
Application Security Engineer - North Central region
GuidePoint Security12 hours ago
Remote, United StatesEntry Level / Mid Level
H1B sponsor
Responsibilities
- Run and tune SAST, DAST, SCA, secrets, and IaC scanning tools; triage findings, remove false positives, and provide prioritized remediation guidance.
- Design and implement security integrations across CI/CD pipelines, source control, IDEs, and ticketing systems, including policy gates and break-the-build criteria.
- Partner with development teams on remediation, secure coding, and developer enablement throughout the SDLC.
- Assess and harden software supply chain controls, including SBOM generation, dependency and container scanning, artifact signing, and pipeline security.
- Perform threat modeling and security architecture reviews for cloud-native, microservice, container, and IaC environments.
- Use AI-assisted and agentic tooling to accelerate security testing, triage, reporting, and remediation, and advise clients on secure AI coding-assistant adoption.
- Help clients mature AppSec programs through metrics, vulnerability-management SLAs, and roadmaps aligned with established security frameworks.
- Produce client-ready deliverables, present findings to technical and executive audiences, and contribute to AppSec practice growth through tooling, methodologies, and knowledge sharing.
Requirements
- 1–3+ years of experience in Application Security, DevSecOps, or software development with a security focus.
- Hands-on experience with SAST, DAST, and SCA tools and their integration into CI/CD pipelines.
- Proficiency with Burp Suite Pro and strong knowledge of the OWASP Top 10 and OWASP API Security Top 10.
- Strong knowledge of secure development lifecycles and experience guiding remediation of application vulnerabilities.
- Ability to review source code in one or more of JavaScript/TypeScript, Python, Java, C#, Go, PHP, or C/C++.
- Working knowledge of AWS, Azure, or GCP, containers, and Git-based development workflows.
- Preferred experience with Invicti, Checkmarx, Snyk, Veracode, Black Duck, Semgrep, or GitHub Advanced Security.
- Preferred experience building agentic AI workflows or automation with Python, Bash, or PowerShell.
- Preferred experience with SBOM, SLSA, Sigstore, IaC/container scanning, threat modeling, and AppSec maturity frameworks.
- Preferred familiarity with Checkov, Trivy, Wiz, STRIDE, OWASP SAMM, BSIMM, and NIST SSDF.
- Industry certifications such as GWAPT, OSWE, OSCP, CSSLP, Certified DevSecOps Professional, or AWS Certified Security – Specialty are preferred.
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- Strong written and verbal communication skills for explaining complex issues to technical and executive audiences.
Benefits
- Primarily remote, U.S.-based work; some travel may be required and Federal positions may require on-site work.
- Up to 10% travel.
- Medical insurance options, including a zero-deductible PPO and a high-deductible plan with HSA contributions.
- Dental insurance with GuidePoint covering 100% of employee premiums and 75% of family-plan premiums.
- 12 corporate holidays and a Flexible Time Off program.
- Mobile phone and home internet allowance.
- Retirement plan eligibility after two months at open enrollment.
- Pet benefit option.
Tech Stack
AWSAzureBambooBashC#C++DockerGitGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaJavaScriptJenkinsKubernetesPHPPowerShellPythonTerraformTypeScript
Categories
About GuidePoint Security
GuidePoint Security provides cybersecurity consulting, managed services, and value-added reselling/integration of security products for enterprises and U.S. public-sector agencies. Its teams deliver assessments, penetration testing, cloud and application security, identity and access management, endpoint and network protection, and governance services. Founded in 2011 and headquartered in Reston, Virginia, the privately held company serves Fortune 500 organizations and cabinet-level federal agencies.