15 sast jobs at 9 companies in Charlotte, NC

3w
Save
Mark Applied
Hide
Senior Application Security Compliance Lead
Charlotte, North Carolina, United States
HybridFull Time
SMBC Group
SMBC GroupNew York Stock Exchange: SMFG: Provides global banking, investment, securities, and consumer finance services.
5+ YOE5+ years in application security with SAST/DAST experience, code review ability, vulnerability remediation, CI/CD integration, container security, and use of Jira/Confluence.
SAST, SCA, DAST, IAST, Jira, Confluence, C#, C++, Java, Python, .NET
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
Undergraduate degree or equivalent; strong experience with DAST and CI/CD integration; familiarity with SAST, SCA, IAST, RASP, secure SDLC, and standards such as NIST, OWASP, MITRE.
DAST, SAST, SCA, IAST, RASP, CI/CD, NIST, OWASP, MITRE
1w
Save
Mark Applied
Hide
Senior Information Security Engineer
Charlotte or Chandler or Irving or Minneapolis or Canada
$100k-$163k/yr HybridFull Time
Wells Fargo
Wells FargoNYSE: WFC: Global provider of banking, investment, and mortgage financial services.
4+ YOE4+ years of information security engineering or equivalent experience; expertise in application security, SAST, DAST, SCA, IaC, CI/CD, OWASP, MITRE frameworks, SSDLC, and security tooling.
SAST, DAST, SCA, Infrastructure as Code (IaC), GitHub, Jira, ServiceNow, Jenkins, Harness, CI/CD, OWASP, MITRE CVE/CWE, Cursor, GitHub Copilot, Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, Qualys, GitHub Advanced Security (GHAS)
1mo
Save
Mark Applied
Hide
Senior Manual Ethical Hacker
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years pentesting/application security experience, ability to perform manual web and mobile assessments, develop PoCs, conduct code reviews, use DAST/SAST, and strong programming/debugging and threat analysis skills.
DAST, SAST, Frida, UNIX, LINUX, TCP/IP, Web APIs, SBOM, CVE, CWE, Port Swigger, LLM security
2mo
Save
Mark Applied
Hide
Lead, Dev SecOps (Charlotte, NC)
Charlotte, North Carolina, United States
HybridFull Time
United Rentals
United RentalsNYSE: URI: Rents and sells industrial and construction equipment globally.
7+ YOERequires 7+ years in application security/DevSecOps, experience building pipeline security (SAST/DAST/SCA/secrets/containers), CI/CD tool integration, Cisco AI Defense and AI security, and proven cross-functional leadership.
SAST, DAST, SCA, IaC, GitHub, GitHub Actions, GitLab CI, Jenkins, Snyk, Burp Suite, Aikido, Cisco AI Defense, AWS, GCP, Azure, Oracle, OWASP, ASVS, SAMM, Python, PowerShell, Bash, PHP, RPG, JavaScript
4w
Save
Mark Applied
Hide
Senior Associate, Application Security, DevSecOps
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yr OnsiteFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
Java, C#, JavaScript, Python, SQL, CI/CD, SAST, DAST, Azure, OWASP
1w
Save
Mark Applied
Hide
Lead DevOps Engineer (Hybrid)
Hartford or Short Hills or Charlotte
$130k-$176k/yr HybridFull Time
Selective Insurance
Selective InsuranceNASDAQ: SIGI: Provider of commercial and personal property and casualty insurance.
5+ YOE5+ years applications development, 3+ years designing DevOps pipelines using Azure DevOps/SonarQube/YAML, Azure cloud and IaC experience (ARM, Terraform, Ansible), containerization, security testing (SAST/DAST), scripting (Bicep/PowerShell/Bash/Python), and leadership.
Azure DevOps, SonarQube, YAML, Azure Resource Manager (ARM) templates, Terraform, Ansible, Docker, Kubernetes, Bicep, PowerShell, Bash, Python, GIT
1mo
Save
Mark Applied
Hide
Senior DevSecOps Engineer
United States or New York City or Charlotte
$130k-$205k/yr HybridFull Time
Red Ventures
Red Ventures: A technology-driven digital marketing and consumer media platform.
5+ YOE5+ years security/platform engineering with cloud security, Terraform, CI/CD security, vulnerability management, SOC 2 experience, scripting for automation, and experience applying AI/LLM to security operations.
Terraform, SAST, SCA, secret scanning, SBOM, CSPM, ASPM, SIEM, Wiz, Prisma Cloud, Snyk, Drata, Vanta, CI/CD, AI/LLM
1mo
Save
Mark Applied
Hide
Container Security Engineer
Malvern or Charlotte or Dallas or Fort Worth
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
Hands-on experience securing containerized AWS environments (ECS/EKS) and serverless workloads; experience with Wiz, CI/CD, image/runtime security, vulnerability assessment and remediation; undergraduate degree or equivalent experience.
Wiz, AWS, ECS, EKS, Serverless, Azure AKS, GCP GKE, CI/CD, SAST, SCA, IAST, DAST, NIST, OWASP, MITRE, AI/ML
1d
Save
Mark Applied
Hide
Lead Security Architect (Application Security)
Charlotte or Irving or Columbus or Minneapolis
$119k-$206k/yr HybridFull Time
Wells Fargo
Wells FargoNYSE: WFC: Global provider of banking, investment, and mortgage financial services.
5+ YOERequires 5+ years of architecture and information security experience, threat modeling, architecture reviews, security assessments, SSDLC, secure coding, and cloud application, API, and modern architecture security.
OWASP Top 10, SAST, DAST, SCA, IaC, Kubernetes, Azure, AWS, Google Cloud, GitHub Copilot
1mo
Save
Mark Applied
Hide
Container Security Engineer
Malvern or Charlotte or Plano or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
Undergraduate degree or equivalent experience; hands-on AWS container security experience; Wiz, CI/CD, cloud-native architecture, container lifecycle, runtime security, and security framework knowledge.
Amazon Web Services (AWS), ECS, EKS, Wiz, Azure, AKS, GCP, GKE, CI/CD, SAST, SCA, IAST, DAST, NIST, OWASP, MITRE, AI/ML
1mo
Save
Mark Applied
Hide
AVP - Information Security - Americas
Norfolk or Charlotte
OnsiteFull Time
PRA Group
PRA GroupNASDAQ: PRAA: Acquires and collects nonperforming loans for banks and creditors.
12+ YOE5+ Mgmt12+ years in information security with technical architecture and engineering depth; 5+ years leadership; cloud, IAM, application security, SIEM/XDR/SOAR, and 2+ years implementing AI/ML in security; Bachelor required, Masters preferred; security certifications preferred.
Azure, AWS, GCP, PAM, MFA, Zero Trust, SAST, DAST, SCA, SIEM, XDR, SOAR, Torq, Tines, XSOAR, Microsoft Logic Apps, Python, PowerShell, KQL, SQL, REST API, LLM, MITRE ATT&CK
1w
Save
Mark Applied
Hide
Lead Information Security Engineer
Charlotte or Irving or Chandler or Minneapolis or United States
$119k-$206k/yr HybridFull Time
Wells Fargo
Wells FargoNYSE: WFC: Global provider of banking, investment, and mortgage financial services.
5+ YOERequires 5+ years of information security engineering experience, AppSec expertise, tooling integration, CI/CD knowledge, leadership, regulated-environment experience, and strong written, verbal, and presentation skills.
SAST, DAST, SCA, Infrastructure as Code (IaC), GitHub, Jira, ServiceNow, Jenkins, Harness, CI/CD, OWASP, MITRE CVE/CWE, Cursor, GitHub Copilot, Checkmarx, Black Duck, Prisma Cloud, TruffleHog, GitHub Advanced Security (GHAS), Snyk, Socket, Invicti, Qualys
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
Malvern or Charlotte or Plano or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
Requires a related undergraduate degree or equivalent experience, strong DAST deployment and CI/CD integration experience, application security expertise, and familiarity with NIST, OWASP, and MITRE.
DAST, CI/CD, SAST, SCA, IAST, RASP, NIST, OWASP, MITRE
1mo
Save
Mark Applied
Hide
Software Supply Chain Security Specialist
Malvern or Charlotte or Plano or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
3+ YOERequires a bachelor's degree and 3–5+ years in software engineering, application security, DevSecOps, or security engineering, with Python or Java, APIs, automation, cloud-native applications, and security concepts.
Python, Java, Azure OpenAI, OpenAI APIs, LangChain, Semantic Kernel, AutoGen, CrewAI, GitHub Advanced Security (GHAS), Snyk, Wiz, JFrog Xray, Kubernetes, AWS, Azure, GitHub, SAST, SCA, SBOM, CI/CD