Application Security Engineer - Container Team (W2 ONLY NO C2C)
Application Security
Cloud Platforms
Cloud Security
Container Security
Cybersecurity Tools
Data Security
DevSecOps
Facilities Management
Information Security
InfoSec
Project Management
Risk Governance
Security
Security Automation
Security Compliance
Security Operations
Security Scanning
Security Standards
Security Testing
Security Triage
Software Security
Job Description
Matlen Silver is hiring an Application Security Engineer for the Container Team in a contract-to-hire role. This position is based onsite in Charlotte, NC, with the contract-to-hire opportunity also available in Atlanta, GA and Raleigh, NC. The work is hands-on and focused on container security, deploying scanning tooling, and strengthening vulnerability workflows across the SDLC.
This is a 4+ month contract with W2 only (no C2C). The role emphasizes practical problem-solving for scanning accuracy and performance, plus clear technical communication with development teams.
Responsibilities
- Provide hands-on container security support, including deployment of container scanning tools such as Wiz, Prisma, and Aqua Security.
- Troubleshoot complex scanning issues and optimize configurations to improve accuracy and performance.
- Apply strong analytical skills to vulnerability triage and risk prioritization.
- Consult with development teams and explain technical findings effectively through strong communication.
Requirements
- Hands-on experience with container security and deployment of scanning tools (e.g., Wiz, Prisma, Aqua Security).
- Proficiency in scripting languages for automation and tool integration, including Python, Bash, or PowerShell.
- Deep understanding of the secure software development lifecycle (SDLC) and common vulnerabilities such as the OWASP Top 10.
- Ability to troubleshoot complex scanning issues and optimize configurations for accuracy and performance.
- Strong analytical skills for vulnerability triage and risk prioritization.
- Excellent communication skills for consulting with development teams and explaining technical findings.
- Experience integrating security tools into CI/CD pipelines.
- Familiarity with cloud-native security across AWS, Azure, and GCP, as well as container orchestration with Kubernetes.
- Exposure to DevSecOps practices and security automation frameworks.
- Relevant certifications such as OSWE, GWAPT, or CSSLP.
Tools and Technologies
- Wiz, Prisma, Aqua Security
- Python, Bash, PowerShell
- OWASP Top 10
- CI/CD
- AWS, Azure, GCP
- Kubernetes
- DevSecOps
- OSWE, GWAPT, CSSLP
Benefits
- Health, vision, and dental insurance with single and family coverage
- 401(k) plan with employee contributions only