
Application Security Remediation Engineer
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in New York.
• Assess and address application-level vulnerabilities identified by Wiz.
• Fix code vulnerabilities in .NET, Java, PHP, Go, and Node.js applications.
• Update vulnerable libraries, frameworks, packages, and third-party dependencies.
• Conduct compatibility and regression testing for upgraded software components.
• Resolve container image vulnerabilities and insecure build configurations.
• Modernize and reconstruct affected images to meet organizational security standards.
• Collaborate with development teams to integrate secure coding practices.
• Tackle insecure configurations within application runtimes and frameworks.
• Validate completed remediations and ensure issues are accurately resolved within Wiz.
• Design and document reusable remediation patterns for recurring classes of vulnerabilities.
• Facilitate secure software delivery through DevSecOps and CI/CD integration.
• Work in partnership with SRE, cloud, platform, and security teams during remediation activities.
• Collaborate with customer software engineering teams across .NET, Java, Go, PHP, Node.js, SQL Server, and MySQL workloads.
• Strong software engineering experience in one or more of .NET/C#, Java, Go, PHP, or Node.js.
• Experience working in enterprise-scale application environments.
• Proven track record in remediating application vulnerabilities and implementing secure coding practices.
• Strong knowledge of OWASP Top 10 vulnerabilities and software supply-chain security.
• Experience with upgrading third-party libraries, frameworks, packages, and application dependencies.
• Knowledge of Docker and experience with container image remediation.
• Familiarity with Kubernetes application deployment and container security.
• Experience with SQL Server and/or MySQL, focusing on application-to-database security fundamentals.
• Understanding of CI/CD pipeline integration, Git-based workflows, and Secure Software Development Lifecycle practices.
• Experience with automated security testing, SAST, SCA, and dependency-management tools.
• Familiarity with vulnerability management programs and prioritizing Critical and High findings.
• Proficient in using tools such as Wiz, Snyk, Veracode, Checkmarx, SonarQube, or similar.
• Strong skills in debugging, analytical thinking, root-cause analysis, documentation, and communication.
• Preferred: Hands-on experience with Wiz.
• Preferred: Experience in securing containerized microservices architectures.
• Preferred: Background in cloud-native application development.
• Preferred: Experience with Amazon EKS and Kubernetes.
• Preferred: Secure coding or application-security certifications.
• Preferred: Experience in healthcare, payments, or other regulated industries.
• Equal opportunity employer.
• Accommodations or adjustments available throughout the interview process and beyond.
• Inclusive work environment.
• 3-month contract engagement.
Cisco
Cotiviti
Twilio
SimSpace
Get handpicked remote jobs straight to your inbox weekly.