CybersecurityJobs.io
← Back to all jobs

Job Description

Based in Houston, TX (hybrid), Calance US is seeking a Senior Application Security Engineer to embed security into the software development lifecycle using traditional SAST/DAST and AI-enabled tooling.

Responsibilities

  • Integrate security across the SDLC, CI/CD pipelines, and developers’ workflows
  • Lead and perform SAST, DAST, SCA, and API security testing
  • Utilize AI-powered code scanning to improve vulnerability detection, lower false positives, and speed remediation
  • Collaborate with developers to remediate vulnerabilities and promote secure coding practices
  • Conduct threat modeling and security reviews for applications and APIs
  • Collect and report security metrics, including vulnerability trends and remediation timelines
  • Deploy and manage AI-driven code scanning to analyze source code, APIs, and dependencies for security issues across the SDLC
  • Apply AI/ML capabilities to uncover complex vulnerability patterns and insecure coding practices that traditional tools may miss
  • Leverage AI to reduce false positives, improve signal-to-noise, and streamline triage of security findings
  • Use AI-assisted insights to perform root cause analysis and provide developers with actionable remediation guidance
  • Integrate AI-enabled scanning into CI/CD to deliver real-time feedback during development and at commit time
  • Evaluate and tune AI models and rulesets to enhance detection accuracy and align with enterprise risk priorities
  • Collaborate with engineering teams to embed AI-assisted code reviews and secure coding recommendations into developer workflows (pull requests, IDE plugins)
  • Monitor the effectiveness of AI-based scanning through metrics such as detection rates, reduced false positives, and remediation speed
  • Stay current on emerging AI security tools, LLM-based code analysis, and automated remediation technologies, and promote adoption where value is added

Requirements

  • Minimum seven years of experience in application security, DevSecOps, or secure software engineering
  • Solid understanding of OWASP Top 10 and secure coding standards
  • Hands-on experience with application security tooling, including SAST, DAST, and SCA
  • Proven ability to integrate security into CI/CD processes
  • Familiarity with Ghazdo and GitHub Advanced Security
  • Proficient in at least one programming language such as Python, Java, or JavaScript

Technologies

  • Python
  • Java
  • JavaScript
  • SAST
  • DAST
  • SCA
  • GitHub Advanced Security
  • Ghazdo

Role Overview

The Senior Application Security Engineer helps secure the software development lifecycle by combining traditional SAST/DAST approaches with AI-enabled tooling to identify and remediate code vulnerabilities. This role partners closely with development, DevOps, and security teams to drive secure coding practices and elevate the application risk posture at scale. It leverages AI-driven capabilities to improve vulnerability detection accuracy, automate code reviews, and accelerate remediation across the organization.

Similar Jobs