Application Security Engineer (Hybrid)
resolution technologiesAtlanta, GA
About the role
Application Security Engineer Career Opportunity We are seeking a skilled and proactive Application Security Engineer to join our security team. This role is critical in ensuring the security of our applications across platforms including Salesforce, .NET applications, and Azure App Services. The ideal candidate will have a strong background in secure coding practices, DevSecOps, and penetration testing, with hands-on experience managing security tools and integrating them into CI/CD pipelines using Git and Azure DevOps. Familiarity with NIST cybersecurity controls and secure design principles is essential. Application Security Engineer Role and Responsibilities Salesforce Security: Review Apex code, Visualforce pages, and Lightning components for security vulnerabilities. Ensure proper configuration of Salesforce security settings including profiles, permission sets, role hierarchies, and sharing rules. Implement and monitor field-level security, object-level access, and record-level access controls. Validate secure integration patterns for external APIs and third-party apps within Salesforce. Enforce OAuth scopes, connected app policies, and IP restrictions. Conduct regular security health checks and Salesforce Shield audits. Align Salesforce security architecture with NIST 800-53 and NIST CSF controls. Secure Development Lifecycle (SDLC): Collaborate with development teams to integrate security best practices into the SDLC. Conduct secure code reviews for applications built on Salesforce, .NET, and Azure platforms. Design and review application architectures to ensure alignment with NIST controls. Perform threat modeling and risk assessments for new and existing applications. Maintain and enhance security integrations with Git, Azure DevOps, and other version control systems. Application Security Testing: Perform manual and automated penetration testing of web applications and APIs. Identify and remediate vulnerabilities in Salesforce customizations, .NET codebases, and Azure-hosted services. Tool Management: Own the configuration, tuning, and maintenance of DevSecOps tools (e.g., SonarQube, Checkmarx, Veracode, Fortify). Monitor and report on security tool performance and coverage. Governance, Risk & Compliance: Map application security controls to NIST standards and support audit readiness. Document security requirements and ensure traceability to NIST control families. Collaboration & Training: Partner with engineering, QA, and operations teams to drive security awareness and training. Provide guidance on secure coding standards and remediation strategies. Incident Response & Risk Management: Support incident response efforts related to application vulnerabilities. Contribute to risk assessments and mitigation planning for new and existing applications. Application Security Engineer Required Qualifications Bachelor degree in Computer Science, Information Security, or related field (or equivalent experience). 7+ years of experience in application security, DevSecOps, or related roles. Strong understanding of secure coding practices in .NET and Apex (Salesforce). Experience with Salesforce security architecture and Azure App Services. Proficiency in CI/CD pipelines and integrating security tools into Git and Azure DevOps workflows. Familiarity with NIST 800-53, NIST CSF, and other cybersecurity frameworks. Hands-on experience with SAST, DAST, SCA, and container security tools. Strong scripting skills (e.g., PowerShell, Python, Bash) for automation.
Preferred Qualifications:
Certifications such as OSCP, GWAPT, CSSLP, or Salesforce Security Specialist. #RT #MCB #DICEJOBS
Matching similar jobs
JOB OVERVIEW
Experience level
Lead
Location
Atlanta, GA
Occupation
Information Security Engineers
Industry
Computer Systems Design Services
Posted
today
Tired of running searches?
Rank the roles you'd take once, and matches like these arrive on their own.
CREATE PROFILE