
• Conduct DAST to uncover runtime vulnerabilities.
• Organize and perform penetration testing initiatives.
• Execute secure code reviews and document findings with practical recommendations.
• Monitor and confirm the remediation of vulnerabilities until resolution.
• Assess application security controls in alignment with program and Department of Defense (DoD) requirements.
• Prepare application security assessment and penetration test reports.
• Assist the Cybersecurity Architect in designing secure SDLC processes.
• Collaborate with developers and architects across a varied application ecosystem.
• Engage in a cybersecurity program that includes architecture, Governance, Risk Management, and Compliance (GRC), as well as operational experts.
• Active Secret or TS clearance is mandatory.
• 3–5 years of experience in application security, secure development practices, or penetration testing.
• Practical experience with SAST tools, with a preference for Fortify.
• Familiarity with the OWASP Top 10 and common classes of application vulnerabilities.
• Proven experience in conducting or assisting with penetration tests.
• DoD 8140.03M DCWF Basic Tier — Certified Ethical Hacker (CEH).
• DoD 8140 Interim Education Options applicable.
• Willingness to travel to Scott Airforce Base quarterly.
• DoD 8140.03M DCWF Intermediate Tier — one of the following: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+.
• Experience with SonarQube or equivalent secure code analysis tools.
• Knowledge of DevSecOps pipelines and the integration of security within CI/CD processes.
• Scripting or programming experience in Python, Java, or similar languages.
• Up to 10% travel may be required.
• Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering is preferred.
• Flexible time off policy.
• Comprehensive learning resources available.
• Healthcare coverage provided.
• Wellness programs offered.
• Financial benefits included.
• Retirement plans available.
• Support for family-related needs.
• Opportunities for continuing education.
• Competitive salary package.
Trimble Inc.
Bugcrowd
ExactCare
Devexperts
Get handpicked remote jobs straight to your inbox weekly.