Apolis logo

Application Security (AppSec) Engineer

Apolis

  • Maryland Heights, MO
  • 9 days ago
  • $55–$60 Per Hour

Highlights

This role focuses on embedding security testing, vulnerability management, and business logic validation into CI/CD pipelines and post-deployment processes to strengthen the organization's application security posture across web, mobile, and microservices architectures. The ideal candidate will have expertise in Secure SDLC, DevSecOps, automated security testing, cloud-native applications, APIs, vulnerability management, and manual penetration testing.

Numbers & Facts

LocationMaryland Heights, MO
IndustryComputer/IT Services
Salary$55–$60 Per Hour
Company Size500 to 999 employees
Websitehttps://www.apolisrises.com/

Description

Job Title:Application Security (AppSec) Engineer

Location:Onsite Maryland Heights, MO

Tax Term (W2, C2C):W2

Job Type (Permanent/Contract):Contract

Duration:Long Term

Description:

We are seeking an experienced Application Security (AppSec) Engineer with 8 15 years of experience in Application Security, DevSecOps, or Security Architecture. The ideal candidate will have expertise in Secure SDLC, DevSecOps, automated security testing, cloud-native applications, APIs, vulnerability management, and manual penetration testing. This role focuses on embedding security testing, vulnerability management, and business logic validation into CI/CD pipelines and post-deployment processes to strengthen the organization's application security posture across web, mobile, and microservices architectures.

Role and Responsibilities:

Application Security Engineering

  • Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
  • Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
  • Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
  • Enable continuous post-deployment security validation and risk monitoring.

Security Testing & Validation

  • Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
  • Perform authenticated and unauthenticated security assessments of applications and APIs.
  • Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
  • Validate remediation effectiveness and secure deployment practices.

DevSecOps Integration

  • Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
  • Automate vulnerability triage, prioritization, and remediation workflows.
  • Develop security-as-code controls and policy enforcement mechanisms.
  • Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.

Vulnerability Management

  • Analyze findings from multiple security tools and eliminate false positives.
  • Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
  • Track remediation efforts through SDLC and release cycles.
  • Develop security metrics, dashboards, and executive reporting.

Developer Enablement

  • Conduct secure coding reviews and developer education sessions.
  • Establish security champions programs across engineering teams.
  • Provide remediation guidance and hands-on support during application releases.
  • Drive adoption of secure development standards and best practices.

Cloud & API Security

  • Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
  • Secure REST, GraphQL, and microservice-based APIs.
  • Evaluate Infrastructure-as-Code (Terraform, ARM, CloudFormation) and container security controls.
  • Support software supply chain security initiatives, including SBOM/SCA validation.

Required Skills:

  • Application Security (AppSec)
  • Secure SDLC
  • DevSecOps
  • SAST
  • DAST
  • IAST
  • Software Composition Analysis (SCA)
  • Secure Code Review
  • Web Application Security
  • Mobile Application Security
  • API Security
  • REST APIs
  • GraphQL
  • Manual Penetration Testing
  • Business Logic Testing
  • Threat Modeling
  • Threat Analysis
  • Attack Path Analysis
  • Vulnerability Management
  • Vulnerability Assessment
  • CI/CD Security
  • GitHub Actions
  • Azure DevOps
  • Jenkins
  • GitLab CI/CD
  • Agile
  • Secure Coding Practices
  • Security-as-Code
  • Cloud Security
  • AWS
  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • Kubernetes
  • Docker
  • Containers
  • Container Security
  • Infrastructure-as-Code (Terraform, ARM, CloudFormation)
  • Secret Scanning
  • SBOM
  • Software Supply Chain Security
  • Security Metrics & Reporting

Qualifications:

  • 8 15 years of experience in Application Security, DevSecOps, or Security Architecture.
  • Hands-on experience implementing enterprise Application Security programs.
  • Strong expertise with Secure SDLC and CI/CD security integration.
  • Experience with SAST, DAST, IAST, SCA, and vulnerability management tools.
  • Experience performing manual penetration testing and business logic testing.
  • Expertise in web, mobile, and API security.
  • Experience securing cloud-native applications across AWS, Azure, and GCP.
  • Strong understanding of Kubernetes, containers, and Infrastructure-as-Code security.
  • Excellent analytical, communication, and problem-solving skills.

Preferred Certifications:

  • CISSP
  • CSSLP
  • GWAPT
  • OSCP
  • CEH
  • AWS Security Certification
  • Azure Security Certification

Benefits

Paid Sick Days, Employee Referral Program, Employee Events, Retirement / Pension Plans

About Company

Since 1996, RJT has provided successful SAP, Oracle, and IT consulting solutions and staffing services to clients around the world. The new Apolis brings you the same personalized service fortified with a greater array of IT solutions, global expertise, and cost-management strategies.

We are a global IT consultancy that seamlessly integrates experts and leading-edge solutions into your organization so you can focus on what really matters.

Similar Jobs

See more jobs