Application Security Engineer

🏢 DecisionPoint Corporation · all DecisionPoint Corporation jobs
📍 United States
📅 Posted 2026-08-04 · via Himalayas
🏷 Application-Security-Engineer,Cybersecurity,Infosec,DevSecOps,Secure-Software-Development,Senior-Application-Security-Engineer,Lead-Application-Security-Engineer,Application-Security-Architect,Application-Security-Lead
Apply on original site ↗

Overview

DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission environment. This role ensures secure development practices across CMS components, APIs, integrations, CI/CD pipelines, and custom code.

The Application Security Engineer supports secure coding standards, threat modeling, static and dynamic testing, and secure secrets management. This position plays a critical role in strengthening application-level defenses, reducing vulnerabilities, and ensuring mission systems meet stringent DoD security requirements.

This position is fully remote.
Duties & Responsibilities
The Application Security Engineer will:
- Conduct secure code reviews, focusing on application logic, API endpoints, CMS modules, and backend integrations.

- Perform API security assessments to validate authentication, authorization, data handling, and boundary protections.

- Support CMS hardening by reviewing templates, modules, configurations, and custom components for secure implementation.

- Integrate security requirements into CI/CD pipelines including SAST/DAST tools, dependency scanning, and automated controls.

- Manage secrets handling, encryption policies, and secure storage of API keys, tokens, and credentials.

- Conduct static and dynamic application security testing, vulnerability assessments, and remediation validation.

- Provide secure coding guidance to developers, architects, and product teams.

- Work with DevSecOps and cloud engineers to ensure secure build and deployment patterns.

- Perform threat modeling and recommend mitigations for high-risk application features.

- Review and validate authentication flows, SSO integrations, and identity-related protections.

- Assist with security documentation including test results, remediation plans, and secure configuration records.

- Support continuous monitoring, log analysis, and triage of application-layer security alerts.

- Participate in sprint teams, code review cycles, and architecture discussions to embed security early.

Qualifications
Clearance Requirement

Must hold an active Top Secret clearance, supported by a Tier 5 background investigation.
Education (Required)

Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field.
Experience (Required)
- Minimum 7 years of experience in application security engineering, secure software development, or cybersecurity.

- Experience conducting code reviews, application penetration testing, or API security testing.

- Experience with static and dynamic testing tools, dependency scanning, and software composition analysis.

- Experience supporting secure CI/CD pipeline integration and DevSecOps practices.

- Experience implementing secure secrets management, encryption, and authentication protections.

Technical Knowledge (Required)
- Strong understanding of OWASP Top 10, secure coding principles, and application-layer attack vectors.

- Experience with SAST/DAST tools, dependency scanners, and code review workflows.

- Knowledge of API security, token-based authentication, and secure data handling.

- Familiarity with CMS structures, template security, and module-level risk considerations.

- Understanding of identity and access management, certificate management, and secure authentication flows.

Technical Knowledge (Preferred)
- Experience with AWS cloud-native application security tools.

- Familiarity with container security, Kubernetes workload protections, and microservices security.

- Experience with modern CI/CD platforms and DevSecOps automation.

Certifications

Required:
- Security+ or CISSP or CCSP

Preferred:
- AWS Security Specialty

- GIAC secure coding or cloud security certifications

- Certified Ethica

← All remote jobs