Want to know if you’re a fit? Upload your resume and let our AI show you.
Skills
ARM (Advanced RISC Machine)unmatched
Amazon Web Services (AWS)unmatched
Analysis Skillsunmatched
Application Programming Interface (API)unmatched
Applications Securityunmatched
Authenticationunmatched
Best Practicesunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Applicationsunmatched
Cloud Computingunmatched
Code Reviewsunmatched
Computer Securityunmatched
Continuous Deployment/Deliveryunmatched
Continuous Integrationunmatched
DevOpsunmatched
Enterprise Applicationsunmatched
Enterprise Protectionunmatched
Establish Prioritiesunmatched
Health Planunmatched
Hybrid Cloudunmatched
Information Technology Consultingunmatched
Internet Applicationunmatched
Internet Securityunmatched
Jenkinsunmatched
Logic Testingunmatched
Metricsunmatched
Microservicesunmatched
Microsoft Windows Azureunmatched
Mobile Web Programmingunmatched
Penetration Testingunmatched
Product Lifecycleunmatched
Reporting Dashboardsunmatched
Risk Managementunmatched
Secure Codingunmatched
Security Analysisunmatched
Security Architectureunmatched
Software Administrationunmatched
Software Development Lifecycle (SDLC)unmatched
Supply Chainunmatched
Test Automationunmatched
Threat Modelingunmatched
Validation Testingunmatched
Vulnerability Scannersunmatched
Description
Our client, a IT Services and Consulting company, is looking for a Application Security (AppSec) Engineer for their Saint Louis, MO location.
Responsibilities:
The role focuses on embedding security testing, vulnerability management, and business logic validation directly intCI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity.
The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing timprove application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle.
Application Security Engineering
Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
Integrate security controls and testing activities intAgile, DevOps, and CI/CD pipelines.
Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
Enable continuous post-deployment security validation and risk monitoring.
Security Testing & Validation
Conduct manual penetration testing and business logic testing tidentify vulnerabilities beyond automated scanning capabilities.
Perform authenticated and unauthenticated security assessments of applications and APIs.
Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
Validate remediation effectiveness and secure deployment practices.
DevSecOps Integration
Embed security testing intGitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
Automate vulnerability triage, prioritization, and remediation workflows.
Develop security-as-code controls and policy enforcement mechanisms.
Collaborate with engineering teams timplement secure coding practices and shift-left security initiatives.
Vulnerability Management
Analyze findings from multiple security tools and eliminate false positives.
Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
Track remediation efforts through SDLC and release cycles.
Develop security metrics, dashboards, and executive reporting.
Developer Enablement
Conduct secure coding reviews and developer education sessions.
Establish security champions programs across engineering teams.
Provide remediation guidance and hands-on support during application releases.
Drive adoption of secure development standards and best practices.
Cloud & API Security
Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
Secure REST, GraphQL, and microservice-based APIs.
Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
Support software supply chain security initiatives, including SBOM/SCA validation.
Requirements:
What are the top 3 skills required for this role
Application Security (AppSec)
Secure SDLC / DevSecOps
SAST, DAST, IAST, SCA
Web, Mobile & API Security Testing
Manual Penetration Testing & Business Logic Testing
Threat Modelling
Vulnerability Management
Secure Code Review
CI/CD Security Integration
8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
Experience securing large-scale enterprise applications across cloud and hybrid environments.
ICONMA is a global information consulting management firm providing Professional Staffing Services and Project-Based Solutions for organizations in a broad range of industries.
Corporate Headquarters in Troy, Michigan; 20+ locations worldwide.
Certified Woman-Owned Business Enterprise (WBE); certified by Women’s Business Enterprise National Council, National Women Business Owners Corporation (NWBOC); and California Public Utilities Commission (CPUC).
Founded in 2000
2000+ Employees
The company was founded on the principle that success is derived from delivering high quality service and resources in the most responsive, flexible, and innovative way. ICONMA invests in people and resources with a single goal: To provide our customers with the highest quality service in the most responsive manner. Through its network of offices, ICONMA provides the resources to help clients maintain their competitive advantage.