3Core Systems , Inc Logo

3Core Systems , Inc

Senior Application Security Engineer DevSecOps and CICD

Posted 10 Days Ago
In-Office or Remote
Hiring Remotely in Austin, TX
Senior level
In-Office or Remote
Hiring Remotely in Austin, TX
Senior level
Embeds application security into the SDLC through DevSecOps processes, security assessments, repository scanning, vulnerability triage, remediation validation, and secure code review. Uses tools such as Burp Suite, CodeQL, SAST, SCA, and secret scanning across applications, APIs, cloud workloads, and infrastructure. Develops security metrics and executive dashboards, coaches development teams, participates in Agile ceremonies, and promotes secure coding and responsible AI-assisted security practices.
The summary above was generated by AI

This is a remote position.

Job Title: Senior Application Security Engineer DevSecOps and CICD

Location: Remote, USA

Estimated Duration :12+ Months 

Must Have Skills/Attributes: Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability

Experience Desired: Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs); Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)

Required Minimum Education: Bachelor’s Degree

Preferred Education: Master’s Degree

Job Description

  • ***Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***

Education Requirements:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Preferred Education:

  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Required Skills for the Cybersecurity Engineer:

  • -5-7 years of hands-on application security/DevSecOps experience
  • - Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
  • - Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
  • - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
  • - Cloud security, identity and access management, and modern application architectures
  • - Safe and effective use of AI-assisted development and security tools
  • - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
  • - Security metrics, coverage reporting, and executive dashboard development
  • - Excellent communication, stakeholder management, presentation, and documentation skills
  • - Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
  • - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
  • - Coaching and knowledge sharing — champions a security-first culture
  • - Comfortable operating within Scrum/Agile delivery and managing own work items

Cybersecurity Engineer Responsibilities:

  • - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
  • - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
  • - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
  • - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
  • - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
  • - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes

 

Typical task breakdown:

  • Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
  • Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
  • Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
  • Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
  • Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
  • Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
  • Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks find value in our e-mail notifications as you continue to consider options for your professional career.


Similar Jobs

40 Minutes Ago
Remote or Hybrid
United States
160K-190K Annually
Senior level
160K-190K Annually
Senior level
Consumer Web • eCommerce • Internet of Things
Represent the company in Internet standards working groups, track adjacent drafts and discussions, revise technical specifications, respond to reviews, and develop reference implementations, interoperability tests, and demos. Build credibility across standards and open-source communities while serving as a technical delegate to the CTO. Over time, author independent standards drafts and engage with engineering, enterprise, and government audiences.
Top Skills: DnsInternet ProtocolsInteroperability TestingOauthOpenid ConnectPkiReference ImplementationsVerifiable Credentials
2 Hours Ago
In-Office or Remote
United States
105K-250K Annually
Junior
105K-250K Annually
Junior
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Develop and manage a branch-based wealth management practice by conducting client discoveries, creating tailored financial plans, driving new business development and referrals, conducting proactive outreach, and coordinating with internal specialists for investment, insurance, estate, and financial planning services.
2 Hours Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
80K-138K Annually
Senior level
80K-138K Annually
Senior level
Artificial Intelligence • Marketing Tech • Software
Own new-client implementations for Movable Ink’s personalization platforms, serving as the project manager and product expert. Responsibilities include developing project plans, coordinating clients and internal teams, designing technical solutions, configuring and QAing campaigns, delivering platform training, troubleshooting issues, and ensuring launches achieve client goals and KPIs. The role requires expertise in mobile messaging, digital marketing, web technologies, data infrastructure, and client or project management.
Top Skills: APIsCloud Data WarehousesData LakesEmail Service ProvidersETLHTMLJavaScriptMmsPush NotificationsSms

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account