Candidates must currently be located within approximately 90 100 miles of Dimondale, MI at the time of submission.
Must be available for an in-person interview.
7+ years of overall IT / Application Security experience preferred
Minimum 5+ years of total IT experience
At least 3+ years of hands-on Application Security, Secure Coding, and DevSecOps experience
We are seeking a highly experienced Senior Application Security Auditor with strong expertise in application security testing, secure software development, DevSecOps, API security, vulnerability assessment, and secure coding practices.
This is not a traditional SOC-focused role. The position will work directly with software engineering teams to identify and remediate security vulnerabilities across front-end, back-end, API, cloud, containerized, and distributed applications.
The ideal candidate should have hands-on experience with SAST, DAST, SCA, ASOC, API security, OWASP vulnerabilities, secure coding frameworks, and security automation.
Hands-on experience with Application Security scanning tools, including:
SAST
DAST
SCA
ASOC
Container Security
Cloud Security
Strong understanding of HTTP request/response headers for web applications and REST APIs.
Deep understanding of the OWASP Top 10, including the ability to explain vulnerabilities, attack vectors, and remediation approaches.
Experience identifying and mitigating vulnerabilities such as:
Cross-Site Scripting (XSS)
Injection attacks
Server-Side Request Forgery (SSRF)
Cross-Site Request Forgery (CSRF)
XML External Entity (XXE)
Authentication and authorization vulnerabilities
API security vulnerabilities
Experience implementing secure coding standards and security guidance including:
OWASP Top 10
SANS
CERT Secure Coding
CWE Top 25
CIS Critical Security Controls
Cloud Security Alliance
SAFECode
Strong understanding of secure software development practices across technologies such as:
Angular
React
Node.js
Java
Spring Boot
IBM WebSphere Application Server
Oracle
JBoss
.NET
Experience with both compiled and interpreted programming environments.
Experience with:
Secure application development
Networking infrastructure
Security automation
DevSecOps
Secure SDLC
Hands-on experience designing, developing, assessing, or securing distributed web and mobile applications.
Ability to use browser developer tools such as Chrome, Firefox, and Microsoft Edge DevTools to analyze requests, responses, headers, cookies, and application behavior.
Experience with security tools such as:
Coverity
Black Duck
Fortify
SRM
Strong knowledge of API Security.
Experience with:
JWT
OAuth 2.0
OpenID Connect (OIDC)
PKCE
API replay attack prevention
Understanding of container technologies and container security.
Cloud development or security experience with:
Microsoft Azure
AWS
Google Cloud Platform (Google Cloud Platform)
Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) across enterprise applications.
Conduct security assessments of web, mobile, API, cloud, and distributed applications.
Work closely with development teams to identify vulnerabilities and recommend secure coding remediation strategies.
Review application architecture, code, APIs, authentication, authorization, and data flows from a security perspective.
Guide developers on secure coding standards, OWASP vulnerabilities, threat mitigation, and secure SDLC practices.
Partner with front-end, back-end, API, cloud, and platform engineering teams to integrate security throughout the software development lifecycle.
Implement and promote reusable application security patterns and secure development practices.
Integrate security scanning and validation into DevSecOps and CI/CD pipelines.
Automate secure configuration validation, compliance checks, application security testing, and authorization processes.
Evaluate REST APIs for authentication, authorization, token management, JWT, OAuth/OIDC, replay attacks, and common API vulnerabilities.
Analyze HTTP requests and responses to identify security weaknesses.
Help mature the organization's Secure Software Development Lifecycle (SSDLC).
Support continuous compliance and application risk mitigation initiatives.
Collaborate with distributed engineering teams to improve how applications are designed, developed, secured, deployed, and operated.
Provide technical guidance on vulnerability remediation and security best practices.
Application Security | SAST | DAST | SCA | ASOC | DevSecOps | OWASP Top 10 | API Security | Secure Coding | Fortify | Coverity | Black Duck | JWT | OAuth | OIDC | PKCE | XSS | SSRF | CSRF | XXE | Java | Spring Boot | Angular | React | Node.js | .NET | WebSphere | JBoss | REST API Security | Cloud Security | AWS | Azure | Google Cloud Platform | Secure SDLC