
Application Security Engineer
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in India.
• Provide engineering support focused on security for web and API applications.
• Integrate security measures into the Secure SDLC, encompassing threat modeling and security design evaluations.
• Ensure compliance with organizational security protocols and industry best practices.
• Administer and oversee vulnerability scanning tools (e.g., Tenable or similar).
• Set up, adjust, and maintain scanning policies and schedules.
• Enhance tool performance to increase accuracy and minimize false positives.
• Implement and sustain SAST and DAST tools within CI/CD pipelines.
• Collaborate with engineering teams to ensure smooth integration and actionable insights.
• Identify and verify vulnerabilities through both automated and manual testing.
• Conduct false-positive analysis and evaluate exploitability.
• Review scanning results and monitor vulnerabilities to resolution.
• Work with development teams for prompt remediation efforts.
• Validate vulnerabilities using manual testing and offensive security techniques.
• Clearly document attack paths, reproduction steps, and impact assessments.
• Conduct both manual and automated security testing for applications and APIs.
• Bachelor’s degree in computer science, Information Security, or a related field.
• 3–6 years of experience in Application Security or a comparable area.
• Practical experience with SAST, DAST, and vulnerability scanning tools.
• Strong knowledge of the OWASP Top 10, as well as web application and API security.
• Familiarity with CI/CD pipeline integrations (e.g., Jenkins, GitHub Actions, GitLab).
• Understanding of secure coding practices and common vulnerability patterns.
• Knowledge of scripting languages (Python, Bash, or similar) is an advantage.
• Experience with threat modeling and secure design reviews is preferred.
• Exposure to red teaming or penetration testing techniques is an advantage.
• Relevant certifications (e.g., OSCP, CEH, GWAPT) are a plus.
• E-Verify participation
• Equal Opportunity Employer
Fusion Practices
Lightology
Trimark Associates, Inc.
Intuitive
Get handpicked remote jobs straight to your inbox weekly.