
Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)
GuidePoint Security3 months ago
Responsibilities
- Implement, operationalize, and troubleshoot SAST tools
- Build and operate security tools within CI/CD pipelines
- Write or adapt custom SAST rules and integrate automated security testing into development workflows
- Use scripting and automation to improve application security processes
- Validate vulnerabilities and triage and remediate findings from web application scanning tools
- Apply OWASP Top 10, threat modeling, secure coding, and secure SDLC practices
- Support proactive integration of application security into the software development process
Requirements
- Proficiency implementing, operationalizing, and troubleshooting SAST tools such as Semgrep, Snyk, CodeQL, Checkmarx, or Veracode
- Understanding of CI/CD pipeline tools and processes, including GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, or CircleCI
- Experience in software engineering, ideally full-stack software development, with modern technologies and application architectures
- Strong scripting and automation experience using one or more programming languages
- Knowledge of application security fundamentals, including the OWASP Top 10, threat modeling, and secure coding practices throughout the SDLC
- Excellent written and verbal communication skills
- Experience writing or adapting custom Semgrep or CodeQL SAST rules is preferred
- Familiarity with IAST, DAST, API security, and SCA tools is preferred
- Familiarity with API security tools such as NoName, Traceable, Salt, or Cequence is preferred
- Hands-on experience validating vulnerabilities and proficiency with Burp Suite is preferred
- Knowledge of secure development lifecycles and experience triaging and remediating vulnerabilities from web application scanning tools is preferred
- Experience building and operating security tools within CI/CD pipelines and proactively integrating security into development is preferred
- Past experience as an application security practitioner or software engineer is preferred
- Bachelor’s degree in a relevant discipline or equivalent experience
- 5–7 years of security engineering experience in the Information Security industry
Benefits
- Remote-first work arrangement for U.S.-based employees, with some travel or on-site work potentially required for certain positions
- Medical insurance options, including PPO and high-deductible health plans with employer premium contributions
- Dental insurance with employer premium contributions
- 12 corporate holidays and a Flexible Time Off program
- Mobile phone and home internet allowance
- Retirement plan eligibility after two months at open enrollment
- Pet benefit option
Tech Stack
CircleCIGitHub ActionsJenkins
Categories
About GuidePoint Security
GuidePoint Security provides cybersecurity consulting, managed services, and value-added reselling/integration of security products for enterprises and U.S. public-sector agencies. Its teams deliver assessments, penetration testing, cloud and application security, identity and access management, endpoint and network protection, and governance services. Founded in 2011 and headquartered in Reston, Virginia, the privately held company serves Fortune 500 organizations and cabinet-level federal agencies.