Application Security Engineer
Quick Overview
Job Description
Application Security Engineer
Job Type: Contract
Location: Albany, NY area preferred
Work Arrangement: Hybrid / Onsite as Required
Employment Type: W2
Work Authorization: , , or Valid Visa
Important: Candidates must be available for onsite training and onsite work when required. Albany, NY-area candidates will be given preference. Only candidates who meet all required qualifications will be considered.
Job Overview
We are seeking an experienced Application Security Engineer with a strong background in application security, software development, secure coding, vulnerability assessment, penetration testing, and DevSecOps.
The ideal candidate will have hands-on experience working with development teams to identify and remediate application security vulnerabilities, review source code and architecture changes, perform application security testing, and integrate security tools into CI/CD pipelines.
This position supports a large-scale healthcare technology environment built on Java, web applications, Service-Oriented Architecture (SOA), RHEL, JBoss, and COTS products.
Responsibilities
- Work closely with software development teams to identify, document, prioritize, and remediate application security vulnerabilities.
- Establish appropriate application security checkpoints throughout the SDLC.
- Perform risk-based application security assessments and penetration testing.
- Conduct SAST and DAST using application security tools such as Fortify and SonarQube.
- Review code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks.
- Evaluate application designs and provide recommendations related to security architecture, vulnerabilities, and remediation.
- Consult with development leadership regarding secure coding and application security practices.
- Integrate AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment.
- Develop repeatable processes for prioritizing security findings, issue dispositions, and remediation activities.
- Provide concise security status updates, risk assessments, and remediation reports to leadership and stakeholders.
- Research emerging attack vectors, application vulnerabilities, cybersecurity threats, and industry trends.
- Develop security training materials and provide application security guidance to development teams.
- Support compliance with applicable industry security standards and best practices.
Required Skills & Experience
- 8+ years of Information Technology experience.
- 5+ years of software development experience as a Developer or Architect.
- 3+ years of Application Security Engineering experience.
- Strong Java / Web Development background.
- Strong secure coding experience.
- Experience with RHEL / Red Hat Enterprise Linux and JBoss.
- Experience with Application Security Assessment and Penetration Testing.
- Hands-on experience with SAST / Static Application Security Testing.
- Hands-on experience with DAST / Dynamic Application Security Testing.
- Experience with Fortify and/or SonarQube.
- Experience reviewing source code, code commits, pull requests, and architecture changes.
- Experience identifying and remediating application vulnerabilities and security risks.
- Experience integrating security/code analysis tools into CI/CD pipelines.
- Hands-on experience with AI-driven code analysis platforms.
- Experience with DevSecOps and SDLC security.
- Experience prioritizing security findings and managing vulnerability remediation.
- Experience preparing risk reports and security updates for technical leadership.
Education
Bachelor’s degree in Computer Science or a related technical field, or an equivalent combination of education and professional experience.
Preferred Certifications
- CISSP
- CEH
- CISA
- OSCP
- OSCE
- OSWE
Required Professional Skills
- Excellent verbal and written communication skills.
- Ability to explain complex application security and technical concepts to developers, technical teams, and management.
- Strong collaboration and teaching abilities.
- Strong analytical and critical-thinking skills.
- Strong problem-solving and troubleshooting abilities.
- Ability to gather and analyze information and develop alternative solutions.
- Ability to work effectively with developers, architects, security teams, and leadership.
Work Requirements
- Albany, NY area candidates preferred.
- Must be available for onsite training.
- Must be available to work onsite when required.
- W2 employment required.
- , , or Valid Visa required.
Ideal Candidate
The strongest candidates will be Application Security Engineers, Application Security Developers, DevSecOps Engineers, Product Security Engineers, or Security-focused Software Engineers with a genuine software development background.
This is not a general cybersecurity, SOC, network security, or GRC role. Candidates should have hands-on experience with Java/web applications, secure coding, application security testing, SAST/DAST, Fortify, SonarQube, code review, vulnerability remediation, penetration testing, and CI/CD security.
Skills
Similar jobs
Sr Senior Security Engineer
Apex Systems · Merrifield, United States
3 minutes agoSenior Cyber Test Engineer (Onsite) with Security Clearance
Nightwing · Sterling, United States
3 minutes agoSenior Cyber Software Engineer (iOS) with Security Clearance
Nightwing · Sterling, United States
3 minutes ago(Cyber) Incident Management Analyst - Weekend Night Shift with Security Clearance
Nightwing · Arlington, United States
3 minutes agoSenior Director of Network Security - Engineering Lead
Bank Of New York Mellon · New York, United States
4 minutes ago$136.5k - $350k/yrSenior Enterprise Security Engineer
Roblox · San Mateo, United States
6 minutes ago$243.3k - $295.3k/yr