Function
Cloud & Data Engineering
Job descriptionApplication Security EngineerCompany: Hitachi Digital Services
Practice: HARC Security
Location: Dallas, TX (Onsite)
Experience: 2+ Years
Role OverviewHitachi Digital Services is seeking an Application Security Engineer to support application security, DevSecOps, secure software development, and AI-enabled security initiatives. The ideal candidate should have hands-on experience with application security testing, CI/CD security, vulnerability management, secure code reviews, and OWASP-based security practices.
Key Responsibilities- Perform application security assessments for web, API, cloud-native, and AI-enabled applications.
- Conduct secure code reviews and support vulnerability remediation efforts.
- Integrate security controls into CI/CD pipelines and DevSecOps workflows.
- Analyze findings from SAST, DAST, SCA, container security, and secret scanning tools.
- Participate in threat modeling and application security design reviews.
- Provide guidance on secure coding practices, OWASP Top 10, and OWASP API Security Top 10.
- Collaborate with development teams to improve security posture and adopt secure-by-design principles.
Required Skills- Minimum 2 years of experience in Application Security, DevSecOps, Secure Development, or Software Security.
- Strong understanding of:
- OWASP Top 10
- Secure SDLC
- Threat Modeling
- Secure Code Review
- API Security Fundamentals
- Familiarity with CI/CD platforms such as:
- Azure DevOps
- GitHub Actions
- Jenkins
- GitLab CI/CD
- Hands-on experience with one or more:
- SAST: Checkmarx, Veracode, Fortify, SonarQube
- DAST: Burp Suite, OWASP ZAP
- SCA: Snyk, Mend, Black Duck
- Knowledge of containers and Kubernetes security fundamentals.
- Basic scripting/programming skills (Python, PowerShell, JavaScript, Java, C#, etc.).
Preferred Qualifications- Experience with Azure and/or AWS cloud environments.
- Knowledge of DevSecOps automation and Infrastructure-as-Code security (Terraform, Bicep, ARM, CloudFormation).
- Experience securing containerized and cloud-native applications.
- Familiarity with AI-assisted development tools (GitHub Copilot, Amazon Q, Cursor, etc.).
- Understanding of AI/LLM security concepts, including prompt injection, sensitive data exposure, model misuse, and OWASP Top 10 for LLM Applications.
- Experience with vulnerability management and application security governance programs.
Preferred Certifications- Security+
- SSCP
- CySA+
- CEH
- CSSLP
- AZ-500
- AWS Certified Security 6 Specialty
- Relevant Application Security, DevSecOps, or Cloud Security certifications
Skills SummaryApplication Security 6 DevSecOps 6 Secure SDLC 6 OWASP Top 10 6 OWASP API Security Top 10 6 AI Security 6 Secure Code Review 6 Threat Modeling 6 SAST 6 DAST 6 SCA 6 CI/CD Security 6 Container Security 6 Kubernetes Security 6 Cloud Security (Azure/AWS) 6 Vulnerability Management 6 Security Automation
Job Level: P10
Focus Areas: Application Security, DevSecOps, AI Security, Secure SDLC, CI/CD Security, Vulnerability Management, Container & Kubernetes Security, Cloud Security (Azure/AWS).