Senior Application Security Engineer DevSecOps and CICD

Posted 3 Days Ago
Hiring Remotely in Austin, TX, USA
In-Office or Remote
Senior level
Information Technology • Consulting
The Role
Embeds application security into the SDLC through DevSecOps processes, security assessments, repository scanning, vulnerability triage, remediation validation, and secure code review. Uses tools such as Burp Suite, CodeQL, SAST, SCA, and secret scanning across applications, APIs, cloud workloads, and infrastructure. Develops security metrics and executive dashboards, coaches development teams, participates in Agile ceremonies, and promotes secure coding and responsible AI-assisted security practices.
Summary Generated by Built In

This is a remote position.

Job Title: Senior Application Security Engineer DevSecOps and CICD

Location: Remote, USA

Estimated Duration :12+ Months 

Must Have Skills/Attributes: Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability

Experience Desired: Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs); Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)

Required Minimum Education: Bachelor’s Degree

Preferred Education: Master’s Degree

Job Description

  • ***Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***

Education Requirements:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Preferred Education:

  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Required Skills for the Cybersecurity Engineer:

  • -5-7 years of hands-on application security/DevSecOps experience
  • - Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
  • - Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
  • - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
  • - Cloud security, identity and access management, and modern application architectures
  • - Safe and effective use of AI-assisted development and security tools
  • - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
  • - Security metrics, coverage reporting, and executive dashboard development
  • - Excellent communication, stakeholder management, presentation, and documentation skills
  • - Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
  • - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
  • - Coaching and knowledge sharing — champions a security-first culture
  • - Comfortable operating within Scrum/Agile delivery and managing own work items

Cybersecurity Engineer Responsibilities:

  • - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
  • - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
  • - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
  • - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
  • - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
  • - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes

 

Typical task breakdown:

  • Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
  • Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
  • Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
  • Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
  • Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
  • Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
  • Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks find value in our e-mail notifications as you continue to consider options for your professional career.


Skills Required

  • 5–7 years of hands-on application security and DevSecOps experience
  • Strong understanding of Secure SDLC, DevSecOps, Agile, and Scrum methodologies
  • 5–7 years of experience with security tooling
  • Experience with Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • Ability to read, analyze, test, and modify production application code in Java and Python
  • Knowledge of OWASP Top 10, API Security Top 10, authentication and authorization controls, secure coding principles, and common attack techniques
  • Knowledge of cloud security, identity and access management, and modern application architectures
  • Experience with vulnerability triage, exploitability validation, business impact assessment, severity analysis, compensating controls, and remediation guidance
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field
  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field
  • Excellent communication, stakeholder management, presentation, and documentation skills
  • Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • Ability to collaborate with architects, developers, DevOps, product owners, and business stakeholders
  • Ability to coach teams and promote a security-first culture
  • Must be located in Irving, Texas; Chicago, Illinois; Peoria, Illinois; or Broomfield, Colorado
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
433 Employees
Year Founded: 2004

What We Do

Established in 2004, 3Core System is a certified small minority owned business providing ERP Systems Integration, AMS, IT Consulting and Staff Augmentation Services to Fortune 1000, SMB, and State, Local and Education (SLED) customers. While our System Integration services help organizations achieve digital and cloud transformation objectives, AMS Services help increase the availability of critical services of end user applications. On the other hand, our IT Consulting Services would provide subject matter experts to help you assist with specific project needs and the Staff Augmentation services help you balance workload and achieve budget parameters. >ERP System Integration Services: 3Core Systems is an SAP Silver Partner and authorized service provider offering technical architecture, application design and configuration, integration, testing, data migration and solution adoption services for solutions including SAP SuccessFactors, SAP HCM On-Premises and SAP Business Intelligence >Application Management Services (AMS): We offer post go-live, System Health Check and Optimization, Function Enhancements, Integration Monitoring, Release, and patch services. Our AMS services span across SAP Solutions including ERP (S/4 HANA), Financial Management, Human Capital Management, Data and Analytics, Supply Chain, CRM, and Customer Experince. >IT Consulting and Staffing Augmentation Services: Ever since its inception, 3Core Systems has been offering IT Consulting and Staff Augmentation solutions including temporary, long-term, project based and contract staffing services that could be personalized based on your needs. Our staffing services span across emerging technologies and legacy solutions including but not limited to Artificial Intelligence, Machine Learning, Data Science, Cloud, ERP, CRM, BI/BW/ETL, Database, Web & E-Commerce, UI/UX, Network & Security and Mobile.

Similar Jobs

Coinbase Logo Coinbase

Staff Software Engineer

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Easy Apply
Remote
USA
4700 Employees
263K-309K Annually

Coinbase Logo Coinbase

Data Engineer

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Easy Apply
Remote
USA
4700 Employees
191K-225K Annually

Coinbase Logo Coinbase

Senior Network Engineer

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Easy Apply
Remote
USA
4700 Employees
186K-219K Annually

Qualtrics Logo Qualtrics

Enterprise Account Executive

Artificial Intelligence • HR Tech • Information Technology • Software • Business Intelligence
Remote
United States
5000 Employees
121K-208K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account