What are the responsibilities and job description for the Applications Security Solutions Engineer position at Vaco by Highspring?
Application Security Engineer (Contract-to-Hire, Hybrid)
Our client, a leading financial institution, is seeking an experienced Application Security Engineer for a 6-month contract-to-hire opportunity in the Columbus, OH market. This role follows a hybrid schedule with four days onsite and one day remote each week. The ideal candidate will play a key role in securing internally developed, acquired, and third-party applications while partnering closely with development, DevOps, risk management, and information security teams.
Key Responsibilities
-
Perform and support application security testing, including SAST, DAST, and SCA.
-
Review, validate, and track remediation of identified vulnerabilities.
-
Conduct and support application penetration testing, including oversight of remediation efforts and reporting of metrics.
-
Coordinate internal and third-party penetration tests; review findings and contribute to remediation planning.
-
Mentor development teams on secure coding practices and embed security throughout the SDLC.
-
Provide threat modeling support and secure design guidance.
-
Assist in securing AI-enabled applications, including evaluating data and model risks.
-
Review application architectures for security vulnerabilities and compliance risks.
-
Support audits and ensure adherence to regulatory requirements.
-
Maintain and enhance application security standards and best practices.
Additional Responsibilities
-
Ensure compliance with organizational policies, procedures, and federal/state regulations.
-
Utilize Microsoft Office and relevant tools to improve workflow efficiency.
-
Collaborate effectively within a team environment.
-
Work with on-site systems and equipment as required.
Qualifications
-
High School Diploma or equivalent required.
-
5–6 years of experience in application security.
-
5–6 years of experience within the financial services industry.
-
5–6 years of hands-on or supporting experience with penetration testing.
Certifications
-
CSSLP, GWAPT, or OSCP (required upon hire).
-
CompTIA Security or CISSP (required upon hire).
Additional Requirements
-
This role is not open to C2C, third-party vendors, visa sponsorship, or student EAD candidates.
Salary : $85