Senior Application Security Engineer

Axelon Services Corporation
  • Jacksonville, FL
  • $70–$75.74 Per Hour
  • Quick Apply
1 day ago

Job Description

Job Title: Senior Application Security Engineer
Location: Jacksonville, FL - In office 5 days
Shift Timings: 8:00 AM – 5:00 PM EST

Position Summary:

  • The Senior Application Security Engineer is responsible for designing, implementing, and optimizing application security capabilities across the software development lifecycle. Working under limited supervision, this individual contributor partners with development, DevOps, architecture, risk, and cybersecurity teams to integrate security testing into delivery processes, identify application vulnerabilities, and improve secure development practices.
  • The role provides technical expertise for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secure code review, and code quality analysis. The engineer configures and tunes scanning technologies, validates findings, supports remediation, and develops meaningful reporting for technical and executive stakeholders.

Must Haves:

  • Experience managing and tuning SAST, DAST, or SCA security scanning platforms.
  • Experience in integrating application security controls into CI/CD and DevSecOps workflows.
  • Experience analyzing vulnerabilities and partnering with development teams to drive remediation.

Nice-to-Have:

  • Experience in regulated environments (financial services preferred).
  • Automation, scripting, and security reporting/dashboard experience.
  • Code Quality Analysis tool administration and configuration experience.

POSITION PURPOSE:Own and optimize application security testing capabilities across the software development lifecycle, with emphasis on SAST, DAST, SCA, SonarQube, scanning configuration, vulnerability triage, and actionable reporting.

    Key Responsibilities and Duties:

    • Administer, configure, tune, and optimize application security platforms supporting SAST, DAST, and SCA capabilities.
    • Manage and maintain SonarQube and similar code analysis technologies, including scanning configurations, rule profiles, quality gates, access, integrations, and reporting.
    • Develop and maintain application security scanning standards, procedures, runbooks, and operating documentation.
    • Integrate application security testing into CI/CD pipelines and DevSecOps workflows in partnership with development and platform engineering teams.
    • Triage and validate security findings, reduce false positives, document risk decisions, and improve the accuracy and usefulness of scan results.
    • Partners with application teams to prioritize and remediate vulnerabilities based on exploitability, business context, compensating controls, and organizational risk criteria.
    • Provide secure coding guidance and technical consultation aligned with OWASP practices, the NIST Secure Software Development Framework, and internal security standards.
    • Create dashboards, metrics, and key risk indicators that communicate application security coverage, finding trends, remediation performance, scan health, and control effectiveness.
    • Analyze recurring vulnerability patterns and recommend preventive controls, developer education, rule changes, or pipeline improvements.
    • Support threat modeling, architecture reviews, secure design assessments, and targeted code reviews for new and existing applications.
    • Assist with audit, examination, and risk assessment requests by providing accurate evidence and documentation for application security controls.
    • Research emerging application security threats, vulnerabilities, attack techniques, and testing methods to continuously improve the program.
    • Serve as a senior technical subject matter expert and mentor, without formal responsibility for assigning, reviewing, or delegating the work of other employees.

    Minimum Qualifications:

    • Bachelor’s degree in Information Security, Computer Science, Software Engineering, or a related field preferred, or equivalent relevant experience.
    • 5 or more years of cybersecurity, software engineering, DevSecOps, vulnerability management, or application security experience.
    • 3 or more years of direct experience operating, administering, or integrating application security scanning technologies.
    • Hands-on experience with SAST and DAST scanning configuration, execution, tuning, triage, and reporting.
    • Working knowledge of SCA, secure code review, vulnerability management, and remediation practices.
    • Experience with SonarQube or a comparable code quality and security analysis platform.
    • Understanding of modern application architectures, APIs, containers, microservices, and cloud-native delivery patterns.
    • Familiarity with CI/CD platforms, source code management, build automation, and DevSecOps processes.
    • Ability to communicate technical risk and remediation guidance clearly to developers, engineers, managers, and nontechnical stakeholders.

    Preferred Qualifications:

    • 7 or more years of cybersecurity, software security, software engineering, or application security experience.
    • Advanced experience with SonarQube administration, custom rule profiles, quality gates, project onboarding, integration, and reporting.
    • Experience with commercial application security technologies such as Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or comparable platforms.
    • Experience integrating security testing into GitHub, GitLab, Azure DevOps, Jenkins, or similar CI/CD platforms.
    • Knowledge of OWASP Top 10, OWASP ASVS, NIST SSDF, secure SDLC practices, and common application weakness classifications.
    • Experience producing operational dashboards, executive metrics, key risk indicators, and trend reporting.
    • Experience working in regulated financial services or another highly regulated enterprise environment.
    • Experience supporting FFIEC, OCC, SOX, PCI DSS, or comparable audit and regulatory requirements.
    • Experience automating application security workflows and reporting through PowerShell, Python, APIs, or vendor scripting.

    Preferred Certifications:

    • CSSLP
    • GWAPT, GWEB, GSSP, or another relevant GIAC certification
    • OSWE or a comparable advanced application security certification
    • CISSP
    • Microsoft Azure Security Engineer Associate, AWS Certified Security – Specialty, or a comparable cloud security certification

    Numbers & Facts

    LocationJacksonville, FL
    Salary$70–$75.74 Per Hour

    Skills

    • Administrative Skillsunmatched
    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Automationunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Improvementunmatched
    • Continuous Integrationunmatched
    • DevOpsunmatched
    • Documentationunmatched
    • Financial Servicesunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • GitHubunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Jenkinsunmatched
    • Mentoringunmatched
    • Metricsunmatched
    • Microservicesunmatched
    • Microsoft Windows Azureunmatched
    • Model Reviewunmatched
    • Onboardingunmatched
    • PCI-DSSunmatched
    • Pattern Analysisunmatched
    • Python Programming/Scripting Languageunmatched
    • Quality Assurance Methodologyunmatched
    • Regulatory Requirementsunmatched
    • Reporting Dashboardsunmatched
    • Reporting Skillsunmatched
    • Riskunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Scripting (Scripting Languages)unmatched
    • Secure Codingunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Infrastructureunmatched
    • Security Softwareunmatched
    • Software Administrationunmatched
    • Software Developmentunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Software Testingunmatched
    • Source Code/Configuration Management (SCM)unmatched
    • Threat Modelingunmatched
    • Trend Analysisunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder