Skip to main content
GuidePoint Security

Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

RemoteUnited States only
Published
Role
Engineering Management
Experience
Mid
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Information security consultancy seeks an application security engineer with 5-7 years of experience in security engineering to implement and operationalize SAST tools for remote work in the Mid-Atlantic region.

Required skills

SemgrepSnykCodeQLCheckmarxVeracodeGitHub ActionsGitLab RunnersAzure DevOpsJenkinsCircleCISAST/CI/CD/scripting/OWASP Top 10/secure codingthreat modelingsecure coding practicesSoftware Development Lifecycle (SDLC)automationAI tools

Optional skills

SemgrepCodeQLIAST toolsDAST toolsAPI security toolsSCA toolsNoNameTraceable

Required languages

English fluent

What you'll do

  • Implementation, operationalization, and troubleshooting of Static Application Security Testing (SAST) tools
  • Understanding of Continuous Integration / Continuous Delivery (CI/CD) pipeline tools and processes
  • Experience in software engineering, ideally full stack software development, including modern technologies and application architectures
  • Strong scripting and automation experience using one or more programming languages
  • Solid working knowledge of application security fundamentals including the OWASP Top 10, threat modeling, and implementing secure coding practices throughout the Software Development Lifecycle (SDLC)
  • Embracing emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
  • Excellent written and verbal communication skills

What they require

  • Bachelor’s degree in a relevant discipline or equivalent experience
  • 5-7 years of security engineering experience in the Information Security industry
  • Proficiency with the implementation, operationalization, and troubleshooting of Static Application Security Testing (SAST) tools such as Semgrep, Snyk, CodeQL, Checkmarx, Veracode, etc.
  • Understanding of Continuous Integration / Continuous Delivery (CI/CD) pipeline tools and processes (e.g. GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, CircleCI, etc.)
  • Experience in software engineering, ideally full stack software development, including modern technologies and application architectures
  • Strong scripting and automation experience using one or more programming languages
  • Solid working knowledge of application security fundamentals including the OWASP Top 10, threat modeling, and implementing secure coding practices throughout the Software Development Lifecycle (SDLC)
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
  • Excellent written and verbal communication skills

Benefits

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option
CybersecurityMid-size
Salary not disclosed