CybersecurityJobs.io
← Back to all jobs

Job Description

An on-site Application Security Engineer is sought in Bethlehem, PA to embed security by design across the enterprise software development life cycle. The role partners with development, DevOps, QA, and IT Operations to strengthen security and compliance, applying NIST SSDF and OWASP ASVS to raise application security maturity and enable secure software delivery. The position requires at least 3 years of relevant experience and offers a salary of USD 125,000 per year.

Responsibilities

  • Continuously assess and strengthen SDLC processes, tools, and release workflows from a security vantage point.
  • Conduct gap analyses against secure development frameworks, including NIST SSDF and OWASP ASVS.
  • Define, maintain, and evolve secure development standards aligned with PCI DSS and CCPA/GDPR requirements.
  • Collaborate with engineering teams to propose and implement practical security improvements across the SDLC.
  • Embed security controls across planning, design, coding, testing, deployment, and maintenance phases.
  • Provide threat modeling, secure‑design guidance, and application architecture reviews.
  • Establish and support secure design and code review practices, coaching developers on security best practices.
  • Balance security needs with developer experience and business requirements to reduce friction while raising security maturity.
  • Implement, operate, and optimize application security tooling including SAST, DAST, and SCA solutions.
  • Integrate security tooling such as Snyk and Checkmarx into CI/CD pipelines to enable automated vulnerability detection.
  • Define and enforce security gates at key points within development and release workflows.
  • Ensure vulnerability findings are actionable, prioritized, and integrated into remediation processes.
  • Support static, dynamic, and penetration testing activities with internal and external resources.
  • Integrate vulnerability management, continuous monitoring, and remediation tracking into the SDLC.
  • Provide application security support during security incidents and assist teams with investigation and remediation.
  • Support secure platform and environment modernization efforts, including container security, OS hardening, and secrets management (for example Vault, Azure Key Vault).
  • Contribute to architecture improvements focused on security, stability, and resilience of applications and platforms.

Requirements

  • Minimum of three years of experience in application security or software engineering with a focus on secure development practices.
  • Hands-on experience applying secure SDLC frameworks such as NIST SSDF and OWASP ASVS.
  • Practical experience integrating SAST and DAST tools into CI/CD pipelines and workflows.
  • Working knowledge of PCI DSS and privacy regulations (CCPA/GDPR) as they affect software development.
  • Strong communication skills with the ability to influence and collaborate with engineering teams.

Technologies

  • SAST
  • DAST
  • SCA
  • Snyk
  • Checkmarx
  • Vault
  • Azure Key Vault
  • NIST SSDF
  • OWASP ASVS
  • PCI DSS
  • CCPA/GDPR
  • OWASP Top 10

Benefits

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance

Preferred Qualifications

  • Experience with container security, image hardening, and secrets management technologies.
  • Familiarity with the OWASP Top 10, API security, and modern application security practices.
  • Experience coordinating or supporting penetration testing or DAST programs.
  • Relevant certifications such as CSSLP, CISSP, GWAPT, GCSA, or similar.

Similar Jobs