Match your resume skills with our AI powered skill match!
The Specialist II will partner with development and DevOps teams to embed secure coding practices and automate security testing throughout the software development lifecycle. They are responsible for managing vulnerability remediation, conducting API security assessments, and maintaining security tools within CI/CD pipelines.
Job Title:
Specialist II, Application Security (TCF)Job Description
We're Concentrix. The intelligent transformation partner. Solution-focused. Tech-powered. Intelligence-fueled.
The Specialist II, Application Security plays a key role in strengthening application security across the software development lifecycle. This role partners closely with Security, DevOps, and Development teams to embed secure coding practices, automate security testing, and support timely vulnerability remediation. The ideal candidate will help advance DevSecOps maturity by integrating security tools, improving CI/CD pipeline controls, and reducing risks across applications, APIs, and internet-facing assets.
Responsibilities
Serve as a key bridge between Security, DevOps, and Development teams to embed security throughout the SDLC.
Partner with application developers to promote secure coding practices, identify security gaps, and recommend effective remediation.
Provide training and guidance to developers on secure coding standards, application security risks, and security tools within CI/CD pipelines.
Support and enhance DevSecOps practices with a focus on automated security testing across development workflows.
Integrate and maintain security tools, including SAST, DAST, and SCA, within CI/CD pipelines.
Drive automation initiatives for application security assessments, including API security testing for authentication, authorization, rate limiting, sensitive data exposure, and access control.
Support external exposure management, including internet-facing asset discovery, attack surface monitoring, and vulnerability identification.
Monitor and manage risks related to internet-facing applications, including MFA, SSO, and exposure risks.
Track, prioritize, and support remediation of vulnerabilities identified through SAST, DAST, SCA, API testing, and external scanning.
Report on vulnerability remediation progress and help ensure findings are closed within defined timelines.
Collaborate with cross-functional teams on root cause analysis, security control improvements, and continuous application security enhancements.
Maintain documentation related to security findings, remediation actions, automation improvements, and DevSecOps pipeline updates.
Ensure application security practices align with organizational policies and industry standards, including OWASP and NIST.
Complete all assigned, mandatory training within the timeframe provided.
Conduct and/or participate in regularly scheduled 1:1 meetings with your direct manager and/or direct reports.
Qualifications
Experience or working knowledge in application security, DevSecOps, secure SDLC practices, or related security functions.
Understanding of secure coding practices and common application security risks.
Familiarity with security testing tools and approaches, including SAST, DAST, and SCA.
Knowledge of API security concepts, including authentication, authorization, rate limiting, access control, and sensitive data exposure.
Experience supporting vulnerability management activities, including tracking, prioritization, remediation coordination, and reporting.
Ability to collaborate effectively with Development, DevOps, and Security teams in a cross-functional environment.
Familiarity with CI/CD pipelines and the integration of automated security testing into development workflows.
Understanding of external exposure management, internet-facing application risks, and attack surface monitoring.
Knowledge of industry security standards and frameworks, including OWASP and NIST.
Strong documentation, communication, analytical, and problem-solving skills.
Ability to support root cause analysis and recommend continuous improvements to strengthen application security posture.
Comfortable providing guidance and training to technical teams on security practices and tooling.
#LI-Remote #WFH
Location:
COL Bogota - Oficinas y terrazas deLanguage Requirements:
Time Type:
Full timeStop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Others
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”