
Senior Application Security Engineer β DevSecOps, CICD
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in Colorado, +2 more states.
β’ Integrate application security into the Software Development Life Cycle (SDLC) by defining and enhancing security processes, standards, workflows, and the Definition of Done criteria.
β’ Conduct both AI-assisted and traditional security evaluations of applications, APIs, cloud workloads, repositories, and their supporting infrastructure.
β’ Oversee repository scanning coverage, which includes source code analysis, secret scanning, dependency analysis, and infrastructure reviews.
β’ Assess findings based on exploitability, business impact, and severity.
β’ Facilitate the remediation process from discovery to verified closure.
β’ Mitigate security debt, dependency vulnerabilities, and software supply chain risks across the application portfolio.
β’ Develop security metrics, coverage reports, and executive dashboards.
β’ Advocate for a security-first culture through coaching, knowledge sharing, and the documentation of best practices.
β’ Review and assess new findings from Static Application Security Testing (SAST), Software Composition Analysis (SCA), secret scanning, and dependency analysis.
β’ Perform manual validation and security testing using tools such as Burp Suite, browser developer tools, API testing platforms, and secure code reviews.
β’ Create and refine backlog items, assign ownership, retest fixes, collect evidence, and confirm closure.
β’ Engage in Scrum ceremonies and manage Agile work items, user stories, tasks, and defects.
β’ Collaborate with application teams on code corrections, configuration modifications, infrastructure updates, and compensating controls.
β’ Execute ongoing security assessments and enhance processes and standards.
β’ Utilize AI tools responsibly for analysis, threat modeling, code review, and documentation within governance frameworks.
β’ Monitor emerging threats and security risks related to AI.
β’ Bachelorβs degree in Computer Science, Cybersecurity, Information Systems, or a related discipline.
β’ 5β7 years of practical experience in application security/DevSecOps.
β’ 5β7 years of experience with Secure SDLC, DevSecOps, Agile, and Scrum methodologies.
β’ 5β7 years of experience with various security tools.
β’ Strong working knowledge of Secure SDLC, DevSecOps, Agile, and Scrum methodologies.
β’ Proficiency with Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tools.
β’ Capability to read, analyze, test, and modify production application code in Java and Python.
β’ Familiarity with OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding practices, and common attack methodologies.
β’ Understanding of cloud security, identity and access management, and modern application architectures.
β’ Ability to effectively and safely utilize AI-assisted development and security tools.
β’ Experience in vulnerability triage and validation, assessing exploitability, business impact, severity, compensating controls, and providing remediation guidance.
β’ Experience in developing security metrics, coverage reports, and executive dashboards.
β’ Exceptional communication, stakeholder management, presentation, and documentation abilities.
β’ Capacity to work independently across multiple applications, teams, portfolios, and technology stacks.
β’ Strong problem-solving skills that balance security, usability, operational impact, and business goals.
β’ Ability to collaborate with and influence architects, developers, DevOps, product owners, and business stakeholders.
β’ Capacity to coach colleagues and share knowledge effectively.
β’ Comfort in operating within Scrum/Agile delivery frameworks and managing personal work items.
β’ Contract engagement with an estimated duration of 12+ months.
ExactCare
Devexperts
Motive
Get handpicked remote jobs straight to your inbox weekly.