EngineerJobs.io
← Back to all jobs

Job Description

Calance US is hiring a Senior Application Security Engineer for a hybrid role in Houston, TX. The position centers on embedding security into the software development lifecycle using SAST and DAST, augmented by AI-enabled tooling. The role collaborates with development, DevOps, and security teams to promote secure coding practices and strengthen the application risk posture. Compensation is USD 80 - 100 per hour, and the role requires a minimum of seven years of relevant experience.

Role Overview

The Senior Application Security Engineer will help secure the software development lifecycle by combining traditional SAST/DAST approaches with AI-enabled tools to identify and remediate code vulnerabilities. This role works closely with development, DevOps, and security teams to drive secure coding practices and scale risk improvements across the organization. AI-driven capabilities will be leveraged to enhance vulnerability detection accuracy, automate code reviews, and accelerate remediation throughout the SDLC.

Responsibilities

  • Integrate application security into the SDLC, CI/CD pipelines, and developer workflows
  • Lead and perform SAST, DAST, SCA, and API security testing
  • Utilize AI-based code scanning to improve vulnerability detection, reduce false positives, and speed remediation
  • Collaborate with developers to remediate vulnerabilities and strengthen secure coding practices
  • Conduct threat modeling and security reviews for applications and APIs
  • Track, analyze, and report security metrics such as vulnerability trends and remediation timelines
  • Deploy and manage AI-powered code scanning across source code, APIs, and dependencies
  • Apply AI/ML to identify complex vulnerability patterns, insecure coding practices, and hidden attack paths
  • Leverage AI to reduce false positives and improve signal-to-noise, enabling efficient triage
  • Provide root-cause analysis and actionable remediation guidance through AI-assisted insights
  • Integrate AI-enabled security scanning into CI/CD pipelines to deliver real-time feedback on development and commits
  • Evaluate and optimize AI models and rulesets to improve detection accuracy and align with enterprise risk priorities
  • Partner with engineering teams to embed AI-assisted code review and secure coding recommendations into pull requests and IDE plugins
  • Monitor and measure the effectiveness of AI-based scanning using metrics such as detection rates and remediation speed
  • Stay current with emerging AI security tools, LLM-based code analysis, and automated remediation technologies, promoting adoption where value is demonstrated

Requirements

  • 7+ years of experience in application security, DevSecOps, or secure software engineering
  • Strong knowledge of OWASP Top 10 and secure coding practices
  • Experience with application security tools such as SAST, DAST, and SCA
  • Experience integrating security into CI/CD pipelines
  • Knowledge of Ghazdo and GitHub Advance security
  • Proficiency in at least one programming language (Python, Java, JavaScript)

Technologies

  • Python
  • Java
  • JavaScript
  • SAST
  • DAST
  • SCA
  • GitHub Advanced Security
  • Ghazdo

Similar Jobs