← Back to jobs

RulesIQ Logo
Sr. Application Security Engineer

RulesIQ

 

Raleigh, NC, USA

Posted On: 1 day ago
Experience: 5+ years
Availability: Onsite
Openings: 1
Category: Senior Application Security Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

You own the security engineering practices for applications, managing vulnerability scanning, remediation, and CI/CD integration.

This role is on-site.

Responsibilities

  • Conduct DAST scans using Invicti and SAST scans using Veracode to identify application and source code vulnerabilities.
  • Analyze scan results, determine root causes, and collaborate with developers to implement effective remediation.
  • Integrate security testing into CI/CD pipelines and automate scanning processes via scripting.
  • Provide guidance on OWASP Top 10 and SANS 25 vulnerabilities, detailing exploitation and prevention methods.
  • Ensure adherence to NIST, PCI-DSS, FFIEC, SOX, and CIS security frameworks across all scanning activities.

Required Skills

  • 5+ years of experience in Application Security, Secure Development, DAST, and SAST.
  • Hands-on experience with DAST tools such as Invicti (Netsparker), AppScan, or Burp Suite.
  • Experience with SAST tools like Veracode or Fortify.
  • Strong knowledge of web security vulnerabilities, including OWASP Top 10 and SANS 25.
  • Software development experience in Java, .NET, or Python.
  • Familiarity with secure software development life cycle (SSDLC) and CI/CD pipelines.
  • Ability to perform scripting in Python or Java for security engineering tasks.
  • Experience managing compliance across NIST, PCI-DSS, and SOX frameworks.

Education

Bachelor's degree

Related Jobs

No related jobs found

← Back to jobs