Application Security Engineer
Job Description
The Application Security Engineer is an onsite role in Bethlehem, PA focused on embedding security by design across the enterprise SDLC, with a salary of USD 125,000 per year.
Responsibilities
- Evaluate and continuously refine SDLC processes, tooling, and release workflows from a security perspective.
- Conduct gap analyses against secure-development frameworks, including NIST SSDF and OWASP ASVS.
- Define, maintain, and evolve secure development standards and procedures aligned with PCI DSS and privacy regulations such as CCPA and GDPR.
- Collaborate with engineering teams to propose and implement practical security improvements across the SDLC.
- Embed security controls across all SDLC phases, including planning, design, coding, testing, deployment, and maintenance.
- Deliver threat modeling, secure-design guidance, and architecture reviews of applications.
- Establish and support secure design and code-review practices, coaching developers on security best practices.
- Balance security requirements with developer experience and business needs to minimize friction while increasing security maturity.
- Deploy, operate, and optimize application security tooling such as SAST, DAST, and SCA solutions.
- Integrate security tooling, including Snyk and Checkmarx, into CI/CD pipelines to enable automated vulnerability detection.
- Define and enforce security gates at key points within development and release workflows.
- Ensure vulnerability findings are actionable, prioritized, and integrated into remediation processes.
- Support static, dynamic, and penetration testing activities in collaboration with internal and external resources.
- Integrate vulnerability management, continuous monitoring, and remediation tracking into the SDLC.
- Provide application-security support during security incidents and assist teams with investigation and remediation.
- Support secure platform and environment modernization efforts, including container security, OS hardening, and secrets management (e.g., Vault, Azure Key Vault).
- Contribute to application and platform architecture improvements focused on security, stability, and resilience.
Requirements
- 3+ years of experience in Application Security or Software Engineering with a focus on secure development practices.
- Hands-on experience implementing secure SDLC frameworks such as NIST SSDF and OWASP ASVS.
- Practical experience integrating SAST/DAST tools into CI/CD pipelines and workflows.
- Working knowledge of PCI DSS and privacy regulations (CCPA/GDPR) as they impact software development.
- Strong communication skills with the ability to influence and collaborate with engineering teams.
Technologies
- SAST
- DAST
- SCA
- Snyk
- Checkmarx
- Vault
- Azure Key Vault
- NIST SSDF
- OWASP ASVS
- PCI DSS
- CCPA/GDPR
- OWASP Top 10
Benefits
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Tuition reimbursement
- Vision insurance
Preferred Qualifications
- Experience with container security, image hardening, and secrets management technologies.
- Familiarity with the OWASP Top 10, API security, and modern application security practices.
- Experience coordinating or supporting penetration testing or DAST programs.
- Relevant certifications such as CSSLP, CISSP, GWAPT, GCSA, or similar.