Embeds application security into the SDLC through DevSecOps processes, security assessments, repository scanning, vulnerability triage, remediation validation, and secure code review. Uses tools such as Burp Suite, CodeQL, SAST, SCA, and secret scanning across applications, APIs, cloud workloads, and infrastructure. Develops security metrics and executive dashboards, coaches development teams, participates in Agile ceremonies, and promotes secure coding and responsible AI-assisted security practices.
This is a remote position.
Job Title: Senior Application Security Engineer DevSecOps and CICD
Location: Remote, USA
Estimated Duration :12+ Months
Must Have Skills/Attributes: Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability
Experience Desired: Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs); Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)
Required Minimum Education: Bachelor’s Degree
Preferred Education: Master’s Degree
Job Description
- ***Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***
Education Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Preferred Education:
- Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Required Skills for the Cybersecurity Engineer:
- -5-7 years of hands-on application security/DevSecOps experience
- - Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
- - Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
- - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
- - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
- - Cloud security, identity and access management, and modern application architectures
- - Safe and effective use of AI-assisted development and security tools
- - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
- - Security metrics, coverage reporting, and executive dashboard development
- - Excellent communication, stakeholder management, presentation, and documentation skills
- - Ability to work independently across multiple applications, teams, portfolios, and technology stacks
- - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
- - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
- - Coaching and knowledge sharing — champions a security-first culture
- - Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities:
- - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
- - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
- - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
- - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
- - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
- - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes
Typical task breakdown:
- Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
- Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
- Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
- Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
- Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
- Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
- Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks find value in our e-mail notifications as you continue to consider options for your professional career.
Similar Jobs
Cloud • Information Technology • Security • Software • Cybersecurity
Own enterprise sales activities for SLED or Healthcare accounts, including executive relationship development, account strategy, stakeholder collaboration, trusted-advisor engagement, and alignment of cloud security solutions with customer goals. The role requires full-cycle software or security sales experience, enterprise and C-level selling, strategic planning, net-new logo acquisition, quota achievement, and knowledge of AI/ML solutions.
Top Skills:
Ai/MlCloud SecuritySaseZero Trust Exchange
Cloud • Information Technology • Security • Software • Cybersecurity
Own enterprise account strategy and full-cycle sales for major accounts. Build relationships with C-suite stakeholders, align Zscaler’s cloud security solutions with customer goals, collaborate with internal teams, develop trusted-advisor relationships, close new logos, meet sales targets, and leverage channel partnerships.
Top Skills:
Ai ToolsCloud SecuritySaseZero Trust Exchange
Artificial Intelligence • Information Technology • Professional Services • Software • Analytics • Generative AI • Big Data Analytics
Leads UX strategy and experience design for enterprise clients, guiding multidisciplinary teams from research and discovery through implementation. Responsibilities include design leadership, client consulting, user research, interaction design, design systems, accessibility, AI-enabled experiences, stakeholder alignment, and business development. The role manages and mentors designers, presents to executives, supports agile product teams, and contributes to proposals and practice growth.
Top Skills:
AIFigjamFigmaGenerative AiWcag
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory


