Application Security Platform Engineer
Quick Overview
Job Description
Application Security Platform Engineer
Hybrid Dallas, TX or Chicago, IL (2-3 days/week onsite)
6-12 months, Contract to Hire (CTH)
WORK TO BE PERFORMED:
Seeking an Application Security Platform Engineer with a strong development and automation background to support and augment our efforts in automating and scaling the process for identifying, assessing, and tracking vulnerabilities by leveraging reusable CI components. The engaged resource will be expected to gain a thorough understanding of the existing system architecture and integrations, while demonstrating a willingness to learn how Security vulnerability management tools operate and how reporting should be integrated into OCC's pipeline.
- Develop custom Docker containers to pull results from vulnerability management tools, verify results using custom rules, and print results into report(s)
- Package the application security assessment pipeline as a reusable CI component and a containerized scheduled job.
- Build the results normalizer for security findings that gives findings stable identifiers, so suppressions and trend metrics survive re-scans.
- Design security gating policies based on vulnerability severity and confidence thresholds, new-vs-baseline diffing, exception workflow - and tune it so developers trust it.
- Author CI rules that enforce application security controls that codify platform-level security requirements and block regressions.
- Stand up the metrics and dashboarding pipeline for program-level reporting.
- Build and operate the benchmark-based drift-detection job.
- Partner with platform, infrastructure and development teams to land integration points and gather feedback.
- Build metrics that measure security posture and vulnerability trends.
SKILL AND EXPERIENCE REQUIRED:
Required
- 5+ years building CI/CD and developer-platform tooling at scale.
- Hands-on experience integrating application-security tooling (SAST, DAST, SCA, or similar) into delivery pipelines - including baseline suppression, false-positive workflows and merge gating.
- Knowledge of scripting languages (Python, Java, JavaScript)
- Working knowledge of containerized deployment and policy-as-code (e.g., Kubernetes admission control, or equivalent).
- Enough application-security depth to read a vulnerability report critically, tune confidence thresholds, and push back on an automated verdict.
- Experience operating under change-control and audit-evidence requirements.
Skills
Similar jobs
Sr. Platform/Devops Engineer
Intraedge · United States
4 minutes agoDevOps Engineer GitLab CI/CD & AWS
ComTec Information Systems · Princeton, United States
4 minutes agoLead Azure DevOps
HR Pundits · United States
6 minutes agoDevOps Engineer - Onsite
VIVA USA INC · Princeton, United States
40 minutes agoDevOps Engineer AWS
Cognitive Minds LLC · United States
1 hour agoDevops Architect
Prudent Technologies and Consulting · Dallas, United States
1 hour ago