What are the responsibilities and job description for the Application Security (AppSec) Engineer position at Spectra Force?
Role: Application Security (AppSec) Engineer Location: Maryland Heights, MO (Onsite) Duration: 13.1 Months Top Required Skills Application Security (AppSec) Secure SDLC / DevSecOps SAST, DAST, IAST & SCA Web, Mobile & API Security Testing Manual Penetration Testing & Business Logic Testing Threat Modeling Vulnerability Management Secure Code Review CI/CD Security Integration Job Summary The Application Security (AppSec) Engineer will focus on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes. The ideal candidate will have strong expertise in Secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing. This role will help improve the security posture of web, mobile, and microservices-based applications while supporting secure development practices without impacting engineering velocity. Key Responsibilities Application Security Engineering Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications. Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines. Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools. Enable continuous post-deployment security validation and risk monitoring. Security Testing & Validation Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning. Perform authenticated and unauthenticated security assessments of applications and APIs. Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services. Validate remediation effectiveness and secure deployment practices. DevSecOps Integration Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms. Automate vulnerability triage, prioritization, and remediation workflows. Develop security-as-code controls and policy enforcement mechanisms. Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives. Vulnerability Management Analyze findings from multiple security tools and eliminate false positives. Prioritize vulnerabilities based on business risk, exploitability, and application criticality. Track remediation efforts throughout SDLC and release cycles. Develop security metrics, dashboards, and executive reporting. Developer Enablement Conduct secure coding reviews and developer education sessions. Establish security champions programs across engineering teams. Provide remediation guidance and hands-on support during application releases. Drive adoption of secure development standards and best practices. Cloud & API Security Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms. Secure REST, GraphQL, and microservice-based APIs. Evaluate Infrastructure-as-Code (IaC) and container security controls using Terraform, ARM, CloudFormation, or similar technologies. Support software supply chain security initiatives, including SBOM and SCA validation. Required Qualifications 8–15 years of experience in Application Security, DevSecOps, or Security Architecture. Experience securing large-scale enterprise applications across cloud and hybrid environments. Strong experience with Secure SDLC and DevSecOps practices. Hands-on experience with automated application security testing tools, including SAST, DAST, SCA, and IAST. Experience with manual penetration testing, business logic testing, threat modeling, and secure code reviews. Experience integrating application security controls into CI/CD pipelines. Years of Experience: 12 Years Preferred Certifications CISSP CSSLP GWAPT OSCP CEH AWS Security Certifications Azure Security Certifications