Application Security Tester / DevSecOps Lead

Diverse Lynx, LLC
  • Berkeley Heights, NJ
  • $70–$75 Per Hour
9 days ago

Job Description

Job Title: Application Security Tester / DevSecOps Lead

Location: Berkeley Heights, NJ (onsite)

Type: Contract

Pay Rate: $70-$75 W2

  • 10+ years in Application Security / DevSecOps, with at least 2-3 years in a lead capacity.
  • Proven, hands-on experience implementing and enforcing SAST/DAST/SCA gates in CI/CD pipelines.
  • Direct experience with Fortify (SAST) in an enforcing/blocking configuration, ideally across multiple technology stacks.
  • Working knowledge of Sonatype (or equivalent SCA) and WebInspect (or equivalent DAST) in production pipelines.

Experience: 10+ Years

____

Role Overview

This is a hands-on DevSecOps Lead role responsible for owning and strengthening the security posture of the software delivery pipeline across three distinct technology stacks: modern cloud-native .NET Core / Azure AKS platform, legacy VB.NET / ASP.NET (.NET Framework 4.8) estate running on IIS, Core COBOL mainframe environment. The successful candidate will be responsible for configuring, tuning, and enforcing security controls within CI/CD pipelines, with direct accountability for transforming SCA, SAST, and DAST from advisory practices into mandatory, pipeline-blocking security gates across all three technology stacks. The role sits at the intersection of Application Security, DevOps Engineering, and Mainframe Modernization, requiring the ability to influence and collaborate effectively with developers across diverse environments from Kubernetes-based microservices and cloud-native applications to traditional COBOL batch workloads and CL-driven mainframe processes. The ideal candidate will combine deep technical expertise with hands-on execution, driving secure-by-design practices while ensuring security controls are seamlessly integrated into the software delivery lifecycle without compromising engineering velocity.

Key Responsibilities

Enforce Security Gates Across All Stacks

  • Convert Fortify SAST from advisory/report-only mode to a blocking gate: Critical and High severity findings must fail the build for the Modern (.NET Core/AKS), Legacy (.NET/IIS), and Core COBOL (mainframe) pipelines.
  • Define and tune Fortify rulesets, filters, and issue-suppression policies per stack to minimize false positives while preserving enforcement integrity.
  • Drive the exception/waiver process for findings that cannot be remediated immediately (compensating controls, documented risk acceptance, expiry dates).

Extend and Mature Security Tooling Coverage

  • Extend Sonatype SCA to the legacy IIS/.NET Framework 4.8 / VB.NET stack, including NuGet and legacy package dependency scanning.
  • Assess Fortify (or Arcad) rulesets for COBOL, pilot on the mainframe codebase, and deploy where technically feasible; document coverage gaps and compensating controls where static analysis is not viable.
  • Maintain and tune WebInspect DAST scans against staging/pre-prod environments for all applications.
  • Integrate Dynatrace and Splunk signals into the security workflow for runtime visibility and post-deployment monitoring.

DevSecOps Pipeline Engineering

  • Embed SAST (Fortify), DAST (WebInspect), and SCA (Sonatype) directly into CI/CD pipelines across GitHub Actions, Ansible, and Harness.
  • Implement build-breaker logic and quality/security gates so pipelines fail deterministically on policy violations, with clear developer-facing feedback.
  • Integrate SonarQube for code quality and security hotspots alongside Fortify, avoiding tool overlap/conflict.
  • Manage secure artifact promotion through Nexus, including scanning gates prior to promotion between environments.
  • Automate vulnerability remediation workflows: auto-ticketing, developer notification, re-scan verification, and closure evidence for audit purposes.

Establish Remediation SLAs

  • Stand up a remediation pipeline with a target SLA of under 30 days for Critical/High findings across SAST, DAST, and SCA.
  • Build tracking, reporting, and escalation workflows (dashboards, ticket auto-creation, aging reports) so overdue findings are visible to engineering leadership and the CISO.
  • Define severity-based SLA tiers (e.g., Critical: 15 days, High: 30 days, Medium: 90 days) and get sign-off from engineering and compliance stakeholders.

Governance, Metrics & Stakeholder Management

  • Report pipeline enforcement status, SLA compliance, and risk trends to the CISO and engineering leadership on a regular cadence.
  • Partner with development leads across all three stacks to drive remediation without stalling delivery velocity.
  • Contribute security control evidence to ISO 27001, SOC 2, NIST CSF, and ISO 42001 audit cycles.
  • Maintain documentation for tool configuration, gate logic, exception handling, and rollback procedures.

AI-Augmented Findings Orchestration & Remediation

  • Operate AI agents to orchestrate findings intake across Fortify, WebInspect, and Sonatype - correlating, deduplicating, and prioritizing results into a single actionable queue.
  • Use AI-assisted triage to distinguish true positives from false positives, reducing manual review load while maintaining audit-defensible reasoning for every disposition.
  • Use AI agents for auto-generate remediation guidance and, where appropriate, remediation code suggestions for developers, with human review gates before merge.
  • Establish guardrails, human-in-the-loop checkpoints, and audit trails for all AI-driven security decisions to satisfy ISO 27001 / SOC 2 / ISO 42001 evidentiary requirements.
  • Measure and report AI-assisted triage performance (false-positive reduction rate, mean time to triage, agent accuracy drift).

Tools & Platforms

Category Tools

Source Control GitHub / GitLab

CI/CD GitHub Actions, Ansible, Harness

Artifact Management Nexus

SAST Fortify

SCA Sonatype

DAST WebInspect

Code Quality / Build Gating SonarQube, Build Breaker

Observability Dynatrace, Splunk

Essential Skills & Experience

  • 10+ years in Application Security / DevSecOps, with at least 2-3 years in a lead capacity.
  • Proven, hands-on experience implementing and enforcing SAST/DAST/SCA gates in CI/CD pipelines.
  • Direct experience with Fortify (SAST) in an enforcing/blocking configuration, ideally across multiple technology stacks.
  • Working knowledge of Sonatype (or equivalent SCA) and WebInspect (or equivalent DAST) in production pipelines.
  • Practical exposure to at least two of the three target stacks: cloud-native .NET/Kubernetes, legacy .NET/IIS, and mainframe/COBOL; candidates with all three are strongly preferred.
  • Experience with GitHub Actions, Ansible, and/or Harness pipeline authoring, including custom actions/plugins for security gating.
  • Familiarity with Nexus repository management and secure artifact promotion practices.
  • Experience defining and operating remediation SLA programs with measurable compliance reporting.
  • Exposure to compliance frameworks relevant to a lean, cloud-native SMB environment: ISO 27001, SOC 2, NIST CSF, GDPR; ISO 42001 awareness a plus.
  • Strong stakeholder management skills - able to hold the line on security gates while working constructively with developers across very different tech generations.
  • Hands-on experience with AI agents / LLM-based tooling for security findings orchestration, triage, and remediation workflows.
  • Demonstrated experience reducing false-positive rates through AI-assisted or ML-assisted triage, including training/fine-tuning models or rule-based classifiers on historical findings data.
  • Understanding of AI governance and safety practices (human-in-the-loop review, audit logging, model drift monitoring) as applied to security decision-making.

Disclaimer: Diverse Lynx LLC is an Equal Opportunity Employer. All applicants and employees are evaluated without discrimination, based solely on their qualifications, ability, competence and performance. This email and its attachments may contain confidential or proprietary information and is intended only for the recipient(s). If you received this message in error, please disregard it and notify the sender. If you no longer wish to receive our communications, you may unsubscribe at any time.

Security Notice: Our official website is www.diverselynx.com We do not operate or authorize any other websites representing Diverse Lynx LLC.

Numbers & Facts

LocationBerkeley Heights, NJ
Salary$70–$75 Per Hour

Skills

  • Ansibleunmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Artificial Intelligence (AI) Agentsunmatched
  • Cadenceunmatched
  • Cloud Applicationsunmatched
  • Cloud Computingunmatched
  • Cobol Programming Languageunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • DevOpsunmatched
  • Documentationunmatched
  • Error Handlingunmatched
  • Establish Prioritiesunmatched
  • GitHubunmatched
  • HP WebInspectunmatched
  • ISO (International Organization for Standardization)unmatched
  • Lead Generationunmatched
  • Leadershipunmatched
  • Lynxunmatched
  • Machine Toolunmatched
  • Mainframe Computerunmatched
  • Metricsunmatched
  • Microservicesunmatched
  • Microsoft .NETunmatched
  • Microsoft ASP.NET (Active Server Page)unmatched
  • Microsoft IIS Web Server (Internet Information Services)unmatched
  • Microsoft Visual Basic.NETunmatched
  • Microsoft Windows Azureunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Risk Managementunmatched
  • Security Softwareunmatched
  • Service Level Agreement (SLA)unmatched
  • Software Testingunmatched
  • Splunkunmatched
  • Status Reportsunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Web Client Plug-insunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder