GuidePoint Security

Application Security Engineer - Northeast region

GuidePoint Security
Apply
4 days ago
Remote, United StatesMid Level
H1B sponsor

Responsibilities

  • Implement, operationalize, troubleshoot, and tune SAST platforms in client environments.
  • Integrate automated security testing and security controls into CI/CD pipelines.
  • Author and adapt custom SAST rules, triage and validate vulnerabilities, and guide remediation.
  • Advise development teams on OWASP Top 10, threat modeling, secure coding, and SDLC practices.
  • Use AI-assisted tooling to accelerate rule development, vulnerability triage, and remediation guidance.
  • Build reusable pipeline patterns, rule libraries, and delivery accelerators for the Application Security practice.
  • Deliver client engagements across the Northeast and Mid-Atlantic region, with occasional on-site presence.

Requirements

  • Experience implementing, operationalizing, and troubleshooting SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode.
  • Understanding of CI/CD pipeline tools and processes, including GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI.
  • Experience in software engineering, ideally full-stack development, with modern technologies and application architectures.
  • Strong scripting and automation experience using one or more programming languages.
  • Working knowledge of application security fundamentals, OWASP Top 10, threat modeling, and secure coding across the SDLC.
  • Experience writing or adapting custom SAST rules using Semgrep or CodeQL is preferred.
  • Familiarity with IAST, DAST, SCA, API security tools, and secure development lifecycle practices is preferred.
  • Experience validating vulnerabilities and proficiency with Burp Suite is preferred.
  • Experience building and operating security tools in CI/CD pipelines and integrating security into development processes is preferred.
  • Excellent written and verbal communication skills and the ability to work with emerging AI tools.

Benefits

  • Remote-first U.S.-based workforce, with some travel and possible on-site work for certain positions.
  • Up to 10% travel may be required.
  • Medical insurance options, including PPO and high-deductible HSA plans, with employer premium contributions.
  • Dental insurance with employer premium contributions.
  • Twelve corporate holidays and a Flexible Time Off program.
  • Mobile phone and home internet allowance.
  • Retirement plan eligibility after two months at open enrollment.
  • Pet benefit option.

Tech Stack

CircleCIGitHub ActionsJenkins

Categories

GuidePoint Security

About GuidePoint Security

1,001-5,000 employees

GuidePoint Security provides cybersecurity consulting, managed services, and value-added reselling/integration of security products for enterprises and U.S. public-sector agencies. Its teams deliver assessments, penetration testing, cloud and application security, identity and access management, endpoint and network protection, and governance services. Founded in 2011 and headquartered in Reston, Virginia, the privately held company serves Fortune 500 organizations and cabinet-level federal agencies.

Contact me