Application Security Engineer / DevSecOps Engineer

Saicon — United States · Posted ~4 hours ago

Senior

Skills

Application security API security AWS security Vulnerability assessment Vulnerability validation Penetration testing Risk assessment Security remediation Web application security AWS Web applications Vulnerability scanners DevSecOps

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A technology organization is seeking an experienced Application Security Engineer to strengthen security across a broad portfolio of web applications and APIs. You will investigate scanner and penetration-testing findings, reproduce vulnerabilities, assess exploitability and business impact, and guide engineering teams through remediation. Strong AWS security expertise is required, with the role emphasizing application and API security rather than traditional infrastructure operations.

Highlights

Hands-on security engineering role with a strong focus on meaningful vulnerability analysis and remediation. Work closely with developers, assess real-world exploitability and business risk, and improve security across web applications, APIs, and cloud environments with AWS expertise at the core.

Description

We are looking for an experienced Application Security Engineer to take a hands-on role in improving security across a broad portfolio of web applications and APIs. This person will partner closely with software engineering teams to identify security weaknesses, determine which issues present meaningful risk, and drive remediation through completion. The role requires someone who can go beyond automated scanner results. You should be comfortable investigating findings, reproducing vulnerabilities, assessing exploitability and business impact, and providing developers with practical guidance on how to resolve issues. Strong AWS security experience is required. This is primarily an application and API security position rather than a traditional infrastructure or DevOps role. ResponsibilitiesAssess security across web applications, APIs, and supporting cloud environments.Investigate and validate vulnerabilities identified through automated security tools, penetration testing, and internal assessments.Manually reproduce potential vulnerabilities to determine exploitability and eliminate false positives.Perform hands-on testing of APIs and applications, with particular attention to authentication, authorization, access controls, session management, injection, and business-logic weaknesses.Evaluate issues such as IDOR/BOLA, privilege escalation, authorization bypasses, and other OWASP-related vulnerabilities.Prioritize findings based on technical severity, exploitability, data exposure, and business impact.Partner with development teams to provide practical remediation guidance and verify that fixes fully address identified vulnerabilities.Conduct secure code reviews and participate in threat modeling for new applications, APIs, and features.Manage and improve SAST and DAST capabilities, including tool configuration, tuning, quality gates, and false-positive reduction.Incorporate application security testing into software development workflows and establish appropriate security gates.Assess application risks associated with AWS services and configurations, including IAM, S3, Lambda, API Gateway, secrets management, and WAF.Evaluate cloud-to-application attack paths and determine how AWS configurations may increase the impact of application vulnerabilities.Identify recurring vulnerability patterns and recommend broader engineering or architectural improvements.Track remediation progress and communicate vulnerability trends, risk, and security posture to engineering and security leadership.Continuously identify opportunities to improve application security processes, tooling, and standards.Required Qualifications5+ years of experience in application security, product security, penetration testing, vulnerability research, or a related security discipline.Strong hands-on experience assessing web applications and APIs.Deep understanding of the OWASP Top 10 and OWASP API Security Top 10.Experience manually validating vulnerabilities rather than relying solely on automated scanner results.Experience testing REST APIs; GraphQL security experience is beneficial.Hands-on experience with Burp Suite or similar manual application security testing tools.Experience operating and tuning SAST and DAST technologies.Ability to read and review application code in at least one modern programming language such as Java, Python, JavaScript/TypeScript, or Go.Strong working knowledge of AWS security, particularly IAM and application-related AWS services.Experience with vulnerability management and cloud/application security platforms.Ability to translate technical security findings into clear remediation recommendations.Strong communication skills and the ability to influence engineering teams when security changes are required.Preferred ExperienceExperience with Wiz, Qualys, Snyk, SonarQube, or comparable cloud security, vulnerability management, SAST, and DAST technologies is preferred. Devsecops - JD-silversearch Additional experience with security automation/SOAR, automated or AI-assisted security testing, custom application security rules, threat modeling, and offensive security testing is beneficial. Certifications focused on AWS security or offensive/application security are also a plus.