Application Security Engineer - North Central region

GuidePoint Security · Remote · Engineering

Posted 2026-10-09

Apply for this role →

General Description

We are looking for a skilled Application Security Engineer to support GuidePoint Security’s Application Security practice in the North Central region. This role will engage in the development of secure software development lifecycle (SSDLC) programs, DevSecOps pipeline integrations, and security assessments of AI-enabled and agentic applications while providing “Wow Them” service to clients and/or internal customers or co-workers.

The Application Security Engineer will be required to demonstrate strong application security testing, DevSecOps automation, and secure code review skills, lead by influence, and strong business/financial acumen to drive the use of progressive application security, software supply chain, and AI security programs that will align the delivery business objectives and priorities.

About the North Central Application Security Practice

The North Central Application Security Practice is responsible for helping clients build, scale, and mature secure software development programs. We assess applications, embed security into engineering workflows, and advise development and security leaders across the organization.

Our team of application security engineers, consultants, and architects focuses on SAST, DAST, SCA, API and cloud-native security, software supply chain security, and the security of AI-enabled and agentic applications. We partner with client engineering, platform, and security teams to reduce risk without slowing delivery.

DevSecOps and “shift-left” security automation across CI/CD pipelines

Software supply chain security, including SBOMs, open-source risk, and artifact integrity

Securing AI/LLM applications and agentic workflows against emerging threats

Roles and Responsibilities:

Run and tune client SAST, DAST, SCA, secrets, and IaC scanning tools; triage results, eliminate false positives, and deliver prioritized, actionable remediation guidance

Design and implement security tool integrations into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Azure DevOps, Jenkins), source control, IDEs, and ticketing systems (e.g., Jira, ServiceNow), including policy gates and break-the-build criteria

Partner with development teams on remediation, secure coding guidance, and developer enablement to embed security throughout the SDLC

Assess and harden software supply chain controls, including SBOM generation, dependency and container image scanning, artifact signing, and pipeline/runner security (e.g., SLSA)

Perform threat modeling and security architecture reviews for cloud-native, microservice, container (Docker/Kubernetes), and Infrastructure-as-Code (Terraform, CloudFormation) environments

Leverage AI-assisted and agentic tooling (e.g., AI code assistants, automated triage, and auto-remediation workflows) to accelerate testing and reporting, and advise clients on the secure adoption of AI coding assistants

Help clients mature AppSec programs by defining metrics, vulnerability management SLAs, and roadmaps aligned to frameworks such as OWASP SAMM, BSIMM, and NIST SSDF

Produce clear, client-ready deliverables, present findings to technical and executive audiences, and contribute to the growth of the AppSec practice through tooling, methodologies, and knowledge sharing

Required Experience and Education:

1–3+ years of experience in Application Security, DevSecOps, or software development with a security focus

Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes

Hands-on experience with SAST, DAST, and SCA tools and integrating them into CI/CD pipelines (e.g., Azure DevOps, GitHub Actions, GitLab CI, Jenkins, Bamboo)

Proficiency with manual testing tools such as Burp Suite Pro and a strong understanding of the OWASP Top 10 and OWASP API Security Top 10 and their mitigation strategies

Strong working knowledge of secure development lifecycles and experience guiding remediation of vulnerabilities identified by application security tools

Ability to review source code in one or more languages such as JavaScript/TypeScript, Python, Java, C#, Go, PHP, or C/C++

Working knowledge of cloud platforms (AWS, Azure, or GCP), containers, and Git-based development workflows

Strong written and verbal communication skills, with the ability to distill complex problems into digestible information for technical and executive audiences

Preferred Experience and Education:

Experience with Invicti (DAST) and/or Checkmarx (SAST/SCA) highly preferred; experience with other platforms (e.g., Snyk, Veracode, Black Duck, Semgrep, GitHub Advanced Security) a plus

Experience building agentic AI workflows or automation (Python, Bash, PowerShell) to scale security testing, triage, and remediation

Experience with software supply chain security (SBOM, SLSA, Sigstore) and IaC/container security scanning (e.g., Checkov, Trivy, Wiz)

Experience with threat modeling methodologies (e.g., STRIDE) and AppSec maturity frameworks such as OWASP SAMM, BSIMM, or NIST SSDF

Industry certifications such as GWAPT, OSWE, OSCP, CSSLP, Certified DevSecOps Professional (CDP), or AWS Certified Security – Specialty

Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience

Travel Requirements:

Up to 10% travel

Physical Requirements:

Sedentary work

Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day

Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

Apply for this role →

← Back to all jobs