Remote job
Application Security Engineer - North Central region
Job details
About this role
Role overview This is a remote, client-facing application security engineering role supporting a regional AppSec practice. The engineer helps organizations build, scale, and mature secure software development programs across cloud-native and AI-enabled systems, embedding security into engineering workflows without slowing delivery.
Responsibilities - Configure and tune SAST, DAST, SCA, secrets, and IaC scanning tools, triaging findings and delivering actionable remediation guidance - Integrate security tooling into CI/CD pipelines (GitHub Actions, GitLab CI, Azure DevOps, Jenkins), source control, IDEs, and ticketing systems, including policy gates and break-the-build criteria - Partner with development teams on remediation, secure coding guidance, and developer enablement throughout the SDLC - Harden software supply chain controls, including SBOM generation, dependency and container image scanning, artifact signing, and pipeline/runner security - Conduct threat modeling and security architecture reviews for cloud-native, microservice, container, and Infrastructure-as-Code environments - Leverage AI-assisted and agentic tooling to accelerate testing and reporting, and advise on the secure adoption of AI coding assistants - Help clients mature AppSec programs by defining metrics, vulnerability SLAs, and roadmaps aligned to frameworks such as OWASP SAMM, BSIMM, and NIST SSDF - Produce client-ready deliverables and present findings to technical and executive audiences
Requirements - 1–3+ years in Application Security, DevSecOps, or software development with a security focus - Hands-on experience with SAST, DAST, and SCA tools and their integration into CI/CD pipelines - Proficiency with manual testing tools such as Burp Suite Pro and a strong understanding of the OWASP Top 10 - Familiarity with SAMM, BSIMM, or NIST SSDF frameworks - Industry certifications such as GWAPT, OSWE, OSCP, CSSLP, Certified DevSecOps Professional (CDP), or AWS Certified Security – Specialty - Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience
Nice to have - Experience securing AI/LLM applications and agentic workflows against emerging threats - Comfort with AI-assisted tooling for code review, automated triage, or auto-remediation workflows
Benefits and work setup - Primarily remote (U.S. based), with up to 10% travel - Group medical insurance options including PPO and high-deductible HSA plans, with employer contributions toward premiums and HSA funding - Group dental insurance with employer-covered premiums - 12 corporate holidays and a flexible time off program - Mobile phone and home internet allowance - Retirement plan eligibility after two months - Pet benefit option