What are the responsibilities and job description for the Application Security Specialist position at Motion Recruitment?
DevSecOps Engineer / Application Security Specialist
Location: Greensboro, NC (Flexible Hybrid)
Duration: Contract-to-Hire
Join a growing Application Security team focused on embedding security throughout the software development lifecycle. This flexible hybrid opportunity supports enterprise-wide security initiatives through secure CI/CD implementation, security automation, vulnerability management, and developer enablement. The ideal candidate will bring a strong blend of hands-on software development and Application Security experience, enabling them to work effectively with engineering teams while improving application security posture across the organization.
This role provides exposure to modern DevSecOps practices, cloud security, security automation, and enterprise-scale application security programs. You'll work across web, mobile, API, and cloud-enabled applications while partnering closely with developers to identify vulnerabilities, drive remediation efforts, and enhance secure development practices. This is an excellent opportunity for someone looking to make a measurable impact on security operations while positioning themselves for long-term growth through a potential contract-to-hire pathway.
Contract Duration: Contract-to-Hire
Required Skills & Experience
· Bachelor's Degree in Computer Science, Cybersecurity, Information Security, Information Technology, Engineering, or equivalent experience
· 3–6 years of Application Security, DevSecOps, Software Development, Security Testing, or Vulnerability Management experience
· Strong hands-on Application Security experience
· Secure coding and secure SDLC expertise
· Experience supporting SAST, SCA/OSCA, and DAST programs
· API security assessment experience
· Vulnerability validation and remediation guidance experience
· DevSecOps and CI/CD pipeline integration experience
· Experience working directly with software development teams
· Knowledge of REST and SOAP APIs
· Experience with GitHub, Jira, and Jenkins
· Cloud security experience (AWS and/or Azure)
· Development or scripting experience in Java, Python, Ruby, Go, Node.js, or similar languages
· Strong communication and stakeholder engagement skills
· Experience explaining vulnerabilities, risks, and remediation strategies to technical and non-technical audiences
Desired Skills & Experience
· Checkmarx One experience
· Sonatype Nexus IQ experience
· WhiteHat or Black Duck DAST experience
· Noname API Security experience
· NowSecure mobile security experience
· Atlas experience
· Salesforce intake workflow experience
· Jira defect management experience
· Docker and Kubernetes experience
· Enterprise DevSecOps pipeline integration experience
· Mobile application security testing experience
· Experience supporting large enterprise Application Security programs
· Master's Degree in a related field
· Relevant certifications such as CISSP, CSSLP, GIAC, Security , AWS Security, or Azure Security
What You Will Be Doing
Tech Breakdown
· 40% Application Security Assessments & Vulnerability Management
· 35% DevSecOps & Security Tool Integration
· 25% Developer Engagement, Remediation Support & Security Consulting
Daily Responsibilities
· 75% Hands On
· 5% Management Duties
· 20% Team Collaboration
Key Responsibilities
· Support end-to-end Application Security services including intake, assessment scoping, and stakeholder engagement
· Conduct and support SAST, SCA, DAST, API Security, and Mobile Security assessment activities
· Validate vulnerabilities and reduce false positives
· Provide remediation guidance to development teams
· Assist with AppSec backlog reduction and vulnerability closure efforts
· Integrate security tooling into CI/CD pipelines and development workflows
· Support secure software development lifecycle initiatives
· Implement and improve security automation capabilities
· Enhance developer self-service security capabilities
· Support cloud-based DevSecOps and application security processes
· Track and manage security findings through Jira and defect management workflows
· Create documentation and operational procedures for AppSec processes
· Partner with cybersecurity and software engineering teams to improve security posture
· Support web, mobile, API, and cloud-enabled application security assessments
Salary : $75 - $85