For Employers

FyerX

Application Security (AppSec) / DevSecOps Engineer

Posted a day ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

Integrate automated security testing into CI/CD pipelines, manage application scanning and vulnerability remediation, and lead threat modeling and secure coding practices. Govern security dashboards and secrets management, harden containerized workloads, and investigate application-layer incidents.

This is a remote position.

Application Security (AppSec) / DevSecOps Engineer

Job Details
  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 4 to 8 years
  • Relevant Experience Required: 3+ years of dedicated experience securing software development lifecycles (SDLC) and engineering DevSecOps pipelines
  • Mandatory Certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH

Job Summary
We are seeking an experienced Application Security / DevSecOps Engineer to bake robust safety controls directly into our automated software delivery frameworks. The ideal candidate will bridge software engineering with security operations, implementing automated code testing gates, leading threat modeling workshops, and hardening application containers to identify and mitigate software vulnerabilities before code hits production.

Key Responsibilities
  • Design and integrate automated security testing gates directly into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Configure and manage application scanning frameworks, orchestrating Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tooling.
  • Triage and remediate software vulnerabilities, analyzing code flaws, open-source dependency risks, and secret exposure incidents alongside software development teams.
  • Lead comprehensive threat modeling assessments for new applications and architecture features, identifying attack surfaces and defining secure coding frameworks.
  • Govern application security infrastructure, managing centralized vulnerability aggregation dashboards (e.g., DefectDojo, SonarQube) and secret vaults (e.g., HashiCorp Vault, AWS Secrets Manager).
  • Secure containerized application workloads, auditing Dockerfile construction rules, verifying baseline machine images, and checking Kubernetes network isolation parameters.
  • Drive application layer incident investigations, analyzing malicious payload web requests, API tampering logs, and cross-site scripting (XSS) vectors to improve software perimeters.



Requirements

  • 4 to 8 years of core software engineering or cloud DevOps experience, with 3+ dedicated years actively designing, building, and deploying application safety frameworks.
  • Strong technical mastery of automated testing engines (e.g., Snyk, Checkmarx, Veracode, OWASP ZAP), container security paradigms, and infrastructure-as-code hardening.
  • Deep structural understanding of the OWASP Top 10 vulnerabilities, API security perimeters, modern secure coding standards, and cryptographic signing protocols.
  • Mandatory certification: CASE, CDP, CSSLP, or CEH.

Preferred Qualifications
  • Prior experience with software development in languages like Java, Python, JavaScript/Node.js, or Go.
  • Experience implementing automated code patching routines or managing runtime application self-protection (RASP) layers.






Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Full Stack Software Engineer - Authoring Tools (Remote, Greece or Cyprus)

Full Time Greece Software Development

AI Automation QA

Full Time United Kingdom Software Development

Salesforce Developer

Full Time United States Software Development

AI Engineer

Full Time India Software Development

Software Development Engineer in Test (SDET)

Full Time India Software Development

Procurement Administrator

Full Time South Africa Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 216,306+ Jobs in Software Development

Answer easy questions

Answer easy questions

216,306+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified