Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH
Job Summary
We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.
Key Responsibilities
Design and integrate automated security testing gates directly into modern CI/CD pipelines (e.g., , , ).
Triage and remediate software vulnerabilities , analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
Govern application security infrastructure , managing centralized vulnerability aggregation dashboards (e.g., , ) and secret vaults (e.g., , ).
Secure containerized application workloads , auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
Drive application layer incident investigations , analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.
Requirements
4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
Strong technical mastery of automated testing engines (e.g., , , Veracode, ), container security paradigms, and infrastructure-as-code hardening.
Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
Mandatory certification: CASE, CDP, CSSLP, or CEH.
Preferred Qualifications
Prior experience with software development in languages like Java, Python, JavaScript/Node.js, or Go .
Job Description:We are looking for a DevSecOps Engineer to strengthen application security across our SaaS platform. This is a senior individual contributor role responsible for designing, implementing, and continuously improving DevSecOps practices across engineering teams and business https://jobeax.com/link/lAC4AGVrlIyfnkFI ...
... project requirements. About the Role We’re looking for Application Security Engineers (AppSec) with strong backend engineering experience and practical cybersecurity knowledge to help evaluate and improve next-generation AI systems. You’ll create realistic, challenging software engineering tasks involving feature implementation, ...
... player-facing applications. This role is well suited to experienced security professionals with strong knowledge of secure coding practices, web, mobile, and API security, and modern DevSecOps tooling. The engineer partners with development teams to identify and remediate vulnerabilities, integrate security testing into CI/CD ...
... https://jobeax.com/link/ASqzekG1uKfCw5VF Role & Impact : We are seeking a meticulous and proactive Application Security (AppSec) Engineer to take charge of our security posture across our fintech and logistics platforms. You will work hand-in-hand with our software engineering, DevOps, and product squads to embed security best ...
... brands, financial institutions, exchanges, and platforms, and millions of investors worldwide. For more information, visit . We are looking for a versatile Application Security Engineer to join the team to continue to mature the application security practices at BitGo. This exciting opportunity empowers you to ensure vulnerabilities ...
... with Engineering, Product, IT, and Security teams to improve secure-by-design practices and reduce software risk over time. - Provide limited support to SOC/security operations when application-related alerts, incidents, or evidence require AppSec input, context, or follow-up. Technologies and platforms you may work with ...
... Contributing to automation of active scans that can detect security lapses in infra.- Scoping activities of functional security assignments from product and engineering teams.- Improving security operations by enhancing use cases, processes, and/or code structure.- Enforcing secure coding practices via DevSecOps and bringing ...
Role : Senior Security Engineer - Application & Data SecurityJob Summary : The Senior Security Engineer will be responsible for the day-to-day operations and maintenance of the organisation's security posture. The role will focus on strengthening security controls, ensuring the effectiveness of security systems, and collaborating ...