{"schemaVersion":"jobsearcher.job.v1","id":"3970082ba13a070d5ce85a23","url":"https://jobsearcher.com/jobs/3970082ba13a070d5ce85a23","canonicalUrl":"https://jobsearcher.com/jobs/3970082ba13a070d5ce85a23","title":"Senior Application Security Engineer DevSecOps and CICD","description":"Senior Application Security Engineer DevSecOps and CICDThis is a remote position.Job Title: Senior Application Security Engineer DevSecOps and CICD Location: Remote, USA Estimated Duration: 12+ Months Must Have Skills/Attributes: Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability Experience Desired: Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs); Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)Required Minimum Education: Bachelor's Degree Preferred Education: Master's Degree Education Requirements: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related fieldPreferred Education:Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field Required Skills for the Cybersecurity Engineer: -5-7 years of hands-on application security/DevSecOps experience - Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding - Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques - Cloud security, identity and access management, and modern application architectures - Safe and effective use of AI-assisted development and security tools - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance - Security metrics, coverage reporting, and executive dashboard development - Excellent communication, stakeholder management, presentation, and documentation skills - Ability to work independently across multiple applications, teams, portfolios, and technology stacks - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders - Coaching and knowledge sharing — champions a security-first culture - Comfortable operating within Scrum/Agile delivery and managing own work items Cybersecurity Engineer Responsibilities: - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and'must-win' business outcomes Typical task breakdown: Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impactDaily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code reviewDaily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closureWeekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defectsWeekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controlsMonthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvementOngoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks","company":"3core Systems","rawCompany":"3core systems","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-11T13:00:31.066Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Application Security Engineer DevSecOps and CICD","description":"Senior Application Security Engineer DevSecOps and CICDThis is a remote position.Job Title: Senior Application Security Engineer DevSecOps and CICD Location: Remote, USA Estimated Duration: 12+ Months Must Have Skills/Attributes: Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability Experience Desired: Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs); Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)Required Minimum Education: Bachelor's Degree Preferred Education: Master's Degree Education Requirements: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related fieldPreferred Education:Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field Required Skills for the Cybersecurity Engineer: -5-7 years of hands-on application security/DevSecOps experience - Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding - Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques - Cloud security, identity and access management, and modern application architectures - Safe and effective use of AI-assisted development and security tools - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance - Security metrics, coverage reporting, and executive dashboard development - Excellent communication, stakeholder management, presentation, and documentation skills - Ability to work independently across multiple applications, teams, portfolios, and technology stacks - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders - Coaching and knowledge sharing — champions a security-first culture - Comfortable operating within Scrum/Agile delivery and managing own work items Cybersecurity Engineer Responsibilities: - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and'must-win' business outcomes Typical task breakdown: Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impactDaily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code reviewDaily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closureWeekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defectsWeekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controlsMonthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvementOngoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks","datePosted":"2026-09-11T13:00:31.066Z","dateModified":"2026-09-11T13:00:31.066Z","hiringOrganization":{"@type":"Organization","name":"3core Systems","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"3970082ba13a070d5ce85a23"},"url":"https://jobsearcher.com/jobs/3970082ba13a070d5ce85a23"}}