Haystack
← Back to Jobs
Technology

Application Security Platform Engineer

PY DATA, INC.Dallas, TX🇺🇸United StatesPosted 31 Jul 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Application Security Platform Engineer

Hybrid Dallas, TX or Chicago, IL (2-3 days/week onsite)

6-12 months, Contract to Hire (CTH)

WORK TO BE PERFORMED:

Seeking an Application Security Platform Engineer with a strong development and automation background to support and augment our efforts in automating and scaling the process for identifying, assessing, and tracking vulnerabilities by leveraging reusable CI components. The engaged resource will be expected to gain a thorough understanding of the existing system architecture and integrations, while demonstrating a willingness to learn how Security vulnerability management tools operate and how reporting should be integrated into OCC's pipeline.

  • Develop custom Docker containers to pull results from vulnerability management tools, verify results using custom rules, and print results into report(s)
  • Package the application security assessment pipeline as a reusable CI component and a containerized scheduled job.
  • Build the results normalizer for security findings that gives findings stable identifiers, so suppressions and trend metrics survive re-scans.
  • Design security gating policies based on vulnerability severity and confidence thresholds, new-vs-baseline diffing, exception workflow - and tune it so developers trust it.
  • Author CI rules that enforce application security controls that codify platform-level security requirements and block regressions.
  • Stand up the metrics and dashboarding pipeline for program-level reporting.
  • Build and operate the benchmark-based drift-detection job.
  • Partner with platform, infrastructure and development teams to land integration points and gather feedback.
  • Build metrics that measure security posture and vulnerability trends.

SKILL AND EXPERIENCE REQUIRED:

Required

  • 5+ years building CI/CD and developer-platform tooling at scale.
  • Hands-on experience integrating application-security tooling (SAST, DAST, SCA, or similar) into delivery pipelines - including baseline suppression, false-positive workflows and merge gating.
  • Knowledge of scripting languages (Python, Java, JavaScript)
  • Working knowledge of containerized deployment and policy-as-code (e.g., Kubernetes admission control, or equivalent).
  • Enough application-security depth to read a vulnerability report critically, tune confidence thresholds, and push back on an automated verdict.
  • Experience operating under change-control and audit-evidence requirements.

Skills

Docker
Java
JavaScript
Kubernetes
Python

Similar jobs