Haystack
← Back to Jobs
Technology
SP

Cyber Security Specialist

Stellar Professionals LLCDimondale, MI🇺🇸United StatesPosted 4 Sept 2026

Why This Role Stands Out

You can make a significant impact by directly embedding security into application development for the State of Michigan, offering a unique opportunity to shape secure web and mobile platforms. This role is perfect for a mid-senior professional passionate about proactive security and DevSecOps, eager to grow their skills in a reputable public sector environment. Apply now to join this critical cybersecurity initiative!

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Dimondale, MI, United States
Posted
18 hours ago
DockerNode.jsSQLSpringSpring BootAWSOAuthOWASPAngularAzure.NETGoogle CloudHTTPJWTJavaKubernetesReact

Job Description

We are seeking a Senior Full-Stack Application Security Auditor to join the State of Michigan’s Cyber Security team in Dimondale, MI. Unlike a traditional SOC role, this position focuses directly on embedded application security—partnering with development teams to review code, run AppSec tools (SAST/DAST/SCA), enforce DevSecOps automation, and audit secure application designs for web and mobile platforms.

  • Client: State of Michigan – Cyber Security / Critical Infrastructure Protection (CIP)
  • Location: Dimondale, MI 48821 (7150 Harris Dr)
  • Work Arrangement: Hybrid (2 days required onsite per week: Wednesdays & Thursdays; candidates MUST reside within 90–100 miles of Dimondale, MI at time of submission)
  • Role Type: Contract (10/05/2026 – 10/05/2027, 1-year contract with extension potential)
  • Interview Process: 1st Round MS Teams Virtual Interview, followed by mandatory 2nd Round IN-PERSON Interview in Dimondale, MI
  • Special Requirements: Candidate-written cover letter and completed prescreening questionnaire required at submission; candidate must be able to pass a CJIS background check.

Key Responsibilities

  • Application Security Auditing: Partner with software engineering teams to evaluate application security, secure coding practices, and runtime configurations across full-stack systems (.NET, Java, Node.js, Angular, React).
  • Vulnerability Assessments & Scanning: Conduct Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Application Security Orchestration and Correlation (ASOC) scanning.
  • API & Web Security: Inspect HTTP Request/Response headers via browser developer tools; evaluate API security protocols (OAuth, OIDC, PKCE, JWT) and mitigate web/API replay threats.
  • Threat Mitigation & Code Review: Perform root-cause analysis and provide remediation guidance for OWASP Top 10 vulnerabilities (XSS, SQL Injection, SSRF, CSRF, XXE).
  • DevSecOps & Cloud Integration: Embed security patterns and automated compliance verification into CI/CD pipelines, container environments, and cloud platforms (Azure, AWS, Google Cloud Platform).

Required Skills & Qualifications

  • Overall IT Experience: 5+ years of total IT experience with a strong background in software development.
  • AppSec Scanning Tools: Direct experience executing SAST, DAST, SCA, and ASOC assessments for web and containerized applications.
  • Secure Coding Standards: 3+ years applying secure coding frameworks (OWASP Top 10, CWE Top 25, SANS, CERT, CIS Controls, SAFECode).
  • Software Development Stack: 3+ years of experience with compiled and interpreted technologies (Java, Spring Boot, Angular, React, Node.js, .NET, WebSphere/JBoss).
  • DevSecOps & Secure Architecture: 3+ years integrating application security automation into CI/CD pipelines and infrastructure environments.
  • Web & API Security: Demonstrated capability inspecting HTTP headers, securing RESTful APIs, and auditing web application traffic.

Preferred Qualifications

  • Enterprise AppSec Tools: Hands-on experience with tools like Coverity, Black Duck, Synopsys SRM, or Micro Focus Fortify.
  • Identity & Authentication Standards: Deep familiarity with OAuth, OpenID Connect (OIDC), PKCE, and JWT token management.
  • Cloud & Containerization: Practical knowledge of Docker/Kubernetes container security and cloud application architectures (Azure, AWS, or Google Cloud Platform).

Similar jobs