
Senior Application Security Engineer DevSecOps
NITYA Software Solutions Inc
Job description
Senior Application Security Engineer, DevSecOps, and CICD
Location: Remote, but the location needs locals.
Irving, TX 75039; Chicago, IL 60661; Peoria, IL 61629; Broomfield, CO 80020
Duration: 12 months
Experience: 11+ years
Education Requirements:
- Bachelor’s degree in computer science, cybersecurity, information systems, or a related field
Preferred Education:
- Master’s degree in computer science, cybersecurity, information systems, or a related field
Required Skills for the Cybersecurity Engineer:
-
10+ years of hands-on application security DevSecOps experience
-
Secure SDLC, DevSecOps, Agile, and Scrum methodologies—strong working understanding
-
Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
-
Ability to read, analyze, test, and modify production application code in Java and Python to validate security findings and support remediation efforts
-
OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
-
Cloud security, identity and access management, and modern application architectures
-
Safe and effective use of AI-assisted development and security tools
-
Vulnerability triage and validation—exploitability, business impact, severity, compensating controls, and remediation guidance
-
Security metrics, coverage reporting, and executive dashboard development
-
Excellent communication, stakeholder management, presentation, and documentation skills
-
Ability to work independently across multiple applications, teams, portfolios, and technology stacks
-
Strong problem-solving mindset—balances security, usability, operational impact, and business objectives
-
Collaboration and influence—negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
-
Coaching and knowledge sharing—champions a security-first culture
-
Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities:
-
Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
-
Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
-
Manages repository scanning coverage—source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
-
Drives remediation from discovery through verified closure and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
-
Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
-
Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes