
Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Implement, configure, administer, and optimize enterprise SAST capabilities.
• Onboard applications and repositories using documented, repeatable patterns.
• Configure scanning profiles, policies, presets, exclusions, and application-specific settings.
• Analyze findings across various languages and frameworks.
• Validate false positives, duplicate findings, and vulnerability classifications through secure code reviews.
• Provide guidance for remediation and examples of secure coding practices.
• Investigate issues related to failed or incomplete scans, performance, and integration.
• Enhance scan quality through query tuning, configuration optimization, and operational metrics.
• Support initiatives for tool migration, consolidation, or rationalization.
• Design and implement application security controls within CI/CD pipelines.
• Integrate SAST with source code repositories, pull requests, build pipelines, and developer workflows.
• Define risk-based security gates for builds, releases, and production deployments.
• Create and maintain reusable pipeline templates and security components.
• Troubleshoot issues related to authentication, API, repositories, build orchestration, and scan execution.
• Collaborate with DevOps and platform engineering teams to enhance reliability, scalability, and maintainability.
• Develop AppSec automation solutions using Python, PowerShell, Bash, or other suitable programming languages.
• Build integrations using REST APIs, webhooks, command-line interfaces, and supported SDKs.
• Automate processes for onboarding, scanning, result retrieval, triage, reporting, and workflow updates.
• Automate finding normalization, deduplication, enrichment, prioritization, and assignment.
• Integrate AppSec platforms with ticketing systems, reporting tools, source control, and collaboration systems.
• Implement logging, error handling, retries, monitoring, and maintain auditable execution records.
• Maintain automation code through version control, testing, documentation, and peer review.
• Prioritize, validate, and track vulnerabilities through remediation, retesting, risk acceptance, or closure.
• Identify recurring vulnerability patterns and recommend systemic preventive controls.
• Apply cloud security governance principles to application workloads, services, and delivery pipelines.
• Translate cloud control requirements into technical guardrails in collaboration with cloud security, architecture, engineering, risk, and compliance teams.
• Assess applications and pipelines against cloud security standards, configuration baselines, and policy requirements.
• Support governance for cloud identities, roles, service accounts, secrets, encryption, logging, and workload access controls.
• Assist with cloud control assessments, evidence collection, exception management, remediation tracking, and audit readiness across AWS, Microsoft Azure, and Google Cloud.
• Map AppSec and CI/CD controls to enterprise policies, regulatory obligations, and recognized security frameworks.
• Embed application security requirements throughout the design, development, testing, and release processes.
• Support threat modeling and security reviews for high-risk applications or significant changes.
• Create standards, checklists, onboarding guides, runbooks, and technical documentation.
• Deliver technical enablement for developers, DevOps engineers, and security champions.
• Maintain program records, coverage metrics, remediation data, and audit evidence.
• Support control assessments, risk reviews, exception governance, and continuous improvement.
• Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.
• Five or more years of relevant experience in Application Security, Product Security, DevSecOps, or software security engineering.
• Strong hands-on experience with enterprise SAST platforms, secure code analysis, and vulnerability validation.
• Practical experience in integrating security scanning into CI/CD pipelines and source control workflows.
• Experience with GitHub, GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent technologies.
• Strong scripting or development skills using Python, PowerShell, Bash, Java, C#, JavaScript, or similar programming languages.
• Experience building integrations using REST APIs, webhooks, service accounts, and modern authentication mechanisms.
• Strong understanding of OWASP Top 10, CWE classifications, secure coding practices, and vulnerability remediation.
• Ability to review source code and validate findings in at least one major programming language.
• Understanding of web applications, APIs, microservices, containers, and cloud-native architectures.
• Working knowledge of cloud security governance, security control implementation, compliance evidence, and exception management.
• Understanding of cloud IAM, encryption, secrets management, logging, monitoring, and secure configuration principles.
• Strong analytical, troubleshooting, documentation, and stakeholder communication skills.
• Hands-on administration or integration experience with leading SAST platforms.
• Current or recent vendor certification focused on SAST administration, implementation, query development, scanning, or secure code analysis.
• Knowledge of or certifications in penetration testing, application security, cloud security, DevSecOps, or secure software development are preferred or beneficial.
• Experience integrating SCA, secrets scanning, API security, Infrastructure as Code scanning, or container security is preferred.
• Experience developing reusable CI/CD components is preferred.
• Knowledge of software supply chain security, dependency risk management, and cloud security is preferred.
• Experience producing AppSec dashboards, control evidence, and program metrics is preferred.
• Health care coverage tailored for both mental and physical well-being.
• Generous time-off policy.
• Continuous learning resources and opportunities for career development.
• Competitive salary.
• Retirement planning options.
• Continuing education program with company-matched contributions for student loans.
• Financial wellness initiatives.
• Family-friendly benefits and perks.
• Retail discounts.
• Referral incentive awards.
Ontrac Solutions
Nebius Group
Xcellent Technology Solutions (XTS)
S&P Global
Get handpicked remote jobs straight to your inbox weekly.