Remote job
Application Security Engineer - Northeast region
Job details
About this role
Role overview An Application Security Engineer position supporting a regional AppSec practice that helps organizations secure how they build and deliver software. The role centers on deploying and tuning application security tooling, embedding automated security testing into development pipelines, and advising engineering teams on secure development practices across the software lifecycle. It is a consultative, client-facing engineering role with up to 10% travel.
Responsibilities - Implement, operationalize, and troubleshoot SAST platforms (such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode) inside client environments. - Design and integrate automated security testing into CI/CD pipelines using GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI. - Author and adapt custom SAST rules, then triage, validate, and guide remediation of identified vulnerabilities. - Advise client development teams on OWASP Top 10, threat modeling, and secure coding practices throughout the SDLC. - Leverage AI-assisted tooling to accelerate rule development, triage, and remediation guidance. - Contribute to reusable pipeline patterns, rule libraries, and delivery accelerators for the broader AppSec practice.
Requirements - Proficiency implementing, operationalizing, and troubleshooting SAST tools across major vendors. - Solid understanding of CI/CD pipeline tools and processes, including build and deployment automation. - Software engineering background, ideally full stack, with experience building and operating security tooling inside pipelines. - Practical experience with proactive integration of security into the development process. - Prior work as an application security practitioner or software engineer.
Benefits and work setup - Primarily remote U.S.-based workforce with occasional on-site presence as needed. - Group medical insurance options (PPO with low deductible or high-deductible HSA plan) with employer premium contributions. - Group dental insurance, twelve corporate holidays, and a flexible time off program. - Mobile phone and home internet allowance, retirement plan eligibility, and a pet benefit option.