Conviso Inc. · 13 hours ago
Application Security Tooling Administrator
Conviso Inc is looking to hire an Application Security Tooling Administrator. The role involves owning and operating various security tools, integrating them into CI/CD processes, and collaborating with engineering teams on secure coding practices.
Responsibilities
Own and operate Sonatype, Fortify, StackRox (ACS), and Burp in on-prem/cloud (OCI preferred)
Integrate security tools into CI/CD with policy gates and secure-by-default workflows
Tune policies, reduce false positives, and run auditable vulnerability management
Partner with engineering on remediation, retesting, and secure coding guidance
Lead container/Kubernetes security and incident-ready detections
Deliver metrics, dashboards, and RMF/ATO audit support
Qualification
Required
Certification Requirement: DoD 8570 IAT II (i.e. Security+)
Active Secret clearance needed
3+ years in application security engineering and/or DevSecOps in regulated environments
Hands-on admin experience in pipeline integration with Sonatype, Fortify, StackRox/ACS, and Burp
Strong CI/CD automation and DevSecOps experience
Solid knowledge of Secure SDLC, OWASP Top 10, SBOM, containers/K8s, Linux, networking, and TLS
Experience with common build systems (Maven, .NET, npm, pip) and Oracle Cloud Infrastructure
Relevant certifications (one or more): Security+, CISSP, CSSLP, GIAC, Kubernetes security certs
Benefits
401K
Some accrued PTO
Company
Conviso Inc.
At Conviso, we empower both government and commercial clients by delivering tailored professional services that drive success and help them overcome unique business challenges.