GuidePoint Security

Application Security Engineer - Southeast region

GuidePoint Security
Apply
3 hours ago
Remote, United StatesSenior
H1B sponsor

Responsibilities

  • Implement, operationalize, troubleshoot, and tune SAST platforms in client environments.
  • Integrate automated security testing and security controls into CI/CD pipelines.
  • Author and adapt custom Semgrep and CodeQL rules; triage, validate, and guide remediation of vulnerabilities.
  • Advise development teams on OWASP Top 10, threat modeling, secure coding, and secure development lifecycle practices.
  • Use AI-assisted tooling to accelerate rule development, vulnerability triage, and remediation guidance.
  • Contribute reusable pipeline patterns, rule libraries, and delivery accelerators for the Application Security practice.
  • Deliver client engagements with occasional on-site presence and up to 10% travel.

Requirements

  • Experience implementing, operationalizing, and troubleshooting SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, and Veracode.
  • Understanding of CI/CD pipeline tools and processes, including GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, and CircleCI.
  • Software engineering experience, ideally including full-stack development and modern application architectures.
  • Strong scripting and automation experience using one or more programming languages.
  • Working knowledge of application security fundamentals, including OWASP Top 10, threat modeling, secure coding, and SDLC practices.
  • Strong written and verbal communication skills.
  • Preferred experience writing or adapting custom Semgrep or CodeQL rules.
  • Familiarity with IAST, DAST, API security, SCA, and API security tools such as NoName, Traceable, Salt, and Cequence.
  • Hands-on vulnerability validation and proficiency with Burp Suite.
  • Experience triaging and remediating technical vulnerabilities identified by web application scanning tools.
  • Past experience as an application security practitioner or software engineer.

Benefits

  • Primarily remote U.S.-based workforce; some travel and on-site work may be required for certain positions.
  • Group medical insurance options, including PPO and HDHP/HSA plans with employer premium contributions.
  • Group dental insurance with employer premium contributions.
  • Twelve corporate holidays and a Flexible Time Off program.
  • Mobile phone and home internet allowance.
  • Retirement plan eligibility after two months at open enrollment.
  • Pet benefit option.

Tech Stack

CircleCIGitHub ActionsJenkins

Categories

GuidePoint Security

About GuidePoint Security

1,001-5,000 employees

GuidePoint Security provides cybersecurity consulting, managed services, and value-added reselling/integration of security products for enterprises and U.S. public-sector agencies. Its teams deliver assessments, penetration testing, cloud and application security, identity and access management, endpoint and network protection, and governance services. Founded in 2011 and headquartered in Reston, Virginia, the privately held company serves Fortune 500 organizations and cabinet-level federal agencies.

Contact me