All Jobs Vacancy

Senior Application Security Engineer DevSecOps and CICD

Posted 2 days ago by 3Core Systems, Inc

Job Title: Senior Application Security Engineer DevSecOps and CICD

Location: Remote, USA

Estimated Duration (In Months): 13

Must Have Skills/Attributes

Agile

API

Artificial Intelligence (AI)

Cloud

SDLC

Security

Vulnerability

Experience Desired

Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs)

Security tooling (5-7 yrs)

OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)

Required Minimum Education: Bachelor’s Degree

Preferred Education: Master’s Degree

Job Description

  • Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO

Education Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Preferred Education

  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Required Skills for the Cybersecurity Engineer

  • 5-7 years of hands-on application security/DevSecOps experience
  • Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
  • Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
  • OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
  • Cloud security, identity and access management, and modern application architectures
  • Safe and effective use of AI-assisted development and security tools
  • Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
  • Security metrics, coverage reporting, and executive dashboard development
  • Excellent communication, stakeholder management, presentation, and documentation skills
  • Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
  • Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
  • Coaching and knowledge sharing — champions a security-first culture
  • Comfortable operating within Scrum/Agile delivery and managing own work items

Cybersecurity Engineer Responsibilities

  • Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
  • Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
  • Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
  • Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
  • Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
  • Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes

Typical task breakdown

  • Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
  • Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
  • Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
  • Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
  • Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
  • Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
  • Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks
Rate:
Not specified
Location:
United States
IR35 Status:
Outside
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job