This position is no longer accepting applications
Closed on August 24, 2026.
This role is filled β get an email when new Information Security roles open on EngineerJobs.io:
Application Security Engineer
Application Security
Cybersecurity Tools
DevSecOps
Dynamic Application Security Testing
Information Security
InfoSec
Risk Management
Security
Security Automation
Security Compliance
Security Standards
Security Testing
Static Application Security Testing
View similar jobs
Get alerted when similar jobs are posted — set up a New Information Security jobs on EngineerJobs.io alert.
See other roles at Cigars International.
Job Description
The Application Security Engineer is an onsite role in Bethlehem, PA focused on embedding security by design across the enterprise SDLC, with a salary of USD 125,000 per year.
Responsibilities
- Evaluate and continuously refine SDLC processes, tooling, and release workflows from a security perspective.
- Conduct gap analyses against secure-development frameworks, including NIST SSDF and OWASP ASVS.
- Define, maintain, and evolve secure development standards and procedures aligned with PCI DSS and privacy regulations such as CCPA and GDPR.
- Collaborate with engineering teams to propose and implement practical security improvements across the SDLC.
- Embed security controls across all SDLC phases, including planning, design, coding, testing, deployment, and maintenance.
- Deliver threat modeling, secure-design guidance, and architecture reviews of applications.
- Establish and support secure design and code-review practices, coaching developers on security best practices.
- Balance security requirements with developer experience and business needs to minimize friction while increasing security maturity.
- Deploy, operate, and optimize application security tooling such as SAST, DAST, and SCA solutions.
- Integrate security tooling, including Snyk and Checkmarx, into CI/CD pipelines to enable automated vulnerability detection.
- Define and enforce security gates at key points within development and release workflows.
- Ensure vulnerability findings are actionable, prioritized, and integrated into remediation processes.
- Support static, dynamic, and penetration testing activities in collaboration with internal and external resources.
- Integrate vulnerability management, continuous monitoring, and remediation tracking into the SDLC.
- Provide application-security support during security incidents and assist teams with investigation and remediation.
- Support secure platform and environment modernization efforts, including container security, OS hardening, and secrets management (e.g., Vault, Azure Key Vault).
- Contribute to application and platform architecture improvements focused on security, stability, and resilience.
Requirements
- 3+ years of experience in Application Security or Software Engineering with a focus on secure development practices.
- Hands-on experience implementing secure SDLC frameworks such as NIST SSDF and OWASP ASVS.
- Practical experience integrating SAST/DAST tools into CI/CD pipelines and workflows.
- Working knowledge of PCI DSS and privacy regulations (CCPA/GDPR) as they impact software development.
- Strong communication skills with the ability to influence and collaborate with engineering teams.
Technologies
- SAST
- DAST
- SCA
- Snyk
- Checkmarx
- Vault
- Azure Key Vault
- NIST SSDF
- OWASP ASVS
- PCI DSS
- CCPA/GDPR
- OWASP Top 10
Benefits
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Tuition reimbursement
- Vision insurance
Preferred Qualifications
- Experience with container security, image hardening, and secrets management technologies.
- Familiarity with the OWASP Top 10, API security, and modern application security practices.
- Experience coordinating or supporting penetration testing or DAST programs.
- Relevant certifications such as CSSLP, CISSP, GWAPT, GCSA, or similar.