GuidePoint Security

Cybersecurity

SeniorApplicationSecurityEngineer

$155–215k ~AI est. Virginia, United States; Maryland, United States; Pennsylvania, United States; North Carolina, United States; Delaware, United States; New Jersey, United States; District of Columbia, United States Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior Application Security Engineer at GuidePoint Security. Skills: Application Security, SAST tools, CI/CD, Software Engineering. Implement SAST tools. Operationalize SAST tools”

Industry & Context.

Cybersecurity
Problems you'll solve

Troubleshooting; Vulnerability validation; Vulnerability remediation

Eligibility Requirements

Some travel may be required, On-site may be required for Federal positions

What They're Looking For.

Must Have

5-7 years security engineering experience, Proficiency with SAST tools, Understanding of CI/CD pipeline tools, Experience in software engineering, Scripting and automation experience, Solid working knowledge of application security fundamentals, OWASP Top 10 knowledge, Threat modeling knowledge, Implement secure coding practices knowledge, Experience throughout the SDLC

Nice to Have

Experience writing custom SAST rules, Familiarity with additional AppSec tools, Familiarity with API Security tools, Hands-on experience validating vulnerabilities, Working knowledge of Secure Development Lifecycles, Experience triaging technical vulnerabilities, Experience remediating technical vulnerabilities, Understanding of automated security testing approaches, Experience building security tools in CI/CD, Experience operating security tools in CI/CD, Experience with proactive security integration, Past experience as AppSec practitioner, Past experience as software engineer

What You'll Do.

Operationalize SAST tools

Troubleshoot SAST tools

Understand CI/CD pipeline tools

Understand CI/CD processes

Develop using modern technologies

Develop using modern architectures

Script automation tasks

Apply application security fundamentals

Perform threat modeling

Implement secure coding practices

Integrate security into SDLC

Write custom SAST rules

Adapt custom SAST rules

Validate application vulnerabilities

Remediate technical vulnerabilities

Build security tools in CI/CD

Operate security tools in CI/CD

Integrate security into development process

How You'll Work.

Team & Collaboration

Cross-functional teams; Colleagues; Mentorship

Communication Scope

Written communication; Verbal communication

Process & Methodology

Software Development Lifecycle

Full Job Description

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U. S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk. Required Experience: Proficiency with the implementation, operationalization, and troubleshooting of Static Application Security Testing (SAST) tools such as Semgrep, Snyk, CodeQL, Checkmarx, Veracode, etc. Understanding of Continuous Integration / Continuous Delivery (CI/CD) pipeline tools and processes (e. g. GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, CircleCI, etc.) Experience in software engineering, ideally full stack software development, including modern technologies and application architectures Strong scripting and automation experience using one or more programming languages Solid working knowledge of application security fundamentals including the OWASP Top 10, threat modeling, and implementing secure coding practices throughout the Software Development Lifecycle (SDLC) Excellent written and verbal communication skills Preferred: Experience writing or adapting custom SAST rules (Semgrep or CodeQL) Familiarity with additional Application Security tools (e. g. Interactive (IAST), Dynamic (DAST) and API security, SCA, etc.) Familiarity with API Security tools (e.g., NoName, Traceable, Salt, Cequence) Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities identified by web application scanning tools Understanding of automated security testing approaches and tools Experience in building and operating security tools within CI/CD pipelines Experienc

Free ATS check

Applying for this Senior Application Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about GuidePoint Security?

Real rants from real employees. Read before you apply.

Read Company Rants →