
Application Security Engineer
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in Illinois.
• Integrate comprehensive security practices throughout the secure SDLC, from design to deployment.
• Perform static (SAST) and dynamic (DAST) application security testing utilizing enterprise-level tools.
• Lead and facilitate penetration testing activities.
• Provide guidance to developers for effective vulnerability remediation.
• Conduct SAST using Fortify on designated applications.
• Carry out ongoing code quality and security assessments with SonarQube.
• Implement DAST to uncover runtime vulnerabilities.
• Organize and carry out penetration testing operations.
• Perform secure code reviews and document findings with practical recommendations.
• Monitor and confirm the closure of vulnerability remediation efforts.
• Assess application security controls in alignment with program and DoD requirements.
• Prepare application security assessment and penetration test reports.
• Assist the Cybersecurity Architect in designing secure SDLC processes.
• Collaborate with developers and architects across a varied application landscape.
• Must possess an active Secret or TS clearance.
• 3–5 years of experience in application security, secure development, or penetration testing.
• Practical experience with SAST tools (Fortify preferred).
• Familiarity with the OWASP Top 10 and prevalent application vulnerability categories.
• Proven experience in conducting or assisting with penetration tests.
• Attainment of DoD 8140.03M DCWF Basic Tier — CEH.
• Completion of DoD 8140 Interim Education Options.
• Willingness to travel quarterly to Scott Airforce Base.
• Attainment of DoD 8140.03M DCWF Intermediate Tier — one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ (preferred).
• Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering (preferred).
• Experience with SonarQube or comparable secure code analysis tools (preferred).
• Knowledge of DevSecOps pipelines and CI/CD security integration (preferred).
• Scripting or programming experience in Python, Java, or related languages (preferred).
• Flexible time off benefit.
• Extensive learning resources.
• Comprehensive healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Generous time off provisions.
• Opportunities for learning and development.
• Flexible work arrangements.
Trimble Inc.
Bugcrowd
ExactCare
Devexperts
Get handpicked remote jobs straight to your inbox weekly.