Lead Application Security Engineer
JNL Technologies
Job description
Job Summary
We are looking for a Lead Security Test Engineer with strong DevSecOps and Application Security experience to design, implement, and execute security testing throughout the software development lifecycle.
The ideal candidate will have hands-on experience with SAST, DAST, SCA, API Security, Penetration Testing, Vulnerability Assessment, and Threat Modeling, along with the ability to integrate security testing into CI/CD pipelines.
Key Responsibilities
-
Design and execute security testing strategies for web applications, APIs, microservices, mobile applications, and cloud environments.
-
Perform SAST, DAST, SCA, API security, container security, and infrastructure security testing.
-
Conduct vulnerability assessments and penetration testing and validate remediation.
-
Integrate security testing tools and automated security gates into CI/CD pipelines.
-
Develop security testing automation using Python, Java, JavaScript, or Bash.
-
Collaborate with Development, QA, DevOps, Cloud, and Security teams to identify and remediate vulnerabilities early.
-
Implement shift-left security and DevSecOps controls across the SDLC.
-
Configure and manage security tools for SAST, DAST, SCA, secrets scanning, container scanning, and IaC security.
-
Perform security testing of Docker/Kubernetes environments.
-
Test REST and GraphQL APIs, including authentication and authorization mechanisms.
-
Integrate security checks with Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, or similar tools.
-
Analyze vulnerability findings, prioritize risks, and track remediation through closure.
-
Develop security test cases, automation frameworks, reports, and security metrics.
-
Participate in threat modeling and security architecture reviews.
-
Support security and compliance standards including OWASP Top 10, OWASP ASVS, SANS, NIST, and CIS Controls.
-
Stay current with emerging security threats, testing methodologies, and DevSecOps tools.
Mandatory Skills
-
Application Security Testing
-
SAST
-
DAST
-
SCA
-
API Security Testing
-
Penetration Testing
-
Vulnerability Assessment
-
Threat Modeling
-
OWASP
-
DevSecOps
-
Security Test Automation
-
CI/CD Security Integration
Desirable Skills
-
AWS Secrets Manager
-
AWS / Cloud Security
-
Docker / Kubernetes Security
-
REST / GraphQL API Security
-
Jenkins / GitHub Actions / GitLab CI/CD / Azure DevOps
Pay: $113,318.86 - $120,470.02 per year
Experience:
- Application Security Testing: 5 years (Preferred)
Work Location: In person