Haystack
← Back to Jobs
Remote
Technology
NS

Application Security Engineer DevSecOps and CICD

NITYA Software Solutions, Inc.TX🇺🇸United StatesPosted 1 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
TX, United States
Posted
Yesterday
OWASPScrumAgileJavaPythonStakeholder Management

Job Description

Senior Application Security Engineer DevSecOps and CICD

Location: Remote, but must be located in Irving, TX 75039/Chicago, IL 60661/Peoria, IL 61629/Broomfield, CO 80020

Duration: 12 months

***Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***

Education Requirements:

- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Preferred Education:

- Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Required Skills for the Cybersecurity Engineer:

- 7+ years of hands-on application security/DevSecOps experience

- Secure SDLC, DevSecOps, Agile, and Scrum methodologies strong working understanding

- Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling

- Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts

- OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques

- Cloud security, identity and access management, and modern application architectures

- Safe and effective use of AI-assisted development and security tools

- Vulnerability triage and validation exploitability, business impact, severity, compensating controls, and remediation guidance

- Security metrics, coverage reporting, and executive dashboard development

- Excellent communication, stakeholder management, presentation, and documentation skills

- Ability to work independently across multiple applications, teams, portfolios, and technology stacks

- Strong problem-solving mindset balances security, usability, operational impact, and business objectives

- Collaboration and influence negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders

- Coaching and knowledge sharing champions a security-first culture

- Comfortable operating within Scrum/Agile delivery and managing own work items

Cybersecurity Engineer Responsibilities:

- Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams

- Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure

- Manages repository scanning coverage source code analysis, secret scanning, dependency analysis, and infrastructure review and triages findings by exploitability, business impact, and severity

- Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio

- Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends

- Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and must-win business outcomes

Typical task breakdown:

- Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact

- Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review

- Daily/Weekly: drive remediation create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure

- Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects

- Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls

- Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement

- Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks

Similar jobs