Senior Application Security Engineer – DevSecOps, CICD

Posted Sep 1

This is a fully remote position, open to applicants in Colorado, +2 more states.

πŸ“‹ Description

β€’ Integrate application security into the Software Development Life Cycle (SDLC) by defining and enhancing security processes, standards, workflows, and the Definition of Done criteria.

β€’ Conduct both AI-assisted and traditional security evaluations of applications, APIs, cloud workloads, repositories, and their supporting infrastructure.

β€’ Oversee repository scanning coverage, which includes source code analysis, secret scanning, dependency analysis, and infrastructure reviews.

β€’ Assess findings based on exploitability, business impact, and severity.

β€’ Facilitate the remediation process from discovery to verified closure.

β€’ Mitigate security debt, dependency vulnerabilities, and software supply chain risks across the application portfolio.

β€’ Develop security metrics, coverage reports, and executive dashboards.

β€’ Advocate for a security-first culture through coaching, knowledge sharing, and the documentation of best practices.

β€’ Review and assess new findings from Static Application Security Testing (SAST), Software Composition Analysis (SCA), secret scanning, and dependency analysis.

β€’ Perform manual validation and security testing using tools such as Burp Suite, browser developer tools, API testing platforms, and secure code reviews.

β€’ Create and refine backlog items, assign ownership, retest fixes, collect evidence, and confirm closure.

β€’ Engage in Scrum ceremonies and manage Agile work items, user stories, tasks, and defects.

β€’ Collaborate with application teams on code corrections, configuration modifications, infrastructure updates, and compensating controls.

β€’ Execute ongoing security assessments and enhance processes and standards.

β€’ Utilize AI tools responsibly for analysis, threat modeling, code review, and documentation within governance frameworks.

β€’ Monitor emerging threats and security risks related to AI.


⛳️ Requirements

β€’ Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related discipline.

β€’ 5–7 years of practical experience in application security/DevSecOps.

β€’ 5–7 years of experience with Secure SDLC, DevSecOps, Agile, and Scrum methodologies.

β€’ 5–7 years of experience with various security tools.

β€’ Strong working knowledge of Secure SDLC, DevSecOps, Agile, and Scrum methodologies.

β€’ Proficiency with Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tools.

β€’ Capability to read, analyze, test, and modify production application code in Java and Python.

β€’ Familiarity with OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding practices, and common attack methodologies.

β€’ Understanding of cloud security, identity and access management, and modern application architectures.

β€’ Ability to effectively and safely utilize AI-assisted development and security tools.

β€’ Experience in vulnerability triage and validation, assessing exploitability, business impact, severity, compensating controls, and providing remediation guidance.

β€’ Experience in developing security metrics, coverage reports, and executive dashboards.

β€’ Exceptional communication, stakeholder management, presentation, and documentation abilities.

β€’ Capacity to work independently across multiple applications, teams, portfolios, and technology stacks.

β€’ Strong problem-solving skills that balance security, usability, operational impact, and business goals.

β€’ Ability to collaborate with and influence architects, developers, DevOps, product owners, and business stakeholders.

β€’ Capacity to coach colleagues and share knowledge effectively.

β€’ Comfort in operating within Scrum/Agile delivery frameworks and managing personal work items.


🏝️ Benefits

β€’ Contract engagement with an estimated duration of 12+ months.

People also viewed

ExactCare2 days ago

Application Support Engineer – Clinical

US flagOhio OnlyFull-timeApplication Engineer
ApplyView job
Devexperts3 days ago

Application Support Engineer, Level 1

BR flagBrazil OnlyFull-timeApplication Engineer
ApplyView job
Copeland3 days ago

Applications Engineer

CO flagColombia OnlyFull-timeApplication Engineer
ApplyView job
Motive3 days ago

Site Reliability Engineer – Application Development, Kubernetes, Linux

US flagTexas OnlyFull-timeApplication Engineer$80k – $90k/year
ApplyView job
Intel Corporation3 days ago

Sales Application Engineer

CA flagCanada OnlyFull-timeApplication EngineerC$251.6k – C$355.2k/year
ApplyView job
Zact3 days ago

Senior Application Support Engineer – India

IN flagIndia OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers