Quick Overview
Job Description
IT Security Auditor Application Security / DevSecOps
Location: Dimondale, MI
Work Arrangement: Hybrid 2 days onsite per week
Duration: 1 year with possible extension
Important Details
- Interview Process: Initial virtual interview via MS Teams, followed by a 2nd-round in-person interview at the Dimondale, MI office.
- Candidates must be available for the in-person interview.
- Onsite Requirement: Must be onsite starting Day 1, 2 days per week.
- Required Onsite Days: Wednesdays and Thursdays.
- No remote-only option.
Job Summary
We are seeking a Senior IT Security Auditor / Application Security professional to help strengthen secure software development practices across complex web, API, mobile, and cloud-based applications.
This role works closely with software development teams to identify vulnerabilities, promote secure coding practices, implement security controls, and automate security assessments throughout the software development lifecycle.
This is not a SOC role. The primary focus is Application Security, Secure Software Development, and DevSecOps.
Key Responsibilities
- Perform SAST, DAST, SCA, ASOC, container, and cloud security assessments.
- Identify application vulnerabilities and recommend remediation.
- Partner with developers to implement secure coding practices.
- Review web applications, REST APIs, mobile applications, and distributed systems.
- Analyze HTTP request/response headers using browser developer tools.
- Assess vulnerabilities using OWASP Top 10, CWE, SANS, and CERT guidance.
- Evaluate API security, JWT, OAuth/OIDC, and PKCE.
- Identify risks including XSS, injection, SSRF, CSRF, XXE, and replay attacks.
- Integrate security controls into DevSecOps/CI/CD pipelines.
- Support secure cloud application development across AWS, Azure, or Google Cloud Platform.
- Help mature secure software development practices across development teams.
Required Qualifications
- 5+ years of total IT experience.
- 3+ years of Application Security, secure coding, or DevSecOps experience.
- Hands-on experience with SAST, DAST, and SCA tools.
- Strong understanding of OWASP Top 10 and web application vulnerabilities.
- Experience with API Security, REST APIs, HTTP, JWT, OAuth/OIDC, and PKCE.
- Experience with technologies such as Java, Spring Boot, .NET, Node.js, Angular, or React.
- Experience with security automation and DevSecOps.
- Experience securing complex distributed web and/or mobile applications.
- Cloud experience with AWS, Azure, or Google Cloud Platform.
- Ability to work closely with software development teams.
- Ability to successfully pass a CJIS background check.
Preferred Qualifications
- Experience with Coverity, Black Duck, Fortify, or similar security tools.
- Experience with Docker/Kubernetes and container security.
- Experience integrating security testing into CI/CD pipelines.
- Knowledge of CIS Controls, Cloud Security Alliance, SAFECode, CWE, SANS, and CERT.
Similar jobs
- RD
ISO Auditor
NewRandstad Digital
Tampa, FL🇺🇸$45 - $50/hrRemoteYesterday401kAuditingCPA+2 - AS
QMS Audit Manager- EHSS
NewAmtex Systems Inc.
South Hackensack, NJ🇺🇸HybridYesterdayERPRisk ManagementFinance - TE
Senior Cybersecurity Auditor with Security Clearance
Telos Corporation
San Antonio, TX🇺🇸Hybrid3 days agoHTTPSTechnology - DT
Audit Manager
NewDhaka Technologies Limited Company
Lincolnshire, IL🇺🇸On-siteYesterdayAuditingCPAMicrosoft OfficeFinance - DA
Inpatient Audit Specialist PRN - Remote
NewDatavant
Remote - United States🇺🇸$35 - $45/hrRemote14 hours ago401kAuditingCerner+6 - ML
IT Security Auditor
NewMasterapp Labs
Dimondale, MI🇺🇸On-siteYesterdayJavaReactAngular+12Technology