Job Title : Senior Application Security Auditor (DevSecOps)Position Overview Help shape secure software development by partnering directly with engineering teams to identify vulnerabilities, improve secure coding practices, and strengthen application security across web, API, cloud, and distributed platforms. This role focuses on proactive application security and continuous compliance rather than Security Operations Center activities.
What You'll Do - Perform Dynamic, Static, and Software Composition Analysis (DAST, SAST, SCA) assessments
- Collaborate with front-end, back-end, and cloud development teams on secure coding practices
- Identify and explain application security vulnerabilities, including OWASP Top 10 risks
- Support secure API design, authentication, authorization, and web security practices
- Help implement security patterns, automation, and compliance within DevSecOps processes
- Contribute to the maturity of secure software development practices across distributed teams
Required Qualifications - 5+ years of total IT experience
- 3+ years implementing secure coding practices using Federal, industry, or open-source security guidance (OWASP, SANS, CERT, CWE, Critical Security Controls, Cloud Security Alliance, SafeCode, etc.)
- 3+ years of experience with application security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud)
- 3+ years working with modern application development technologies including compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere, Oracle JBoss, or .NET
- 3+ years of experience in networking, infrastructure, secure application development, and DevSecOps security automation
- 3+ years of hands-on experience building and deploying secure distributed web and mobile applications
- Strong understanding of HTTP request/response headers, REST APIs, API security, JWT, OAuth/OIDC/PKCE, replay attacks, and common web application vulnerabilities
- Ability to pass a CJIS background check
Preferred Qualifications - Experience with Coverity, BlackDuck, Fortify, or SRM
- Cloud development experience with Azure, AWS, or GCP
#LI-NC1 #ApplicationSecurity #DevSecOps #SecurityEngineer #SecureCoding #OWASP #CyberSecurityJobs #APISecurity