Application Security (AppSec) Engineer - W2 Only
Saransh Inc · Maryland Heights, MO · Yesterday
On-siteInformation TechnologyContract
About the Role
This role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity. The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures.
Responsibilities
- Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
- Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
- Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
- Enable continuous post-deployment security validation and risk monitoring.
- Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
- Perform authenticated and unauthenticated security assessments of applications and APIs.
- Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
- Validate remediation effectiveness and secure deployment practices.
- Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
- Automate vulnerability triage, prioritization, and remediation workflows.
- Develop security-as-code controls and policy enforcement mechanisms.
- Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
- Analyze findings from multiple security tools and eliminate false positives.
- Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
- Track remediation efforts through SDLC and release cycles.
- Develop security metrics, dashboards, and executive reporting.
- Conduct secure coding reviews and developer education sessions.
- Establish security champions programs across engineering teams.
- Provide remediation guidance and hands-on support during application releases.
- Drive adoption of secure development standards and best practices.
- Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
- Secure REST, GraphQL, and microservice-based APIs.
- Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
- Support software supply chain security initiatives, including SBOM/SCA validation.
Requirements
- 8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
- Experience securing large-scale enterprise applications across cloud and hybrid environments.
Preferred Qualifications
- CISSP
- CSSLP
- GWAPT
- OSCP
- CEH
- Azure/AWS Security Certifications
Top Skills
- Application Security (AppSec)
- Secure SDLC / DevSecOps
- SAST, DAST, IAST, SCA
- Web, Mobile & API Security Testing
- Manual Penetration Testing & Business Logic Testing
- Threat Modelling
- Vulnerability Management
- Secure Code Review
- CI/CD Security Integration