Jobs · Information Technology · Missouri

Application Security (AppSec) Engineer - W2 Only

Saransh Inc · Maryland Heights, MO · Yesterday
On-siteInformation TechnologyContract

About the Role

This role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity. The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures.

Responsibilities

  • Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
  • Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
  • Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
  • Enable continuous post-deployment security validation and risk monitoring.
  • Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
  • Perform authenticated and unauthenticated security assessments of applications and APIs.
  • Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
  • Validate remediation effectiveness and secure deployment practices.
  • Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
  • Automate vulnerability triage, prioritization, and remediation workflows.
  • Develop security-as-code controls and policy enforcement mechanisms.
  • Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
  • Analyze findings from multiple security tools and eliminate false positives.
  • Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
  • Track remediation efforts through SDLC and release cycles.
  • Develop security metrics, dashboards, and executive reporting.
  • Conduct secure coding reviews and developer education sessions.
  • Establish security champions programs across engineering teams.
  • Provide remediation guidance and hands-on support during application releases.
  • Drive adoption of secure development standards and best practices.
  • Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
  • Secure REST, GraphQL, and microservice-based APIs.
  • Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
  • Support software supply chain security initiatives, including SBOM/SCA validation.

Requirements

  • 8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
  • Experience securing large-scale enterprise applications across cloud and hybrid environments.

Preferred Qualifications

  • CISSP
  • CSSLP
  • GWAPT
  • OSCP
  • CEH
  • Azure/AWS Security Certifications

Top Skills

  • Application Security (AppSec)
  • Secure SDLC / DevSecOps
  • SAST, DAST, IAST, SCA
  • Web, Mobile & API Security Testing
  • Manual Penetration Testing & Business Logic Testing
  • Threat Modelling
  • Vulnerability Management
  • Secure Code Review
  • CI/CD Security Integration

Similar jobs

Application Engineer 2

Central States Industrial (CSI)Springfield, MO· 2 mo ago
Information Technology$29–$42/hrapply on csidesigns.clearcompany.com