Application Security Engineer
Job Description
Application Security Engineer role with Wolfe, LLC in Pittsburgh, PA, onsite five days per week.
Responsibilities
- Conduct code reviews, SAST/DAST testing, basic penetration testing, and lightweight threat modeling, collaborating with developers to remediate vulnerabilities across application code, libraries, containers, and infrastructure as code.
- Integrate and operate automated security tooling (for example Snyk, SemGrep, Cycode) within CI/CD pipelines across code repositories such as GitHub, GitLab, Jenkins, and AWS DevOps, and assist with triage and reporting of findings.
- Oversee vulnerability management programs, scanning tools, and the enterprise Bug Bounty program, tracking and prioritizing remediation against defined SLAs.
- Support Bot Management, Web Application Firewall, secrets management, and API security controls across Wolfe's applications.
- Promote secure coding standards aligned with OWASP and SANS CWE Top 25, and contribute to measuring DevSecOps maturity using DSOMM or BSIMM.
- Collaborate with developers, security operations, product management, and incident response teams, sharing secure-coding and vulnerability-management practices while expanding personal expertise.
Requirements
- Minimum 2 years of experience in application security, DevSecOps, or security-exposed software development, including developers transitioning into security roles; Bachelor's degree in Information Security, Cybersecurity, Computer Science, or a related field (equivalent experience accepted).
- Strong coding background with working knowledge of secure coding principles (OWASP Top 10, SANS CWE Top 25).
- Hands-on exposure to CI/CD pipelines (GitHub, GitLab, Jenkins, AWS DevOps) and interest in embedding security tooling into those workflows.
- Excellent verbal and written communication skills, capable of explaining security concepts to technical and non-technical teammates.
- Willingness to learn enterprise security tooling (vulnerability scanners, Bot Management, SAST/DAST/SCA) and maturity frameworks such as DSOMM or BSIMM; prior experience is a plus but not required.
- No mandatory certifications; familiarity with CISSP, OSCP, GCSA, AWS Security Specialty, or CSSLP is a plus, and Wolfe will support pursuing them.
Technologies
- Snyk
- SemGrep
- Cycode
- GitHub
- GitLab
- Jenkins
- AWS DevOps
- DSOMM
- BSIMM
- OWASP Top 10
- SANS CWE Top 25
- SAST
- DAST
- SCA
- Bot Management
- WAF
Benefits
- Restricted Stock Units (RSUs)
- Profit Share and/or Incentive Bonus
- Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of the premium)
- Short-Term Disability Insurance (Wolfe pays 100% of the premium)
- Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
- PTO (vacation and sick time)
- Corporate Holidays and Floating Holidays
- 401(k)
- Employee recognition program
- Charitable donation to a charity of your choice yearly
- Employee referral bonus
- Tuition reimbursement
- Internal training and information sessions
- Family Picnic, Holiday Party, and other outings
- Internal Culture Club
Impact Statement
- Update the existing Application Security Strategy and improve monitoring and KPI reporting
- Deliver a significant improvement to at least one automated security tool in the production CI/CD pipeline and establish a documented triage workflow
- Drive additional Bug Bounty submissions and strengthen bot management protections before the end of Q3
- Provide product and technology advisement and testing for new application and AI functionality
- Develop and plan a targeted Application and AI development training program