Talent.com
Corps Team
Senior Application Security EngineerCorps Team • Jacksonville, FL, US
Senior Application Security Engineer

Senior Application Security Engineer

Corps Team • Jacksonville, FL, US
1 day ago
Salary
$67.30–$78.20 hourly
Job type
  • Temporary
  • Quick Apply
Job description

Our client, a diversified financial services company providing banking and investing services, is seeking a Senior Application Security Engineer for a 6 month contract role ocated in Jacksonville, FL. This role is fully onsite.

POSITION PURPOSE:
Own and optimize application security testing capabilities across the software development lifecycle, with emphasis on SAST, DAST, SCA, SonarQube, scanning configuration, vulnerability triage, and actionable reporting.

Position Summary:
The Senior Application Security Engineer is responsible for designing, implementing, and optimizing application security capabilities across the software development lifecycle. Working under limited supervision, this individual contributor partners with development, DevOps, architecture, risk, and cybersecurity teams to integrate security testing into delivery processes, identify application vulnerabilities, and improve secure development practices.

The role provides technical expertise for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secure code review, and code quality analysis. The engineer configures and tunes scanning technologies, validates findings, supports remediation, and develops meaningful reporting for technical and executive stakeholders.

Key Responsibilities and Duties:

  • Administer, configure, tune, and optimize application security platforms supporting SAST, DAST, and SCA capabilities.
  • Manage and maintain SonarQube and similar code analysis technologies, including scanning configurations, rule profiles, quality gates, access, integrations, and reporting.
  • Develop and maintain application security scanning standards, procedures, runbooks, and operating documentation.
  • Integrate application security testing into CI/CD pipelines and DevSecOps workflows in partnership with development and platform engineering teams.
  • Triage and validate security findings, reduce false positives, document risk decisions, and improve the accuracy and usefulness of scan results.
  • Partners with application teams to prioritize and remediate vulnerabilities based on exploitability, business context, compensating controls, and organizational risk criteria.
  • Provide secure coding guidance and technical consultation aligned with OWASP practices, the NIST Secure Software Development Framework, and internal security standards.
  • Create dashboards, metrics, and key risk indicators that communicate application security coverage, finding trends, remediation performance, scan health, and control effectiveness.
  • Analyze recurring vulnerability patterns and recommend preventive controls, developer education, rule changes, or pipeline improvements.
  • Support threat modeling, architecture reviews, secure design assessments, and targeted code reviews for new and existing applications.
  • Assist with audit, examination, and risk assessment requests by providing accurate evidence and documentation for application security controls.
  • Research emerging application security threats, vulnerabilities, attack techniques, and testing methods to continuously improve the program.
  • Serve as a senior technical subject matter expert and mentor, without formal responsibility for assigning, reviewing, or delegating the work of other employees.

Minimum Qualifications

  • Bachelor’s degree in Information Security, Computer Science, Software Engineering, or a related field preferred, or equivalent relevant experience.
  • 5 or more years of cybersecurity, software engineering, DevSecOps, vulnerability management, or application security experience.
  • 3 or more years of direct experience operating, administering, or integrating application security scanning technologies.
  • Hands-on experience with SAST and DAST scanning configuration, execution, tuning, triage, and reporting.
  • Working knowledge of SCA, secure code review, vulnerability management, and remediation practices.
  • Experience with SonarQube or a comparable code quality and security analysis platform.
  • Understanding of modern application architectures, APIs, containers, microservices, and cloud-native delivery patterns.
  • Familiarity with CI/CD platforms, source code management, build automation, and DevSecOps processes.
  • Ability to communicate technical risk and remediation guidance clearly to developers, engineers, managers, and nontechnical stakeholders.

Preferred Qualifications

  • 7 or more years of cybersecurity, software security, software engineering, or application security experience.
  • Advanced experience with SonarQube administration, custom rule profiles, quality gates, project onboarding, integration, and reporting.
  • Experience with commercial application security technologies such as Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or comparable platforms.
  • Experience integrating security testing into GitHub, GitLab, Azure DevOps, Jenkins, or similar CI/CD platforms.
  • Knowledge of OWASP Top 10, OWASP ASVS, NIST SSDF, secure SDLC practices, and common application weakness classifications.
  • Experience producing operational dashboards, executive metrics, key risk indicators, and trend reporting.
  • Experience working in regulated financial services or another highly regulated enterprise environment.
  • Experience supporting FFIEC, OCC, SOX, PCI DSS, or comparable audit and regulatory requirements.
  • Experience automating application security workflows and reporting through PowerShell, Python, APIs, or vendor scripting.

Preferred Certifications

  • CSSLP
  • GWAPT, GWEB, GSSP, or another relevant GIAC certification
  • OSWE or a comparable advanced application security certification
  • CISSP
  • Microsoft Azure Security Engineer Associate, AWS Certified Security – Specialty, or a comparable cloud security certification

Must Have:

  • Experience managing and tuning SAST, DAST, or SCA security scanning platforms.
  • Experience in integrating application security controls into CI/CD and DevSecOps workflows.
  • Experience analyzing vulnerabilities and partnering with development teams to drive remediation.

Nice-to-Have:

  • Experience in regulated environments (financial services preferred).
  • Automation, scripting, and security reporting/dashboard experience.
  • Code Quality Analysis tool administration and configuration experience.

Pay Rate- $67.30- $78.20/hour

Create a job alert for this search

Senior Application Security Engineer • Jacksonville, FL, US

Similar jobs

Security Agent

ACTS-Aviation Security IncJacksonville, FL, United States
Full-time

DescriptionJoin a Global Leader in Aviation Security!Medical, dental & vision insurance available! 401K with company matching! Paid vacation & holidays!ACTS-Aviation Security, Inc.Full-Time... Show more

 • Promoted

Cybersecurity Engineer - Remote

American Recruiting & Consulting GroupJacksonville, FL, United States
Remote
Full-time

Cybersecurity EngineerARC Group has an immediate opportunity for a Cybersecurity Engineer! This position is 100% remote working eastern time zone business hours.This is starting out as a contract p... Show more

 • Promoted

Analyst Senior Implementation

Omni InclusiveJacksonville, FL, United States
Full-time

Senior-level SME and individual contributor delivering FIS imaging and distributed capture solutions across ImageCentre, Voyager, Chargeback Manager, DirectLink, CCX, FXD, DLM, and DLC platforms.Op... Show more

 • Promoted

AWS Security Architect REMOTE (PST Timezone)

Simple SolutionsJacksonville, FL, United States
Remote
Full-time

AWS Security ArchitectKey word search :AWS Certified Security - Specialty who also have a CISSP or CCSP designationThe primary objective is to provide advisory services for securing and drafting cy... Show more

 • Promoted

Cloud Security Senior Manager Azure Infrastructure & AI

DeloitteJacksonville, FL, United States
Full-time

Deloitte is committed to providing reasonable accommodations for people with disabilities.If you require a reasonable accommodation to participate in the recruiting process, please direct your inqu... Show more

 • Promoted

Project Manager Security Installation

Pathway TechnologiesJacksonville, FL, United States
Full-time

About the RoleWe are seeking an experienced Project Manager - Security Installation & Integration to lead end-to-end delivery of physical security projects including access control, CCTV, intru... Show more

 • Promoted

Advanced Cyber Threat Response & Forensics Lead/Manager

DeloitteJacksonville, FL, United States
Full-time

Cyber Defense And Resilience Team Member.Deloitte's Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilitie... Show more

 • Promoted

Service Design Delivery Engineer

Apex SystemsJacksonville, FL, United States
Full-time

Service Design Delivery Engineer.This position oversees the delivery of collaboration and productivity solutions.The role requires technical knowledge and process expertise to introduce and manage ... Show more

 • Promoted

Cyber Security Director - Public Sector (Location: Tallahassee)

RSMJacksonville, FL, United States
Full-time

Public Sector Security And Privacy Director.To meet the evolving cybersecurity needs of our clients, RSM US LLP has established the Cyber Risk and Data Protection (CYBER) groupan elite team of over... Show more

 • Promoted

Cloud Security Manager Azure Infrastructure & AI

DeloitteJacksonville, FL, United States
Full-time

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.Join our team to deliver powerful solutions to help our clients navigate the ever-changi... Show more

 • Promoted

Training Expert - Electronic Warfare Operator (EWO)

ASECJacksonville, FL, United States
Full-time

Training Expert Electronic Warfare Operator (EWO).Security Clearance Requirement: Active DoD Secret with the ability to obtain a Top Secret clearance.Telework Eligible? No, work will be performed ... Show more

 • Promoted

Information Security Analyst, Senior or Lead -- Remote

USAble Life - ExternalJacksonville, FL, United States
Remote
Full-time

Information Security Analyst, Sr.Or Lead RemoteWhen it comes to making a meaningful difference in the lives of our customers and employees, USAble Life is always ready.We are a diverse group of ind... Show more

 • Promoted

Associate Cybersecurity Engineer - Netskope - Remote

SGAJacksonville, FL, United States
Remote
Full-time

Software Guidance & Assistance, Inc.SGA), is searching for an Associate Cybersecurity Engineer - Netskope - Remote for a contract assignment with one of our premier Healthcare services clients ... Show more

 • Promoted

Security Specialist - PT

Security Industry SpecialistsJacksonville, FL, United States
Part-time

Security Specialist - PTSalary Range $20.HourlyPosition Type Part TimeDescriptionAbout the role:The Security Specialists, under the direct supervision of the Shift Supervisor, ensures SIS standards... Show more

 • Promoted

Associate Mgr Physical Security

JACKSONVILLE ELECTRIC AUTHORITYJacksonville, FL, United States
Full-time

Provides managerial oversight and operational leadership for the maintenance, reliability, and compliance of physical security and fire protection systems.Manages technicians responsible for access... Show more

 • Promoted

Security Systems Project Manager

Sciens Building SolutionsJacksonville, FL, United States
Full-time

Security Systems Project Manager.Sciens Building Solutions seeks an experienced Security Systems Project Manager (PM) responsible for the execution of low voltage system projects in accordance with... Show more