Haystack
← Back to Jobs
Technology
ME

IT Security Auditor Application Security / DevSecOps

Morph Enterprise LLCDimondale, MI🇺🇸United StatesPosted 8 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Dimondale, MI, United States
Posted
Yesterday
JavaReactAngularNode.jsSpring BootSpring.NETRESTAWSAzureGoogle CloudDockerKubernetesOAuthJWTOWASPHTTP

Job Description

IT Security Auditor Application Security / DevSecOps

Location: Dimondale, MI
Work Arrangement: Hybrid 2 days onsite per week
Duration: 1 year with possible extension

Important Details

  • Interview Process: Initial virtual interview via MS Teams, followed by a 2nd-round in-person interview at the Dimondale, MI office.
  • Candidates must be available for the in-person interview.
  • Onsite Requirement: Must be onsite starting Day 1, 2 days per week.
  • Required Onsite Days: Wednesdays and Thursdays.
  • No remote-only option.

Job Summary

We are seeking a Senior IT Security Auditor / Application Security professional to help strengthen secure software development practices across complex web, API, mobile, and cloud-based applications.

This role works closely with software development teams to identify vulnerabilities, promote secure coding practices, implement security controls, and automate security assessments throughout the software development lifecycle.

This is not a SOC role. The primary focus is Application Security, Secure Software Development, and DevSecOps.

Key Responsibilities

  • Perform SAST, DAST, SCA, ASOC, container, and cloud security assessments.
  • Identify application vulnerabilities and recommend remediation.
  • Partner with developers to implement secure coding practices.
  • Review web applications, REST APIs, mobile applications, and distributed systems.
  • Analyze HTTP request/response headers using browser developer tools.
  • Assess vulnerabilities using OWASP Top 10, CWE, SANS, and CERT guidance.
  • Evaluate API security, JWT, OAuth/OIDC, and PKCE.
  • Identify risks including XSS, injection, SSRF, CSRF, XXE, and replay attacks.
  • Integrate security controls into DevSecOps/CI/CD pipelines.
  • Support secure cloud application development across AWS, Azure, or Google Cloud Platform.
  • Help mature secure software development practices across development teams.

Required Qualifications

  • 5+ years of total IT experience.
  • 3+ years of Application Security, secure coding, or DevSecOps experience.
  • Hands-on experience with SAST, DAST, and SCA tools.
  • Strong understanding of OWASP Top 10 and web application vulnerabilities.
  • Experience with API Security, REST APIs, HTTP, JWT, OAuth/OIDC, and PKCE.
  • Experience with technologies such as Java, Spring Boot, .NET, Node.js, Angular, or React.
  • Experience with security automation and DevSecOps.
  • Experience securing complex distributed web and/or mobile applications.
  • Cloud experience with AWS, Azure, or Google Cloud Platform.
  • Ability to work closely with software development teams.
  • Ability to successfully pass a CJIS background check.

Preferred Qualifications

  • Experience with Coverity, Black Duck, Fortify, or similar security tools.
  • Experience with Docker/Kubernetes and container security.
  • Experience integrating security testing into CI/CD pipelines.
  • Knowledge of CIS Controls, Cloud Security Alliance, SAFECode, CWE, SANS, and CERT.

Similar jobs