Haystack
← Back to Jobs
Technology

Application Security Engineer

DKMRBH Inc.Albany, NY🇺🇸United StatesPosted 14 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Application Security Engineer

Job Type: Contract
Location: Albany, NY area preferred
Work Arrangement: Hybrid / Onsite as Required
Employment Type: W2
Work Authorization: , , or Valid Visa

Important: Candidates must be available for onsite training and onsite work when required. Albany, NY-area candidates will be given preference. Only candidates who meet all required qualifications will be considered.

Job Overview

We are seeking an experienced Application Security Engineer with a strong background in application security, software development, secure coding, vulnerability assessment, penetration testing, and DevSecOps.

The ideal candidate will have hands-on experience working with development teams to identify and remediate application security vulnerabilities, review source code and architecture changes, perform application security testing, and integrate security tools into CI/CD pipelines.

This position supports a large-scale healthcare technology environment built on Java, web applications, Service-Oriented Architecture (SOA), RHEL, JBoss, and COTS products.

Responsibilities

  • Work closely with software development teams to identify, document, prioritize, and remediate application security vulnerabilities.
  • Establish appropriate application security checkpoints throughout the SDLC.
  • Perform risk-based application security assessments and penetration testing.
  • Conduct SAST and DAST using application security tools such as Fortify and SonarQube.
  • Review code commits, pull requests, and architecture changes for vulnerabilities, misconfigurations, and compliance risks.
  • Evaluate application designs and provide recommendations related to security architecture, vulnerabilities, and remediation.
  • Consult with development leadership regarding secure coding and application security practices.
  • Integrate AI-driven code analysis platforms into CI/CD pipelines to identify vulnerabilities and insecure coding patterns before deployment.
  • Develop repeatable processes for prioritizing security findings, issue dispositions, and remediation activities.
  • Provide concise security status updates, risk assessments, and remediation reports to leadership and stakeholders.
  • Research emerging attack vectors, application vulnerabilities, cybersecurity threats, and industry trends.
  • Develop security training materials and provide application security guidance to development teams.
  • Support compliance with applicable industry security standards and best practices.

Required Skills & Experience

  • 8+ years of Information Technology experience.
  • 5+ years of software development experience as a Developer or Architect.
  • 3+ years of Application Security Engineering experience.
  • Strong Java / Web Development background.
  • Strong secure coding experience.
  • Experience with RHEL / Red Hat Enterprise Linux and JBoss.
  • Experience with Application Security Assessment and Penetration Testing.
  • Hands-on experience with SAST / Static Application Security Testing.
  • Hands-on experience with DAST / Dynamic Application Security Testing.
  • Experience with Fortify and/or SonarQube.
  • Experience reviewing source code, code commits, pull requests, and architecture changes.
  • Experience identifying and remediating application vulnerabilities and security risks.
  • Experience integrating security/code analysis tools into CI/CD pipelines.
  • Hands-on experience with AI-driven code analysis platforms.
  • Experience with DevSecOps and SDLC security.
  • Experience prioritizing security findings and managing vulnerability remediation.
  • Experience preparing risk reports and security updates for technical leadership.

Education

Bachelor’s degree in Computer Science or a related technical field, or an equivalent combination of education and professional experience.

Preferred Certifications

  • CISSP
  • CEH
  • CISA
  • OSCP
  • OSCE
  • OSWE

Required Professional Skills

  • Excellent verbal and written communication skills.
  • Ability to explain complex application security and technical concepts to developers, technical teams, and management.
  • Strong collaboration and teaching abilities.
  • Strong analytical and critical-thinking skills.
  • Strong problem-solving and troubleshooting abilities.
  • Ability to gather and analyze information and develop alternative solutions.
  • Ability to work effectively with developers, architects, security teams, and leadership.

Work Requirements

  • Albany, NY area candidates preferred.
  • Must be available for onsite training.
  • Must be available to work onsite when required.
  • W2 employment required.
  • , , or Valid Visa required.

Ideal Candidate

The strongest candidates will be Application Security Engineers, Application Security Developers, DevSecOps Engineers, Product Security Engineers, or Security-focused Software Engineers with a genuine software development background.

This is not a general cybersecurity, SOC, network security, or GRC role. Candidates should have hands-on experience with Java/web applications, secure coding, application security testing, SAST/DAST, Fortify, SonarQube, code review, vulnerability remediation, penetration testing, and CI/CD security.

Skills

SonarQube
Java
Penetration Testing

Similar jobs