SYSTEMTEC · 7 hours ago
Application Security Engineer
SYSTEMTEC is seeking an Application Security Engineer for a Direct Hire opportunity for a mission-driven organization. This role focuses on integrating security into the development process, ensuring that applications are secure and resilient against vulnerabilities. The engineer will be responsible for implementing security testing, conducting threat modeling, and training developers on secure coding practices.
ConsultingInformation TechnologySoftware
Responsibilities
Integrate security testing (SAST, DAST, SCA) into CI/CD pipelines
Conduct threat modeling, design reviews, and architecture assessments
Perform code reviews for security flaws and penetration testing on web applications and APIs
Develop security patterns and tools that help developers build securely by default
Train developers on secure coding practices and OWASP Top 10
Secure containerized applications, Kubernetes deployments, and microservices across AWS/GCP
Implement secrets management, encryption strategies, and data protection controls
Investigate application-layer security incidents and implement preventative controls
Qualification
Required
4+ years in application security or similar role securing production applications
Deep understanding of OWASP Top 10 and common application vulnerabilities
Hands-on experience with SAST tools (Checkmarx, SonarQube, Fortify), DAST tools (Burp Suite, OWASP ZAP), and dependency scanning (Snyk, Dependabot)
Experience securing applications in AWS, GCP, or DigitalOcean
Working knowledge of Git, containerization (Docker/Kubernetes), and CI/CD pipelines (GitLab, GitHub Actions)
Understanding of API security, authentication/authorization patterns (OAuth, JWT), and API gateway configurations
Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience and certifications)
Preferred
Proficient in at least one programming language (Python, JavaScript, or PHP preferred)