Role Description
We are seeking a Senior Application Security Engineer / DevSecOps Engineer to support and strengthen the execution of our Application Security Program. The ideal candidate will have strong hands-on experience integrating application security practices into the software development lifecycle, working closely with development teams, and implementing security controls within CI/CD pipelines. This is a hands-on role focused on application security testing, vulnerability analysis and remediation, DevSecOps integration, and collaboration with application development teams.
Key Responsibilities
-
Configure, execute, monitor, administer, and troubleshoot application security platforms (SAST, DAST, and SCA), including working with vendors to resolve platform issues and manage support tickets.
-
Analyze and manage application security vulnerabilities, including false positives, identifying duplicates, assessing exploitability, and assist with prioritization, remediation, vulnerability exception documentation, and risk assessment.
-
Provide developers with actionable remediation guidance and support the verification of implemented fixes.
-
Build, integrate, maintain, and report on application security controls and activities, GitLab and Jenkins CI/CD pipelines/integrations, security metrics, vulnerability dashboards, weekly status reporting, and monthly management reporting.
-
Support the implementation and improvement of Secure Software Development Lifecycle (Secure SDLC) practices.
-
Collaborate closely with software development teams to identify and remediate application security vulnerabilities, support secure coding practices, validate implemented fixes, and facilitate vulnerability closure.
-
Support and engage with Security Champions across application development teams.
-
Maintain accurate vulnerability records, remediation status, supporting evidence, and risk or exception information. Prepare application security reports, metrics, and status updates for technical and business stakeholders.
-
Help identify opportunities to automate and improve application security processes.
-
Work with security and engineering teams to ensure security requirements are incorporated throughout the development lifecycle.
Qualifications
-
5+ years of experience in Application Security, Product Security, DevSecOps, or a related cybersecurity discipline.
-
Hands-on experience configuring, operating, and troubleshooting SAST, DAST, and SCA tools and methodologies.
-
Strong understanding of application vulnerabilities, vulnerability assessment, prioritization, and remediation.
-
Hands-on experience integrating security tools into GitLab CI/CD pipelines.
-
Strong understanding of DevSecOps principles and Secure SDLC practices.
-
Experience working directly with software developers and engineering teams.
-
Knowledge of OWASP Top 10 and common web application security vulnerabilities.
-
Experience with application security reporting and vulnerability/remediation tracking.
-
Strong communication and collaboration skills.
Preferred Qualifications
-
Experience implementing or supporting a Security Champions Program.
-
Experience with Veracode and GitLab security capabilities and application security pipeline controls.
-
Experience using APIs and scripting languages such as Python, PowerShell, Bash, or similar technologies to automate security processes.
-
Familiarity with cloud environments such as AWS.
-
Familiarity with container security, Infrastructure as Code scanning, secrets detection, and API security testing.
-
Relevant cybersecurity certifications such as GWAPT, GWEB, OSCP, CSSLP, Security+, or equivalent experience.
Technical Skills
-
Application Security
-
SAST
-
DAST
-
SCA
-
OWASP Top 10
-
Vulnerability Management
-
Secure Coding
-
Secure SDLC
-
DevSecOps
-
GitLab
-
GitLab CI/CD
-
CI/CD Security Integration
-
Security Automation
-
DevSecOps Practices
Location
Remote (LATAM closed to AST)
Engagement
6-Month Contract (Renewable)
Position
2
Languages
Fully Bilingual (Spanish/English)