Resolution Technologies is seeking an Application Security Engineer to strengthen application security across Salesforce, .NET, and Azure App Services. This hybrid role in Atlanta, GA emphasizes secure SDLC practices, penetration testing, and DevSecOps integration aligned to NIST controls.
Responsibilities
- Review Apex code, Visualforce pages, and Lightning components for security vulnerabilities.
- Verify correct Salesforce security configuration, including profiles, permission sets, role hierarchies, and sharing rules.
- Implement and monitor field-level security, object-level access, and record-level access controls.
- Validate secure integration patterns for external APIs and third-party apps within Salesforce.
- Enforce OAuth scopes, connected app policies, and IP restrictions.
- Perform regular security health checks, including Salesforce Shield audits.
- Align Salesforce security architecture with NIST 800-53 and NIST CSF controls.
- Partner with development teams to embed security best practices into the SDLC.
- Lead secure code reviews for applications built on Salesforce, .NET, and Azure platforms.
- Design and review application architectures to ensure alignment with NIST controls.
- Conduct threat modeling and risk assessments for new and existing applications.
- Maintain and improve security integrations with Git, Azure DevOps, and other version control systems.
- Perform manual and automated penetration testing of web applications and APIs.
- Identify and remediate vulnerabilities across Salesforce customizations, .NET codebases, and Azure-hosted services.
- Own the configuration, tuning, and maintenance of DevSecOps tooling such as SonarQube, Checkmarx, Veracode, and Fortify.
- Monitor and report on security tool performance and coverage.
- Map application security controls to NIST standards and support audit readiness.
- Document security requirements and ensure traceability to NIST control families.
- Collaborate with engineering, QA, and operations teams to drive security awareness and training.
- Provide guidance on secure coding standards and remediation strategies.
- Support incident response activities related to application vulnerabilities.
- Contribute to risk assessments and mitigation planning for new and existing applications.
Requirements
- Bachelor degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 7+ years of experience in application security, DevSecOps, or related roles.
- Strong knowledge of secure coding practices in .NET and Apex (Salesforce).
- Experience with Salesforce security architecture and Azure App Services.
- Proficiency with CI/CD pipelines and integrating security tools into workflows using Git and Azure DevOps.
- Familiarity with NIST 800-53, NIST CSF, and other cybersecurity frameworks.
- Hands-on experience with SAST, DAST, SCA, and container security tools.
- Strong scripting skills for automation, such as PowerShell, Python, and Bash.
Technologies
Salesforce, Apex, Visualforce, Lightning components, OAuth, Salesforce Shield, NIST 800-53, NIST CSF, DevSecOps, SDLC, Git, Azure DevOps, SonarQube, Checkmarx, Veracode, Fortify, SAST, DAST, SCA, container security tools, PowerShell, Python, Bash, .NET, Azure App Services.
Preferred Qualifications
- Certifications such as OSCP, GWAPT, CSSLP, or Salesforce Security Specialist.