GuidePoint Security
Posted 2mo ago

Application Security Engineer (Remote in the U.S.)

GuidePoint Security
United States
RemoteFull Time
Responsibilities
  • run assessments
  • review outputs
  • integrate tooling
Requirements
  • Bachelor's in CS/IS/InfoSec
  • 4 years in Application Security
  • 2 years with IDE/CI/CD
  • SAST/DAST/SCA tooling
  • Web app remediation
  • Code review in multiple languages
  • Burp Suite Pro
Technical tools mentioned
IDECI/CD toolsBurp Suite ProInvictiCheckmarxGitHubAzure DevOpsJenkinsBamboo

Job description

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Run client SAST, DAST, and SCA tools, review outputs and provide recommendations; Implement integrations for tools into pipelines, ticketing systems, etc.; Collaborate with developers to provide secure design guidance and remediation strategies; Familiarity with CI/CD systems (i.e. GitHub) and integrating software security tools into the development workflow; Strong understanding of web application security principles and best practices; Manage, maintain and operate application security tooling, including configuration, tuning, and automation.

Position allows for 100% remote work from within the US.

Requirements:

Bachelor's degree in Computer Science, Information Systems or Information Security, and 4 years progressive baccalaureate experience as a security engineer, security analyst or related position working in Application Security.

Must have 2 years of experience with each of the following:

  • Integrated Development Environment (IDE) and Continuous integration /
  • Continuous Delivery (CI/CD) Pipeline tools and processes (e.g. Azure Dev Ops, Jenkins, Bamboo, etc.);
  • Secure Development Lifecycles and experience remediating technical vulnerabilities identified by web application scanning tools,
  • Information Systems architecture, security control design, and development experience;
  • Manual testing tools such as Burp Suite Pro; Knowledge of and experience with SAST/DAST/SCA Application Security tools (Invicti (DAST) or Checkmarx (SAST/SCA);
  • Experience with the integration of tools into development pipelines;
  • Experience understanding and mitigating Application Security related vulnerabilities;
  • Experience with reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

 

About GuidePoint Security

Provides cybersecurity consulting, managed services, and integrated technology solutions.

Year founded
2011
Employees
1200
Organization type
Private
Latest investment
Raised $5.00M Private Equity (2023) — led by Audax Private Equity
Headquarters
US

Similar jobs

Application Security Engineer roles
2mo
Save
Mark Applied
Hide
Security Engineer, Application Security
United States
$100k-$200k/yr RemoteFull Time
Trail of Bits
Trail of Bits: Provides high-end security research and software auditing services.
Deep application security and low-level code assessment experience, manual static/dynamic and binary analysis, memory corruption expertise, tool development, and proficiency in multiple programming languages for security tooling.
Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, C++, AWS, GCP, Azure
14h
Save
Mark Applied
Hide
Staff/Lead Application Security Engineer
San Francisco or New York or Toronto
OnsiteFull Time
SnailWorks
SnailWorks: SnailWorks provides mail tracking and delivery intelligence software for marketers.
Expert web/API security, identity and access design, applied cryptography, cloud and container security; production coding experience and a record of driving security work across engineering organizations.
AI, SAST, DAST, SCA, CI/CD, RBAC, ABAC
16h
Save
Mark Applied
Hide
Application Security Engineer, AppSec ASSET
Seattle, Washington, United States
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires a bachelor's degree in computer science or equivalent, 3+ years programming experience, 2+ years security code review and systems troubleshooting, networking knowledge, and security vulnerability expertise.
Python, Ruby, Go, Swift, Java, .NET, C++, HTTP, DNS, TCP/IP, AWS, command line tools, Microsoft?
1d
Save
Mark Applied
Hide
Application Security Engineer IV - AI Harness
Tempe or St. Louis
HybridFull Time
Edward Jones
Edward Jones: Offers investment management and financial planning through local branches.
6+ YOEBachelor's degree or equivalent practical experience and 6+ years in application security, secure software engineering, DevSecOps, platform engineering, security operations, or related cybersecurity engineering roles.
Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, Jira, Azure DevOps, Python, SARIF, SBOMs, SAST, SCA, DAST, OWASP Top 10, CWE, CVSS, NIST SSDF, NIST CSF 2.0, SIEM, APIs, Kubernetes, AWS, Azure
1d
Save
Mark Applied
Hide
Confluent - Staff Security Engineer
Poughkeepsie or Lowell or Rochester or Tucson or Research Triangle Park or Armonk or Boston or Bellevue or Atlanta or San Jose or Dallas or Austin or San Francisco or Seattle
$161k-$299k/yr RemoteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
10+ YOERequires a bachelor's degree and 10+ years of application security experience, with expertise in secure architecture, cloud-native platforms, security automation, CI/CD, and Go, Python, or Java.
Go, Python, Java, CI/CD, AI, LLMs
2d
Save
Mark Applied
Hide
Application Security Engineer IV - AI Harness
Tempe or St. Louis
$102k/yr HybridFull Time
Edward Jones
Edward Jones: Provides personalized financial advice and wealth management services.
6+ YOEBachelor's degree or equivalent practical experience, 6+ years in application security or related cybersecurity engineering, CI/CD and AppSec tooling, automation with Python or shell, observability, secure SDLC, and AI-assisted security workflows.
Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, Jira, Azure DevOps, Python, SAST, SCA, DAST, SBOMs, SARIF, Selenium, Microsoft Azure, AWS, Kubernetes, SIEM, APIs, NIST SSDF, NIST CSF 2.0, OWASP Top 10, CWE, CVSS, CISSP, CSSLP, CCSP, GIAC
2d
Save
Mark Applied
Hide
Application Security Engineer
Atlanta or Mountain View or United States
$112k-$186k/yr HybridFull Time
Omnissa
Omnissa: Provides AI-driven digital workspace and endpoint management software solutions.
4+ YOERequires 4+ years in application security or security-focused software engineering, manual secure code review and testing, programming proficiency in Java or C++, and strong problem-solving, documentation, and communication skills.
Java, C++
4d
Save
Mark Applied
Hide
Senior Application Security Engineer
United States
$116k-$145k/yr RemoteFull Time
World Wide Technology
World Wide Technology: Global technology solutions provider and systems integrator.
8+ YOEBachelor's degree or equivalent experience; 8+ years in application or information security, software engineering, or SecDevOps; expertise in AppSec tooling, cloud-native applications, secure coding, threat modeling, and security frameworks.
SCA, SAST, DAST, CI/CD, GitHub Actions, GitLab CI, Jenkins, Azure DevOps, AWS, Azure, GCP, Docker, Kubernetes, OpenShift, Java, JavaScript, TypeScript, Python, Go, C#, Bash, PowerShell, SSO, OAuth2, OIDC, JWT, TLS, PKI, HTTP, REST, GraphQL, OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, CWE, NIST SSDF, NIST 800-53, NIST 800-171, ISO 27001, SOC 2, CMMC, STRIDE, PASTA, Wiz, Snyk, Apiiro, OX Security, Cycode, Checkmarx, Veracode, GitHub Advanced Security, OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic AI, MITRE ATLAS, NIST AI RMF, Model Context Protocol (MCP), CISSP, CSSLP, GWAPT, GWEB, OSCP, OSWE