Application Security Engineer

New York, NY, US • Posted 10 hours ago • Updated 10 hours ago
Contract W2
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🧠 Analyzing your skills...

Job Details

Skills

  • Application Security Engineer
  • NIST 800-53
  • Veracode
  • SAST
  • DAST
  • Rest API Security
  • web and mobile application Architecture
  • Java
  • React
  • GIS Systems

Summary

Application Security Engineer- in Brooklyn, NY (On-site)


Position Overview

The Application Security Engineer is embedded within the Application Development team and ensures security is integrated into all stages of software development. The role focuses on designing and building secure applications while working closely with application administrators who manage security tools and CI/CD pipelines.

This position is responsible for enabling developers to produce secure, resilient, and compliant software for the client''s web, mobile, API, GIS, and cloud-based systems supporting Fire, EMS, and administrative operations.


Core Responsibilities

1. Secure Software Development

  • Establish and apply secure coding practices within the development team.
  • Define and enforce secure coding standards for Java, .NET, Python, and JavaScript applications.
  • Conduct secure design and architecture reviews for new and legacy systems.
  • Educate developers on secure coding practices, authentication/authorization best practices, and common application vulnerabilities.
  • Apply protections aligned with:
    • OWASP Top 10
    • OWASP API Security Top 10

2. Application & API Security

  • Design and implement secure REST APIs and web services.
  • Implement secure authentication/authorization using:
    • SAML2
    • OIDC
    • OAuth2
  • Secure Java and JavaScript applications, including:
    • Spring Boot
    • React
  • Ensure secure handling of tokens, sessions, and secrets.
  • Collaborate with App Admins and the Security team to integrate applications into WAFs, load balancers, and other security monitoring tools.

Mandatory Qualifications

  • Minimum 4+ years in secure application development.
  • Prior hands-on software development experience.
  • Strong understanding of:
    • Web and mobile application architecture
    • Internet protocols (HTTP, HTTPS, WebSockets)
    • REST API security
  • Expertise in SAST, DAST, and SCA concepts (understanding results and remediation), in collaboration with App Admins.
  • Familiarity with security tools such as Veracode, Burp Suite, Zimperium, Prisma, Rapid7.
  • Experience applying NIST 800-53 and 800-171 controls at the application design level.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work independently within a development-focused team.

Preferred Qualifications

  • Experience with containerized applications (Docker, Kubernetes).
  • Knowledge of:
    • Core Java, J2EE, Spring Boot
    • React, AngularJS, HTML5, CSS, JavaScript
  • Experience designing secure GIS systems.
  • Familiarity with public safety or emergency response systems.
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: RTL208955
  • Position Id: 8914608
  • Posted 10 hours ago

Company Info

About SunTechPros, Inc.

SunTechPros, consultant Solutions Company started by group of highly experienced IT consultants focused on becoming the central source for all IT consulting services. We truly committed to taking the time to get to know our Consultant and clients and their needs.



We are committed to earn a level of trust that goes beyond the typical client/supplier relationship. We enjoy lasting, ongoing relationships with our clients and consider ourselves a partner in their success. At SunTechPros we have team of individuals who have the knowledge and the commitment to deliver expected results.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs