Haystack
← Back to Jobs
Remote
Technology
JT

Application Security Engineer Security Automation & DevSecOps

Javen Technologies, IncUnited States🇺🇸United StatesPosted 2 Sept 2026

Why This Role Stands Out

This fully remote Application Security Engineer role offers significant growth by enabling you to shape and automate security practices across the entire development lifecycle, utilizing cutting-edge SAST, SCA, and API security platforms. If you are a mid-senior professional with expertise in API security, JavaScript/NodeJS, Python, and security testing tools, you'll thrive in this impactful position that emphasizes developer enablement and operational efficiency. Apply now to join a forward-thinking team and elevate your career in DevSecOps!

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
18 hours ago
AWSJavaScriptPower BIPythonTerraform

Job Description

Job Title: Information Security Engineer
Location: 100% Remote
Experience: 15+ Years

JOB DESCRIPTION

Must Have

  • API security, JavaScript/NodeJS, Python, Software Application Security Testing (SAST), Software Composition Analysis (SCA), Terraform

Nice To Have

  • , , , , ,

Job Summary

The Code Security Engineer is responsible for the administration, operation, and continuous improvement of the organization's code security capabilities, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), and API Security platforms. This role supports security tooling operations, runtime monitoring, developer enablement, and end-user support while partnering with engineering teams to develop integrations, automation, reporting, and processes that improve security visibility and operational efficiency across the software development lifecycle.

Key Responsibilities

  • Administer and support SAST, SCA, and API Security platforms.
  • Configure, maintain, and optimize security scanning and runtime monitoring capabilities.
  • Analyze security findings and assist development teams with vulnerability remediation and risk reduction.
  • Provide end-user support, troubleshooting, and onboarding assistance for security tools and related processes.
  • Monitor platform health, scan coverage, performance metrics, and operational effectiveness.
  • Design and develop integrations between security platforms, CI/CD pipelines, reporting systems, and other enterprise tools.
  • Build automation and one-off solutions to improve security workflows and reduce operational overhead.
  • Utilize Infrastructure as Code (IaC) practices to deploy and manage tooling and supporting infrastructure.
  • Develop dashboards, metrics, and reporting to support security program visibility and decision-making.
  • Collaborate with development, DevOps, and security teams to integrate security into engineering workflows.
  • Contribute to security tooling roadmaps, enhancement efforts, and operational improvements.

Required Qualifications

  • Experience with:
    • API Security
    • Software Composition Analysis (SCA)
    • Static Application Security Testing (SAST)
  • Experience providing end-user support and troubleshooting technical issues.
  • Experience with Terraform or similar Infrastructure as Code technologies.
  • Proficiency in one or more modern programming languages:
    • Javascript
    • Python
  • Experience developing automation, integrations, or operational tooling.
  • Understanding of secure software development lifecycle (SSDLC) principles and application security practices.
  • Strong analytical, troubleshooting, and communication skills.

Preferred Qualifications

  • Unit testing experience.
  • Experience writing one-off automation and data-processing scripts.
  • Amazon Web Services (AWS) experience.
  • Power BI experience.
  • Windows Server administration experience.
  • Familiarity with CI/CD pipelines, API gateways, and DevOps practices.

Similar jobs