Application Security Engineer - North Central region
General Description
We are looking for a skilled Application Security Engineer to support GuidePoint Security’s Application Security practice in the North Central region. This role will engage in the development of secure software development lifecycle (SSDLC) programs, DevSecOps pipeline integrations, and security assessments of AI-enabled and agentic applications while providing “Wow Them” service to clients and/or internal customers or co-workers.
The Application Security Engineer will be required to demonstrate strong application security testing, DevSecOps automation, and secure code review skills, lead by influence, and strong business/financial acumen to drive the use of progressive application security, software supply chain, and AI security programs that will align the delivery business objectives and priorities.
About the North Central Application Security Practice
The North Central Application Security Practice is responsible for helping clients build, scale, and mature secure software development programs. We assess applications, embed security into engineering workflows, and advise development and security leaders across the organization.
Our team of application security engineers, consultants, and architects focuses on SAST, DAST, SCA, API and cloud-native security, software supply chain security, and the security of AI-enabled and agentic applications. We partner with client engineering, platform, and security teams to reduce risk without slowing delivery.
DevSecOps and “shift-left” security automation across CI/CD pipelines
Software supply chain security, including SBOMs, open-source risk, and artifact integrity
Securing AI/LLM applications and agentic workflows against emerging threats
Roles and Responsibilities:
Run and tune client SAST, DAST, SCA, secrets, and IaC scanning tools; triage results, eliminate false positives, and deliver prioritized, actionable remediation guidance
Design and implement security tool integrations into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Azure DevOps, Jenkins), source control, IDEs, and ticketing systems (e.g., Jira, ServiceNow), including policy gates and break-the-build criteria
Partner with development teams on remediation, secure coding guidance, and developer enablement to embed security throughout the SDLC
Assess and harden software supply chain controls, including SBOM generation, dependency and container image scanning, artifact signing, and pipeline/runner security (e.g., SLSA)
Perform threat modeling and security architecture reviews for cloud-native, microservice, container (Docker/Kubernetes), and Infrastructure-as-Code (Terraform, CloudFormation) environments
Leverage AI-assisted and agentic tooling (e.g., AI code assistants, automated triage, and auto-remediation workflows) to accelerate testing and reporting, and advise clients on the secure adoption of AI coding assistants
Help clients mature AppSec programs by defining metrics, vulnerability management SLAs, and roadmaps aligned to frameworks such as OWASP SAMM, BSIMM, and NIST SSDF
Produce clear, client-ready deliverables, present findings to technical and executive audiences, and contribute to the growth of the AppSec practice through tooling, methodologies, and knowledge sharing
Required Experience and Education:
1–3+ years of experience in Application Security, DevSecOps, or software development with a security focus
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Hands-on experience with SAST, DAST, and SCA tools and integrating them into CI/CD pipelines (e.g., Azure DevOps, GitHub Actions, GitLab CI, Jenkins, Bamboo)
Proficiency with manual testing tools such as Burp Suite Pro and a strong understanding of the OWASP Top 10 and OWASP API Security Top 10 and their mitigation strategies
Strong working knowledge of secure development lifecycles and experience guiding remediation of vulnerabilities identified by application security tools
Ability to review source code in one or more languages such as JavaScript/TypeScript, Python, Java, C#, Go, PHP, or C/C++
Working knowledge of cloud platforms (AWS, Azure, or GCP), containers, and Git-based development workflows
Strong written and verbal communication skills, with the ability to distill complex problems into digestible information for technical and executive audiences
Preferred Experience and Education:
Experience with Invicti (DAST) and/or Checkmarx (SAST/SCA) highly preferred; experience with other platforms (e.g., Snyk, Veracode, Black Duck, Semgrep, GitHub Advanced Security) a plus
Experience building agentic AI workflows or automation (Python, Bash, PowerShell) to scale security testing, triage, and remediation
Experience with software supply chain security (SBOM, SLSA, Sigstore) and IaC/container security scanning (e.g., Checkov, Trivy, Wiz)
Experience with threat modeling methodologies (e.g., STRIDE) and AppSec maturity frameworks such as OWASP SAMM, BSIMM, or NIST SSDF
Industry certifications such as GWAPT, OSWE, OSCP, CSSLP, Certified DevSecOps Professional (CDP), or AWS Certified Security – Specialty
Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience
Travel Requirements:
Up to 10% travel
Physical Requirements:
Sedentary work
Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day