Назад
Company hidden
10 дней назад

Application Security Engineer (SAST/DAST)

84 500 - 162 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (SAST/DAST): Implementing and administering application security testing and posture management tools, integrating them into CI/CD pipelines, and supporting development teams with vulnerability remediation. with an accent on secure coding, vulnerability triage, and application security tooling across cloud, container, and software development environments. Focus on consolidating findings, resolving false positives, automating DevSecOps workflows, and communicating technical risks to technical and non-technical stakeholders.

Location: North Chicago, Illinois, United States

Salary: $84,500–$162,000 per year

Company

hirify.global develops medicines and solutions for serious health issues across immunology, oncology, neuroscience, and aesthetics.

What you will do

  • Implement, administer, and maintain Application Security Testing tools, including SAST, DAST, IAST, and SCA.
  • Implement Application Security Posture Management tools to consolidate and deduplicate findings across security solutions.
  • Integrate application security tooling into CI/CD and DevSecOps pipelines.
  • Support developers by investigating false positives, advising on remediation, and evaluating security exceptions.
  • Produce reports on security findings and remediation progress, and communicate risks to technical and non-technical stakeholders.
  • Triage vulnerabilities at scale across application environments and business units while promoting secure development practices.

Requirements

  • Bachelor’s degree with 5 years of experience, or a master’s degree with 4 years of experience.
  • Experience in application security, software development, and administration of SAST, DAST, IAST, or SCA tooling.
  • Knowledge of secure coding practices across multiple programming languages, especially Java and Node.
  • Experience integrating security testing into CI/CD pipelines and applying OWASP Top 10, CWE, and related mitigations.
  • Ability to support developers, assess security findings, coach junior engineers, and communicate technical issues clearly.
  • Excellent written and oral English communication skills, demonstrated through presentations at scientific or technical conferences.

Nice to have

  • Experience with Snyk, Endor Labs, CSPM integration, and consolidation of application security findings.
  • Python or other programming and scripting experience for workflow automation.
  • Experience building logging into DevSecOps pipelines and collaborating with vulnerability and risk management teams.

Culture & Benefits

  • Paid vacation, holidays, and sick leave.
  • Medical, dental, and vision insurance for eligible employees.
  • 401(k) benefits for eligible employees.
  • Eligibility for short-term incentive programs.
  • Equal opportunity employment environment focused on integrity, innovation, and community impact.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →