Job posting has expired
New
Application Security Engineer
![]() | |
![]() | |
![]() | |
![]() United States, California, Fountain Valley | |
![]() | |
*You will be doing : *
Secure SDLC & App Scanning *Expand application security scanning coverage by deploying and maintaining SAST, DAST, SCA, and secret scanning tools. *Conduct static and dynamic software analysis to identify security vulnerabilities in code, APIs, and third-party libraries. *Work with development teams to integrate security tools into CI/CD pipelines. Vulnerability Management *Enhance vulnerability management by prioritizing risks based on business impact, CVSS scores, exploitability, and asset criticality. *Track, triage, and assist with remediation of application-layer vulnerabilities through automated workflows and manual processes. *Continuously monitor and report on vulnerability trends and metrics to leadership. Code Governance *Centralize code repositories to standardize security controls, enable access management, and improve auditing capabilities. *Improve code review processes by implementing secure code review checklists, peer-review frameworks, and developer education. Remediation & Response *Develop and improve corrective action plans for security findings, including documentation, timelines, responsible parties, and verification steps. *Work closely with product and engineering teams to implement secure design recommendations and patches. *Participate in security incident response related to application vulnerabilities or breaches. Collaboration & Education *Collaborate with development, QA, and DevOps teams to ensure security is embedded in the SDLC. *Provide training, documentation, and resources to help developers adopt secure coding best practices. *Required Qualifications:* * 7+ years of experience in Application Security, Software Engineering, or related technical role. * Strong understanding of OWASP Top 10, secure coding standards, and application-layer attack vectors. * Experience with application security tools such as SonarQube, Veracode, Fortify, Checkmarx, Snyk, or GitHub Advanced Security. * Proficient in at least one programming language (e.g., Java, Python, JavaScript). * Familiarity with code repositories like GitHub, GitLab, and Bitbucket. *Additional Skills & Qualifications* Preferred Certifications: *OSWE, GWAPT, CSSLP, or similar application security certifications. *Familiarity with threat modeling tools (e.g., OWASP Threat Dragon, Microsoft Threat Modeling Tool). *Pay and Benefits* The pay range for this position is $80.00 - $95.00/hr. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: * Medical, dental & vision * Critical Illness, Accident, and Hospital * 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available * Life Insurance (Voluntary Life & AD&D for the employee and dependents) * Short and long-term disability * Health Spending Account (HSA) * Transportation benefits * Employee Assistance Program * Time Off/Leave (PTO, Vacation or Sick Leave) *Workplace Type* This is a fully onsite position in Fountain Valley,CA. *Application Deadline* This position is anticipated to close on Jun 17, 2025. About TEKsystems and TEKsystems Global Services We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com. The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. |