RESPONSIBILITIES:
Kforce has a client that is seeking an Application Security Risk & Automation SME in San Antonio, TX.
Summary:
We are seeking an Application Security Risk & Automation Subject Matter Expert (SME) to support the automation and operationalization of Secure SDLC practices. This role will focus on improving application security processes, reducing developer friction, enhancing risk-based vulnerability management, and driving adoption of AI-assisted security workflows within a modern DevSecOps environment.
Key Responsibilities:
* Support the implementation and continuous improvement of Secure SDLC automation and application security operations
* Reduce developer friction through vulnerability validation, risk-based prioritization, and false-positive reduction
* Configure and maintain GitLab security controls, approval workflows, merge request (MR) security policies, and enforcement gates
* Implement and support AI-assisted triage, remediation recommendations, and automated findings management solutions
* Develop and maintain automation for vulnerability enrichment, correlation, routing, deduplication, and reporting
* Partner with development teams to improve remediation outcomes and increase adoption of secure development practices
* Support onboarding, integration, and operationalization of new application security tools and capabilities
* Collaborate with security, engineering, and DevOps teams to strengthen security controls throughout the software development lifecycle
REQUIREMENTS:
* 5+ years of experience in Application Security, DevSecOps, Security Engineering, or a related cybersecurity discipline
* Hands-on experience with security testing technologies including SAST, DAST, Software Composition Analysis (SCA), Container Security, and Secrets Detection
* Experience configuring GitLab security capabilities, approval workflows, policy enforcement, and secure development controls
* Experience integrating security tools with GitLab, ServiceNow, Jira, and enterprise reporting platforms
* Strong knowledge of application security concepts and the OWASP Top 10
* Understanding of software supply chain security, dependency management, and secure coding practices
* Proficiency with APIs, scripting, automation technologies, and AI-enabled workflows
* Strong analytical, problem-solving, and communication skills with the ability to collaborate effectively across technical teams
Preferred Qualifications:
* Relevant security certifications such as CSSLP, GSEC, Security+, CISSP, or comparable credentials
* Experience implementing security automation at scale within cloud-native or enterprise environments
* Experience driving process improvements that enhance developer experience while maintaining security standards
* Knowledge of CI/CD pipelines and modern DevSecOps practices
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: kforcecx
- Position Id: ITTND2186787
- Posted 5 hours ago