- Страна
- США
Откликайтесь
на вакансии с ИИ

Application Security Engineer - North Central region (Remote in the U.S.)
Отличная вакансия в стабильной и растущей компании с сильным социальным пакетом (100% оплата страховки, гибкий график). Удаленный формат работы в США и работа с крупными клиентами делают позицию очень привлекательной для специалистов среднего уровня.
Сложность вакансии
Роль требует глубоких знаний в области безопасности приложений (SAST/DAST/SCA) и практического опыта работы с инструментами вроде Burp Suite и Invicti. Кандидат должен уметь не только находить уязвимости, но и эффективно взаимодействовать с разработчиками для их устранения.
Анализ зарплаты
Предлагаемая роль соответствует рыночным стандартам для Application Security Engineer в США. Учитывая требования к опыту (2-3 года), зарплата находится в медианном диапазоне для специалистов уровня Middle в сфере кибербезопасности.
Сопроводительное письмо
I am writing to express my interest in the Application Security Engineer position at GuidePoint Security. With over 3 years of experience in application security and a deep understanding of the SDLC, I have successfully implemented SAST/DAST/SCA tools and collaborated with development teams to remediate critical vulnerabilities. My technical background includes extensive use of Burp Suite Pro and Invicti, which aligns perfectly with your team's preferred toolset.
Throughout my career, I have focused on integrating security into CI/CD pipelines to ensure that protection is a continuous process rather than an afterthought. I am particularly drawn to GuidePoint's holistic approach to cybersecurity and its reputation as a trusted advisor to Fortune 500 companies. I am confident that my ability to distill complex security issues into actionable recommendations for both technical and non-technical stakeholders will make me a valuable asset to your North Central region team.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в guidepointsecurity уже сейчас
Присоединяйтесь к команде экспертов GuidePoint Security и станьте ключевым звеном в защите крупнейших компаний США!
Описание вакансии
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
Roles and Responsibilities:
- Run client SAST/DAST/SCA tools, review outputs and provide recommendations
- Work with development teams to identify and remediate security vulnerabilities
- Provide security guidance during the software development lifecycle (SDLC)
- Identify, track, and prioritize security vulnerabilities
- Validate fixes and conduct retesting
- Implement and maintain application security tools and scanning solutions
- Create reports for technical and non-technical stakeholders
Experience Requirements:
- 2-3 years experience working in Application Security
- Understanding of Integrated Development Environment (IDE) and Continuous integration / Continuous Delivery (CI/CD) Pipeline tools and processes (e.g. GitHub, etc.)
- Strong working knowledge of Secure Development Lifecycles and experience remediating technical vulnerabilities identified by web application scanning tools, Information Systems architecture, security control design, and development experience
- Deep knowledge of manual testing tools such as Burp Suite Pro
- Knowledge of and experience with SAST/DAST/SCA Application Security tools. Invicti (DAST) or Checkmarx (SAST/SCA) experience highly preferred
- Experience with the integration of tools into development pipelines
- Understanding of a broad range of Application Security issues as well as their mitigation strategies
- Understanding of Application Security related vulnerabilities
- Experience with reviewing source code written in JavaScript, Python, Java, C++, PHP, or C# a plus
- Written communication skills for written interactions with clients
- Strong communication skills that include the ability to clearly articulate thoughts and distill complex problems into digestible pieces of information
- Personal drive and passion to not only continue growing yourself but also the Application Security Engineering practice
- Bachelor's degree in Computer Science or Information Security preferred
- Standard industry certifications are preferred
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- SAST
- DAST
- SCA
- SDLC
- CI/CD
- GitHub
- Burp Suite Pro
- Invicti
- Checkmarx
- JavaScript
- Python
- Java
- C++
- PHP
Возможные вопросы на собеседовании
Проверка практического опыта работы с ключевым инструментом, указанным в вакансии.
Расскажите о вашем опыте использования Burp Suite Pro для ручного тестирования. Какие расширения вы считаете наиболее полезными?
Оценка способности кандидата интегрировать безопасность в процессы разработки.
Как бы вы организовали процесс внедрения SAST-инструмента в уже существующий CI/CD конвейер, чтобы не замедлить работу разработчиков?
Проверка навыков приоритизации и оценки рисков.
Если сканер обнаружил сотни уязвимостей, по каким критериям вы будете определять, какие из них требуют немедленного исправления?
Оценка навыков коммуникации и влияния на команду разработки.
Опишите случай, когда разработчик не соглашался с важностью найденной вами уязвимости. Как вы аргументировали свою позицию?
Проверка технических знаний в области анализа кода.
Какие специфические уязвимости вы ищете при аудите исходного кода на Python или Java?
Похожие вакансии
Security Engineer
Principal Network Security Engineer
Conseiller.ère en architecture de sécurité
Security Engineer, Cloud Security
Security Engineer, Application Security
Security Engineer
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США