Application Security Engineer

Posted 4 Days Ago
Be an Early Applicant
Rensselaer, NY, USA
In-Office
90K-110K Annually
Senior level
Information Technology • Professional Services • Cybersecurity • Defense
The Role
Work with development teams to identify, assess, and remediate application security vulnerabilities; perform risk-based assessments and penetration tests using static and dynamic tools; integrate security tooling (including AI-driven code analysis) into CI/CD; review commits/PRs and architecture changes; provide training and risk reporting; research new attack vectors and consult on secure designs.
Summary Generated by Built In

Location: Albany, NY
Security Clearance: No clearance needed
Job Type: Full-Time

Target Salary Range*: $90,000-110,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary

Position Overview:

Deliver simple solutions to complex problems as an Application Security Engineer. Your work will have you fully immersed in our client’s domain in order to deliver solutions for their complex needs. You’ll prioritize the client while we prioritize your career.

You will join our team in partnership with New York State of Health (NYSoH) to provide comprehensive health coverage to more than 7.2 million New Yorkers through its Health Benefit Exchange (HBE)

Key Responsibilities:
  • You’ll join our talented Development Team. Our project is built on a multi-tier architecture including Service Oriented architecture, multi-tier web applications using Java and various other COTS products.
  • Work closely with development teams to diagnose, document, and remediate application security vulnerabilities and identify appropriate security checkpoints in SDLC.
  • Perform risk-based, technical assessments/penetration tests of applications, using dynamic and static scanning tools, and audits ensuring compliance with industry standards
  • Consult with Development leadership on application development training.
  • Research new attack vectors and stay current with cybersecurity news and trends.
Qualifications:

Education: Bachelor’s degree in Computer Science, or related technical field, OR equivalent combination of education and experience

Required Experience:

  • 8+ years Information Technology.
  • Hands-on experience designing and executing a repeatable process to aggressively prioritize issue dispositions and remediations of security findings — while providing clear, concise status updates and risk reporting to leadership and stakeholders.
  • Hands-on experience integrating AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment.
  • Hands-on experience assessing new code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks.
  • 3+years with Application Security Engineering conducting assessments, penetration testing, implementing tools for dynamic /automated code review, dynamic and static application scanning (Fortify, SonarQube); consulting on security designs of applications, potential vulnerabilities, and remediation, and creating training materials on key security concepts.
  • Java/Web development with strong secure coding background in RHEL and JBoss.
  • 5+ years in software development role as a Developer, or Architect

Skills:

  • Strong oral and written communication skills, with a demonstrated ability to communicate complex topics to colleagues, and management.
  • Critical thinking and creative problem solving
  • Identify and resolve problems in a timely manner; gather and analyze information skillfully; develop alternative solutions.
  • Strong analytical skills.
  • Demonstrated collaboration and teaching abilities.
Preferred Qualifications:
  • CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications

Skills Required

  • Bachelor's degree in Computer Science or related field, or equivalent experience
  • 8+ years Information Technology experience
  • Hands-on experience designing and executing repeatable processes to prioritize and remediate security findings, with status and risk reporting to leadership
  • Hands-on experience integrating AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities before deployment
  • Hands-on experience assessing new code commits, pull requests, and architecture changes for vulnerabilities and misconfigurations
  • 3+ years Application Security Engineering experience conducting assessments, penetration testing, and implementing dynamic/automated code review and static/dynamic scanning (e.g., Fortify, SonarQube)
  • Java/web development experience with strong secure coding background in RHEL and JBoss
  • 5+ years in a software development role (Developer or Architect)
  • Strong oral and written communication skills
  • Critical thinking and creative problem solving
  • Ability to identify and resolve problems timely; gather and analyze information; develop alternative solutions
  • Strong analytical skills
  • Demonstrated collaboration and teaching/training abilities
  • CISSP, CEH, CISA, OSCP, OSCE, or OSWE Certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
200 Employees
Year Founded: 2011

What We Do

The Amatriot Group is a talent solutions firm providing technology expertise to the federal and commercial sectors. With over a decade of experience delivering mission-critical support to the intelligence, defense, and national security sectors, the company specializes in delivering cutting-edge technology solutions by securing top-tier talent to bridge workforce gaps in the most complex and secure environments.

Similar Jobs

Zeta Global Logo Zeta Global

Application Security Engineer

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
140K-180K Annually

Datadog Logo Datadog

Application Security Engineer

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
9 Locations
6500 Employees
244K-305K Annually

NBCUniversal Logo NBCUniversal

Application Security Engineer

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
120K-145K Annually

Beyond Finance Logo Beyond Finance

Application Security Engineer

Fintech • Financial Services
Easy Apply
Remote or Hybrid
United States
2200 Employees
140K-165K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account