Demo

Application Security Engineer

HDJ & Associates, Inc.
Pittsburgh, PA Full Time
POSTED ON 12/13/2025
AVAILABLE BEFORE 2/13/2026
Are you ready to elevate security practices to new heights? Our organization is on the lookout for a dynamic Application Security Engineer who will revolutionize our application security strategies. Located in the vibrant city of Pittsburgh, PA, this on-site role is the perfect opportunity to collaborate with key stakeholders in Technology, Product, and Strategic Business Units to tackle the most pressing security challenges head-on.

As a Application Security Engineer, you will spearhead the secure software development lifecycle, embedding cutting-edge security practices at every step of our DevOps pipelines and application security processes. Your expertise in maturity models like DSOMM (DevSecOps Maturity Model), CI/CD pipelines, and vulnerability management tools will be crucial in transforming our security landscape. Join forces with our engineering, DevOps, Product, and Technology teams to implement automated security controls, threat modeling, and risk mitigation strategies that will shape the future of our software development lifecycle.

This role requires minimal travel and the ability to work in a fast-paced, dynamic environment. The position may involve working outside normal business hours to address urgent compliance or security incidents.

Key Responsibilities

DevSecOps & Maturity Measurement Implementation: 

  • Assess, report, and assist with improving application security and DevSecOps Maturity, utilizing a measurement framework such as DSOMM or BSIMM, across the organization. 
  • Define and implement security policies, standards, and best practices for DevOps, CI/CD pipelines, and cloud security. 
  • Work with development and DevOps teams to integrate automated security testing (SAST, DAST, SCA, IaC security scanning, etc.) into pipelines. 
  • Establish security gates in CI/CD workflows to prevent deployment of vulnerable code. 

Application Security & Code Vulnerabilities:

  • Perform code reviews, static/dynamic security testing (SAST/DAST), and secure coding guidance to developers. 
  • Identify and remediate vulnerabilities in application code, libraries, containers, and infrastructure as code (IaC). 
  • Develop and enforce secure coding standards in alignment with OWASP, NIST, and other frameworks. 
  • Conduct threat modeling and security architecture reviews for applications and services. For example, assist application teams with developing accurate data flow diagrams and developing appropriate identity management solutions. 
  • Manage and mature Bot Management services for all applications. Assist with WAF management and maturity. 
  • Improve secrets management and API security. 

Vulnerability Management & Risk Reduction: 

  • Manage and mature enterprise-wide Bug Bounty program (e.g. BugCrowd, HackerOne) 
  • Manage vulnerability scanning tools (e.g., Tenable, Qualys, Sonar, Snyk) and prioritize remediation efforts. 
  • Track, assess, and coordinate the remediation of vulnerabilities across the application, infrastructure, and cloud environments. 
  • Develop risk-based vulnerability management workflows and collaborate with engineering teams to drive fixes. 
  • Monitor security dashboards and metrics, ensuring vulnerabilities are patched in alignment with SLAs. 

Security CI/CD Automation & Tooling: 

  • Implement security automation using APIs, scripts, and cloud-native security controls. 
  • Work with DevOps engineers to integrate security tooling (like SemGrep, Snyk, Cycode) or within Jenkins, GitHub, GitLab CI/CD, or AWS DevOps. 
  • Automate security findings triage, reporting, and prioritization processes. 

Security Awareness & Collaboration: 

  • Train and mentor developers on secure coding, threat modeling, DevSecOps, and vulnerability management best practices. 
  • Collaborate with security operations, incident response, and compliance teams on security initiatives. 
  • Participate in security assessments, penetration testing, and security incident investigations.

Requirements

Qualifications & Experience
  • Bachelor’s Degree in Information Security, Cybersecurity, Computer Science, or a related field OR a minimum of 6 years’ equivalent experience in lieu of a degree
  • 4 years of experience in application security, DevSecOps, and security engineering OR a combination of 2 years experience as a developer and 2 years in application security, DevSecOps, and security engineering
  • Hands-on experience with DevSecOps tools (SAST, DAST, SCA, container security, IaC security), integrating security solutions within CI/CD pipelines, strong knowledge of secure coding principles (OWASP Top 10, SANS CWE Top 25), and familiarity with AI ML or LLM usage within security tooling. 
  • Experience with vulnerability management, web app penetration testing tooling, and security certifications like CISSP, OSCP, GCPN, GCSA, AWS Security Specialty, or CSSLP are preferred. 
  • Proficiency in Bot Management tooling, client-side monitoring tooling, and implementing maturity measurement frameworks such as DSOMM or BSIMM in an enterprise setting. 
  • Ability to understand and communicate best-practice system architectures, data flows, and security controls within modern web applications and cloud (SaaS/PaaS, IaaS). 
  • Excellent verbal and written communication skills, with the ability to communicate complex security concepts to technical and non-technical stakeholders. 

Salary.com Estimation for Application Security Engineer in Pittsburgh, PA
$81,724 to $104,670
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Engineer?

Sign up to receive alerts about other jobs on the Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$155,218 - $198,966
Income Estimation: 
$188,900 - $249,994
Income Estimation: 
$187,890 - $240,773
Income Estimation: 
$73,727 - $94,067
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$90,707 - $120,959
Income Estimation: 
$91,486 - $118,193
Income Estimation: 
$92,017 - $124,111
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$131,745 - $167,716
Income Estimation: 
$144,503 - $184,592
Income Estimation: 
$102,541 - $137,871
Income Estimation: 
$153,752 - $200,235
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at HDJ & Associates, Inc.

  • HDJ & Associates, Inc. Wexford, PA
  • If you don't see an open position that fits your background or experience today, apply here so that we have your information in our database and we can con... more
  • 5 Days Ago

  • HDJ & Associates, Inc. Pittsburgh, PA
  • Our client has an exciting opportunity to join their team as an outside sales Healthcare Account Executive. You will be the face of the company with the ho... more
  • 5 Days Ago

  • HDJ & Associates, Inc. Pittsburgh, PA
  • Our client is looking for a Media Ad Operations Specialist to be responsible for executing media campaigns that help clients effectively reach their target... more
  • 5 Days Ago

  • HDJ & Associates, Inc. Pittsburgh, PA
  • Our client is hiring a Senior Systems Engineer for a company that improves clients’ operations by creatively solving business problems through the effectiv... more
  • 5 Days Ago


Not the job you're looking for? Here are some other Application Security Engineer jobs in the Pittsburgh, PA area that may be a better fit.

  • Huntington National Bank Pittsburgh, PA
  • Description Application Security Engineer – Expert About The Role We are seeking a highly skilled and experienced Application Security Engineer, Expert to ... more
  • 5 Days Ago

  • YinzCam, Inc. Pittsburgh, PA
  • Description ABOUT YINZCAM YinzCam is a tech leader in sports, developing mobile apps, Connected TV apps, and analytics solutions for sports teams, leagues,... more
  • 20 Days Ago

AI Assistant is available now!

Feel free to start your new journey!