Application Security EngineerThis role focuses on identifying, analyzing, and mitigating application security vulnerabilities throughout the SDLC. It supports a broader "Shift Left" cybersecurity strategy, ensuring security is integrated early in development and reinforced through DevSecOps practices.Key Responsibilities:Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testingAnalyze vulnerabilities and recommend secure coding fixesDemonstrate vulnerabilities to development teamsDrive remediation efforts to closureWork within CI/CD pipelines using tools such as: Jenkins, GitLab, GitHub Actions, TeamCity, Checkmarx, GitHub Advanced Security, Burp SuiteIntegrate security controls into development workflowsLead Web Application Firewall (WAF) deployment for new and existing appsImplement application security policies, controls, and standardsPartner with development, platform, and supplier teamsProvide clear remediation guidanceTrain teams on secure coding and application security practicesDevelop training materialsConduct security assessments using standard toolsTrack and report: Risks, Milestones, Deliverables, Status updatesRecommend strategies based on application risk postureThis role is based in Auburn Hills, MI and is required to be on-site in our HQ building 5 days per week.Basic Qualifications:Bachelor's degree in Computer Science, Information Technology, or related field3+ years of hands-on experience in application security, security testing, and DevSecOpsStrong understanding of: Application architectures (web, mobile, APIs), Software development methodologies (Agile, SDLC), Modern programming languages (Java, C#, Python)Experience performing and interpreting results from: SAST, DAST, IAST, SCA, and mobile security testing toolsHands-on experience with secure code review in common languages (Java, C#, Python preferred)Prior background in application development, including: Compiled code, Web applications / services, Mobile app developmentKnowledge of security frameworks and standards: NIST, ISO 27001, NIST SSDF or similar secure development frameworksStrong understanding of: OWASP Top 10 vulnerabilities and mitigation techniques, Common attack vectors (web exploits, DDoS, bot attacks)Experience with WAF technologies: Akamai, Cloudflare, AWS WAF, Azure Front DoorFamiliarity with cloud platforms and modern environments: AWS, Azure, GCP, Containers (Docker, Kubernetes)Working knowledge of: Programming/scripting: Java, JavaScript, SQL, HTML, Scripting languages (Python, Bash preferred)Strong analytical, problem-solving, and communication skillsAbility to explain technical risks to non-technical audiencesExperience writing security reports and documentationAbility to work independently and cross-functionallyPreferred Qualifications:Industry certifications: GIAC GWEB, ISC2 CSSLP, EC-Council CASE, or equivalent AppSec certifications