Skip to main content

GuidePoint Security

Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)

Remote (Remote)midAdded 1 month ago

About this role

GuidePoint Security seeks a mid-level Application Security Engineer to implement and manage SAST tools, secure CI/CD pipelines, and integrate security practices throughout the software development lifecycle. You'll work remotely across the Mid-Atlantic region, leveraging your software engineering background and application security expertise to help enterprise and government clients reduce risk.

What you'll do

  • Deploy, configure, and troubleshoot SAST tools like Semgrep, Snyk, CodeQL, and Checkmarx
  • Integrate application security controls into CI/CD pipelines and automation workflows
  • Triage and remediate vulnerabilities identified by security scanning tools
  • Develop custom SAST rules and validation approaches for automated security testing
  • Collaborate with development teams to implement secure coding practices and threat modeling
  • Evaluate and recommend additional application security tools (DAST, IAST, API security)

What they're looking for

  • SAST tool implementation and operationalization
  • CI/CD pipeline tools (GitHub Actions, GitLab, Azure DevOps, Jenkins, CircleCI)
  • Full stack software development and modern application architectures
  • Scripting and automation with multiple programming languages
  • OWASP Top 10 and secure development lifecycle knowledge
  • Burp Suite and vulnerability validation
  • API security tools and dynamic application testing
  • Written and verbal communication

Benefits

  • Remote position within VA, MD, PA, NC, DE, NJ, or DC
  • Comprehensive medical, dental, and vision insurance with high employer contributions
  • HSA contributions up to $1,750 annually for family plans
  • Flexible Time Off and 12 corporate holidays
  • Mobile phone and home internet allowance
  • Retirement plan eligibility after 2 months; pet benefit option
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

GuidePoint Security

GuidePoint Security builds and deploys security infrastructure and automation solutions for federal government, intelligence community, and enterprise clients. The company is hiring for specialized security engineering roles including cloud security architects, network security engineers, Linux automation specialists, and security operations professionals with expertise in platforms like Splunk, Zscaler, and firewall technologies.

View all jobs at GuidePoint Security

Likely interview questions

  • Walk us through your experience implementing and operationalizing SAST tools like Semgrep, Snyk, or Checkmarx. What challenges have you faced and how did you overcome them?
  • Describe a time you integrated application security into a CI/CD pipeline. Which tools did you use, and how did you handle false positives or tool tuning?