Application Security Automation Engineer
Experis · New York, NY · Today
On-siteInformation TechnologyContract
About the role
Our client, a leading organization in the technology and security sector, is seeking a passionate and skilled Application Security Automation Engineer to join their dynamic team. The role is based in New York, NY with a hybrid work arrangement.
Responsibilities
- Develop and operate systems that scan repositories for vulnerabilities and outdated libraries, utilizing AI-driven automation to streamline remediation processes.
- Integrate security scanning tools such as Snyk, Xray, CodeQL, Dependabot, Trivy, or Semgrep into CI/CD pipelines to ensure continuous security monitoring.
- Build agentic workflows that interpret findings, generate patch pull requests, run tests, and summarize fixes using large language models (LLMs).
- Collaborate with development teams to embed security automation into existing workflows, ensuring minimal manual intervention.
- Create dashboards and reports to visualize vulnerability trends, coverage, and remediation effectiveness for leadership and technical teams.
Requirements
- 7+ years of experience in application security, automation, or related fields.
- Proficiency in Python programming, with experience in scripting and API integration; basic Bash scripting for CI/CD workflows.
- Hands-on experience with source and artifact management systems such as GitHub and JFrog Artifactory/Xray.
- Familiarity with security scanning tools like Snyk, Xray, CodeQL, Dependabot, Trivy, or Semgrep, and understanding of CVE/CVSS scoring and EOL sources.
- Experience in building AI-driven workflows for vulnerability remediation, including prompt engineering for code-editing agents.
Benefits
- Opportunity to work on cutting-edge security automation projects that impact the entire organization.
- Collaborate with a talented and innovative team committed to continuous learning and improvement.
- Engage in a hybrid work environment that promotes work-life balance and flexibility.
- Contribute to a culture that values diversity, inclusion, and professional growth.
- Be part of a forward-thinking organization dedicated to leveraging technology for security excellence.