What are the responsibilities and job description for the Application Security Engineer - Secure SDLC & Vulnerability Management position at Artmac?
Who We Are
Artmac Soft is a technology consulting and service-oriented IT company dedicated to providing innovative technology solutions and services to Customers.
Job Description
Job Title : Application Security Engineer – Secure SDLC & Vulnerability Management
Job Type : W2
Experience : 8 to 15 years
Location : Dallas, Texas
Responsibilities
Artmac Soft is a technology consulting and service-oriented IT company dedicated to providing innovative technology solutions and services to Customers.
Job Description
Job Title : Application Security Engineer – Secure SDLC & Vulnerability Management
Job Type : W2
Experience : 8 to 15 years
Location : Dallas, Texas
Responsibilities
- Perform regular application security scans using tools such as IBM AppScan, Coverity, SonarQube, Veracode, Fortify, or similar.
- Analyze SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and SCA (Software Composition Analysis) results to identify vulnerabilities in code and dependencies.
- Collaborate with developers to remediate vulnerabilities and integrate security best practices into the SDLC.
- Track, prioritize, and manage vulnerabilities through their lifecycle, ensuring timely resolution.
- Develop and maintain security scanning processes and procedures to ensure compliance with internal security policies and industry standards.
- Conduct secure code reviews and provide recommendations to mitigate OWASP Top 10 and other common vulnerabilities.
- Ensure no new security vulnerabilities are introduced into applications or platforms before release.
- Stay updated with emerging threats, vulnerabilities, and security trends, and apply them to enhance security posture.
- Support DevSecOps initiatives by integrating security into CI/CD pipelines.
- Strong understanding of software security vulnerabilities, such as OWASP Top 10, SANS 25, SQL Injection, XSS, CSRF, etc.
- Hands-on experience with at least one security scanning tool (e.g., SonarQube, Veracode, AppScan, Fortify, Coverity).
- Basic knowledge of software development principles and secure coding practices.
- Familiarity with SDLC, DevSecOps, and security automation.
- Strong analytical and problem-solving skills.
- Excellent communication and collaboration skills to work with cross-functional teams
- Bachelor's degree or equivalent combination of education and experience.