Haystack
← Back to Jobs
Technology

Application Security Engineer

Arnex Solutions LLCChicago, IL🇺🇸United StatesPosted 24 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Application Security Platform Engineer 
Location: Hybrid in Chicago or Dallas
 
Overview:
Seeking an Application Security Platform Engineer with a strong development and automation background to support and augment our efforts in automating and scaling the process for identifying, assessing, and tracking vulnerabilities by leveraging reusable CI components. The engaged resource will be expected to gain a thorough understanding of the existing system architecture and integrations, while demonstrating a willingness to learn how Security vulnerability management tools operate and how reporting should be integrated into pipelines.

Responsibilities:
  • Develop custom Docker containers to pull results from vulnerability management tools, verify results using custom rules, and print results into report(s)
  • Package the application security assessment pipeline as a reusable CI component and a containerized scheduled job.                                                  
  • Build the results normalizer for security findings that gives findings stable identifiers, so suppressions and trend metrics survive re-scans.
  • Design security gating policies based on vulnerability severity and confidence thresholds, new-vs-baseline diffing, exception workflow - and tune it so developers trust it. 
  • Author CI rules that enforce application security controls that codify platform-level security requirements and block regressions.                        
  • Stand up the metrics and dashboarding pipeline for program-level reporting.                                                                        
  • Build and operate the benchmark-based drift-detection job.                                                                                          
  • Partner with platform, infrastructure and development teams to land integration points and gather feedback.                                      
  • Build metrics that measure security posture and vulnerability trends.

Qualifications:
Required Qualifications:
  • 5+ years building CI/CD and developer-platform tooling at scale.
  • Hands-on experience integrating application-security tooling (SAST, DAST, SCA, or similar) into delivery pipelines - including baseline suppression, false-positive workflows and merge gating.                                                                                
  • Knowledge of scripting languages (Python, Java, JavaScript)                                                                                                                                       
  • Working knowledge of containerized deployment and policy-as-code (e.g., Kubernetes admission control, or equivalent).
  • Enough application-security depth to read a vulnerability report critically, tune confidence thresholds, and push back on an automated verdict.  
  • Experience operating under change-control and audit-evidence requirements.    

Preferred Qualifications:
  • Experience with LLM-based or agentic tooling - handling non-determinism, output validation, prompt/workflow orchestration.                       
  • Familiarity with enterprise vulnerability-management platforms.
  • Reading fluency in Java and TypeScript codebases.            
  • Background in a regulated industry (financial services, healthcare, critical infrastructure).
  • Experience with Jenkins shared libraries and Helm is a plus.              
  • Experience or relevant training in Terraform and cloud platforms such as AWS
  • Experience with Java programming including Java Servlets, Spring.

Skills

Docker
Spring
AWS
Helm
Java
JavaScript
Jenkins
Kubernetes
LLM
Python
Terraform
TypeScript

Similar jobs