Application Security Engineer - Northeast region

GuidePoint Security
United States
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Communication","Client communication","Lead by influence","Business acumen","Automation"]

Support the Northeast Application Security practice by implementing, operating, and troubleshooting SAST tooling and integrating automated security testing into CI/CD pipelines. Create and adapt custom SAST rules, triage vulnerabilities, and guide remediation using secure development practices across the SDLC. Partner with client teams and internal AppSec experts to reduce scan noise, accelerate delivery with DevSecOps/shift-left programs, and deliver occasional on-site engagements with up to 10% travel.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GuidePoint Security
GuidePoint Security
1 day ago

Application Security Engineer - Northeast region

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 18 minutes agoStatus: Live

Job Summary

Support the Northeast Application Security practice by implementing, operating, and troubleshooting SAST tooling and integrating automated security testing into CI/CD pipelines. Create and adapt custom SAST rules, triage vulnerabilities, and guide remediation using secure development practices across the SDLC. Partner with client teams and internal AppSec experts to reduce scan noise, accelerate delivery with DevSecOps/shift-left programs, and deliver occasional on-site engagements with up to 10% travel.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Implement, operationalize, and troubleshoot SAST platforms within client environments.
  • •Design and integrate automated security testing into CI/CD pipelines.
  • •Author and adapt custom SAST rules and guide triage/validation and remediation of vulnerabilities.
  • •Advise client teams on OWASP Top 10, threat modeling, and secure coding throughout the SDLC.
  • •Contribute reusable pipeline patterns, rule libraries, and delivery accelerators for the AppSec practice, with occasional on-site presence as needed.
Travel: Low travel

Pay and Benefits

Perks:Health InsuranceDentalPaid LeaveHome InternetMobile AllowanceRetirementPet Insurance

Key Requirements

  • •Proficiency implementing, operationalizing, and troubleshooting Static Application Security Testing (SAST) tools such as Semgrep, Snyk, CodeQL, Checkmarx, and Veracode.
  • •Understanding of CI/CD pipeline tools and processes, including GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, and CircleCI.
  • •Experience in software engineering with ideally full-stack development and modern application architectures.
  • •Strong scripting and automation experience using one or more programming languages.
  • •Solid knowledge of application security fundamentals, including OWASP Top 10, threat modeling, and secure coding practices across the SDLC.
Experience:DevSecOpsApplication securityCybersecurityCI/CD
Skills:CommunicationClient communicationLead by influenceBusiness acumenAutomation
Tech Stack:SemgrepSnykCodeQLCheckmarxVeracodeSASTCI/CDGitHub ActionsGitLab RunnersAzure DevOpsJenkinsCircleCIOWASP Top 10Threat modelingSDLCNIST SSDFOWASP SAMMSLSASBOMAI tools

Company Brief

GuidePoint Security
Provides cybersecurity consulting, managed security services, incident response, cloud and network security, and compliance solutions to enterprises and government organizations, helping clients identify, mitigate, and respond to cyber threats across complex environments.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Herndon, United States
Founded: 2010
WebsiteLinkedIn