Why This Role Stands Out
You can make a significant impact by directly embedding security into application development for the State of Michigan, offering a unique opportunity to shape secure web and mobile platforms. This role is perfect for a mid-senior professional passionate about proactive security and DevSecOps, eager to grow their skills in a reputable public sector environment. Apply now to join this critical cybersecurity initiative!
Quick Overview
Job Description
We are seeking a Senior Full-Stack Application Security Auditor to join the State of Michigan’s Cyber Security team in Dimondale, MI. Unlike a traditional SOC role, this position focuses directly on embedded application security—partnering with development teams to review code, run AppSec tools (SAST/DAST/SCA), enforce DevSecOps automation, and audit secure application designs for web and mobile platforms.
- Client: State of Michigan – Cyber Security / Critical Infrastructure Protection (CIP)
- Location: Dimondale, MI 48821 (7150 Harris Dr)
- Work Arrangement: Hybrid (2 days required onsite per week: Wednesdays & Thursdays; candidates MUST reside within 90–100 miles of Dimondale, MI at time of submission)
- Role Type: Contract (10/05/2026 – 10/05/2027, 1-year contract with extension potential)
- Interview Process: 1st Round MS Teams Virtual Interview, followed by mandatory 2nd Round IN-PERSON Interview in Dimondale, MI
- Special Requirements: Candidate-written cover letter and completed prescreening questionnaire required at submission; candidate must be able to pass a CJIS background check.
Key Responsibilities
- Application Security Auditing: Partner with software engineering teams to evaluate application security, secure coding practices, and runtime configurations across full-stack systems (.NET, Java, Node.js, Angular, React).
- Vulnerability Assessments & Scanning: Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Application Security Orchestration and Correlation (ASOC) scanning.
- API & Web Security: Inspect HTTP Request/Response headers via browser developer tools; evaluate API security protocols (OAuth, OIDC, PKCE, JWT) and mitigate web/API replay threats.
- Threat Mitigation & Code Review: Perform root-cause analysis and provide remediation guidance for OWASP Top 10 vulnerabilities (XSS, SQL Injection, SSRF, CSRF, XXE).
- DevSecOps & Cloud Integration: Embed security patterns and automated compliance verification into CI/CD pipelines, container environments, and cloud platforms (Azure, AWS, Google Cloud Platform).
Required Skills & Qualifications
- Overall IT Experience: 5+ years of total IT experience with a strong background in software development.
- AppSec Scanning Tools: Direct experience executing SAST, DAST, SCA, and ASOC assessments for web and containerized applications.
- Secure Coding Standards: 3+ years applying secure coding frameworks (OWASP Top 10, CWE Top 25, SANS, CERT, CIS Controls, SAFECode).
- Software Development Stack: 3+ years of experience with compiled and interpreted technologies (Java, Spring Boot, Angular, React, Node.js, .NET, WebSphere/JBoss).
- DevSecOps & Secure Architecture: 3+ years integrating application security automation into CI/CD pipelines and infrastructure environments.
- Web & API Security: Demonstrated capability inspecting HTTP headers, securing RESTful APIs, and auditing web application traffic.
Preferred Qualifications
- Enterprise AppSec Tools: Hands-on experience with tools like Coverity, Black Duck, Synopsys SRM, or Micro Focus Fortify.
- Identity & Authentication Standards: Deep familiarity with OAuth, OpenID Connect (OIDC), PKCE, and JWT token management.
- Cloud & Containerization: Practical knowledge of Docker/Kubernetes container security and cloud application architectures (Azure, AWS, or Google Cloud Platform).
Similar jobs
- DO
IT CYBERSECURITY SPECIALIST (INFOSEC) with Security Clearance
NewDepartment of the Navy
Norfolk, VA🇺🇸On-site18 hours agoHTTPSTechnology - SE
Exploitation Analyst EA Level 14 with Security Clearance
NewSentar
Annapolis Junction, MD🇺🇸HybridYesterdayMental HealthPenetration TestingRecruiting - AD
Security Engineer with Security Clearance
NewAgile Defense, Inc.
Springfield, VA🇺🇸$120k - $140k/yrHybrid18 hours agoActive DirectoryAgileConfluence+2Technology - OS
Network Engineer with Security Clearance
NewOpen Systems Technologies Corporation
Quantico, VA🇺🇸HybridYesterdayEncryptionTechnology - B/
Information Assurance Security Engineer with Security Clearance
B/Core
Springfield, VA🇺🇸$117k - $129k/yrHybrid7 weeks agoAWSPowerShellVMwareTechnology - RD
Security GRC Operations Specialist (TPRM & Risk Management)
NewRandstad Digital
Houston, TX🇺🇸$53 - $63/hrOn-site18 hours agoOperations & Project Management