EngineerJobs.io
← Back to all jobs

Job Description

The Application Security Engineer is an onsite role in Bethlehem, PA focused on embedding security by design across the enterprise SDLC, with a salary of USD 125,000 per year.

Responsibilities

  • Evaluate and continuously refine SDLC processes, tooling, and release workflows from a security perspective.
  • Conduct gap analyses against secure-development frameworks, including NIST SSDF and OWASP ASVS.
  • Define, maintain, and evolve secure development standards and procedures aligned with PCI DSS and privacy regulations such as CCPA and GDPR.
  • Collaborate with engineering teams to propose and implement practical security improvements across the SDLC.
  • Embed security controls across all SDLC phases, including planning, design, coding, testing, deployment, and maintenance.
  • Deliver threat modeling, secure-design guidance, and architecture reviews of applications.
  • Establish and support secure design and code-review practices, coaching developers on security best practices.
  • Balance security requirements with developer experience and business needs to minimize friction while increasing security maturity.
  • Deploy, operate, and optimize application security tooling such as SAST, DAST, and SCA solutions.
  • Integrate security tooling, including Snyk and Checkmarx, into CI/CD pipelines to enable automated vulnerability detection.
  • Define and enforce security gates at key points within development and release workflows.
  • Ensure vulnerability findings are actionable, prioritized, and integrated into remediation processes.
  • Support static, dynamic, and penetration testing activities in collaboration with internal and external resources.
  • Integrate vulnerability management, continuous monitoring, and remediation tracking into the SDLC.
  • Provide application-security support during security incidents and assist teams with investigation and remediation.
  • Support secure platform and environment modernization efforts, including container security, OS hardening, and secrets management (e.g., Vault, Azure Key Vault).
  • Contribute to application and platform architecture improvements focused on security, stability, and resilience.

Requirements

  • 3+ years of experience in Application Security or Software Engineering with a focus on secure development practices.
  • Hands-on experience implementing secure SDLC frameworks such as NIST SSDF and OWASP ASVS.
  • Practical experience integrating SAST/DAST tools into CI/CD pipelines and workflows.
  • Working knowledge of PCI DSS and privacy regulations (CCPA/GDPR) as they impact software development.
  • Strong communication skills with the ability to influence and collaborate with engineering teams.

Technologies

  • SAST
  • DAST
  • SCA
  • Snyk
  • Checkmarx
  • Vault
  • Azure Key Vault
  • NIST SSDF
  • OWASP ASVS
  • PCI DSS
  • CCPA/GDPR
  • OWASP Top 10

Benefits

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance

Preferred Qualifications

  • Experience with container security, image hardening, and secrets management technologies.
  • Familiarity with the OWASP Top 10, API security, and modern application security practices.
  • Experience coordinating or supporting penetration testing or DAST programs.
  • Relevant certifications such as CSSLP, CISSP, GWAPT, GCSA, or similar.

Similar Jobs