Application Security Automation Engineer - New York, NY - Locals Only
Steneral Consulting · New York, NY · 2 wk ago
On-siteInformation TechnologyContract
About the role
Develop and maintain automated systems to scan GitHub and Artifactory repositories for security vulnerabilities and end-of-life (EOL) libraries. Utilize AI-driven automation to remediate vulnerabilities, reducing manual triage and patching time across the organization.
Responsibilities
- Design and implement solutions using strong Python programming skills, with Bash scripting for CI/CD integration.
- Work extensively with source and artifact management systems, including GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray, supporting multi-repo and multi-language environments.
- Integrate and operate scanning tools such as Snyk, Xray, CodeQL, Dependabot, Trivy, or Semgrep; analyze CVE/CVSS scores and EOL-detection sources.
- Build and manage agentic workflows using LLM-based AI to interpret scan findings, generate and test patch pull requests, and summarize remediation actions.
- Implement and maintain CI/CD pipelines (GitHub Actions, Jenkins) and use Docker for isolated testing of fixes; manage scheduling with Airflow or cron.
- Structure and report vulnerability findings (in JSON/SQL) into dashboards for monitoring coverage and trends.