FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Engineer
GuidePoint Security. Support GuidePoint Security’s Application Security practice in the North Central region .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Application Security and DevSecOps, with a strong focus on integrating security into software development lifecycles and CI/CD pipelines. Proficient in security assessments, vulnerability management, and leveraging AI tools for enhanced security practices.
Highest-signal resume keywords
Application SecurityDevSecOpsSAST, DAST, SCA ToolsSecure Software Development LifecycleOWASP Top 10
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Secure Software Development LifecycleSAST ToolsDAST ToolsSCA ToolsThreat ModelingVulnerability ManagementSource Code ReviewCI/CD Pipeline IntegrationContainer SecurityAI Tool Integration
Soft Skills
Strong Written CommunicationStrong Verbal Communication
Tools & Technologies
Burp Suite ProAzure DevOpsGitHub ActionsGitLab CIJenkinsBambooAWSAzureGCPGit-based Development Workflows
Certifications & Qualifications
GWAPTOSWEOSCPCSSLPAWS Certified Security – Specialty
Industry Keywords
AppSecSBOMSLSASigstoreIaC SecurityMicroservicesCloud-native SecurityAgentic AI WorkflowsAppSec Maturity FrameworksSecurity Architecture
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformJavaJavaScriptJenkinsPHPPythonTypeScriptC++Go
About the role
Key responsibilities & impact- Support GuidePoint Security’s Application Security practice in the North Central region
- Develop secure software development lifecycle programs
- Integrate security into DevSecOps pipelines
- Perform security assessments of AI-enabled and agentic applications
- Run and tune SAST, DAST, SCA, secrets, and IaC scanning tools
- Triage scan results, eliminate false positives, and provide prioritized remediation guidance
- Design and implement security integrations across CI/CD pipelines, source control, IDEs, and ticketing systems
- Configure policy gates and break-the-build criteria
- Partner with development teams on remediation, secure coding, and developer enablement
- Assess and harden software supply chain controls, including SBOMs, dependency and container image scanning, artifact signing, and pipeline/runner security
- Perform threat modeling and security architecture reviews for cloud-native, microservice, container, and Infrastructure-as-Code environments
- Leverage AI-assisted and agentic tooling to accelerate testing, triage, reporting, and remediation
- Advise clients on secure adoption of AI coding assistants
- Define AppSec metrics, vulnerability management SLAs, and maturity roadmaps aligned with OWASP SAMM, BSIMM, and NIST SSDF
- Produce client-ready deliverables and present findings to technical and executive audiences
- Contribute to AppSec practice growth through tooling, methodologies, and knowledge sharing
- Provide service to clients, internal customers, and coworkers
Requirements
What you’ll need- 1–3+ years of experience in Application Security, DevSecOps, or software development with a security focus
- Embraces emerging technologies, including AI tools
- Hands-on experience with SAST, DAST, and SCA tools and integrating them into CI/CD pipelines such as Azure DevOps, GitHub Actions, GitLab CI, Jenkins, or Bamboo
- Proficiency with Burp Suite Pro
- Strong understanding of the OWASP Top 10 and OWASP API Security Top 10 and mitigation strategies
- Strong working knowledge of secure development lifecycles
- Experience guiding remediation of vulnerabilities identified by application security tools
- Ability to review source code in one or more languages such as JavaScript/TypeScript, Python, Java, C#, Go, PHP, or C/C++
- Working knowledge of AWS, Azure, or GCP
- Working knowledge of containers and Git-based development workflows
- Strong written and verbal communication skills
- Preferred: Experience with Invicti and/or Checkmarx; other platforms such as Snyk, Veracode, Black Duck, Semgrep, or GitHub Advanced Security
- Preferred: Experience building agentic AI workflows or automation using Python, Bash, or PowerShell
- Preferred: Experience with software supply chain security, SBOM, SLSA, Sigstore, IaC/container security scanning, threat modeling, and AppSec maturity frameworks
- Preferred: Industry certifications such as GWAPT, OSWE, OSCP, CSSLP, CDP, or AWS Certified Security – Specialty
- Preferred: Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience
- Up to 10% travel
- Sedentary work
- Substantial movement of wrists, hands, and/or fingers for at least 8 hours daily
- Close visual acuity for computer terminal viewing and/or extensive reading for at least 8 hours daily
Benefits
Comp & perks- Remote workforce primarily (U.S. based only)
- Some travel may be required for certain positions
- Group Medical Insurance options: Zero Deductible PPO Plan with GuidePoint paying 90% of employee premiums and 70% of family premiums
- High Deductible Health Plan with HSA with GuidePoint paying 100% of employee premiums and 75% of family premiums
- HSA contributions: $850 annually per employee or $1,750 annually per family
- Group Dental Insurance with GuidePoint paying 100% of employee premiums and 75% of family premiums
- 12 corporate holidays
- Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
- Mentorship and guidance opportunities
- Opportunity for career growth