Application Security Engineer-68257
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer, Security Management & Operations
Function
Cloud & Data Engineering
Our CompanyWe’re Hitachi Digital Services, a global digital solutions and transformation business with a bold vision of our world’s potential. We’re people-centric and here to power good. Every day, we future-proof urban spaces, conserve natural resources, protect rainforests, and save lives. This is a world where innovation, technology, and deep expertise come together to take our company and customers from what’s now to what’s next.
We make it happen through the power of acceleration.
Imagine the sheer breadth of talent it takes to bring a better tomorrow closer to today. We don’t expect you to ‘fit’ every requirement – your life experience, character, perspective, and passion for achieving great things in the world are equally as important to us.
Job description Application Security EngineerCompany: Hitachi Digital Services
Practice: HARC Security
Location: Dallas, TX (Onsite)
Experience: 2+ Years
Hitachi Digital Services is seeking an Application Security Engineer to support application security, Dev Sec Ops , secure software development, and AI-enabled security initiatives. The ideal candidate should have hand-on experience with application security testing, CI/CD security, vulnerability management, secure code reviews, and OWASP-based security practices.
Key Responsibilities- Perform application security assessments for web, API, cloud-native, and AI-enabled applications.
- Conduct secure code reviews and support vulnerability remediation efforts.
- Integrate security controls into CI/CD pipelines and Dev Sec Ops workflows.
- Analyze findings from SAST, DAST, SCA, container security, and secret scanning tools.
- Participate in threat modeling and application security design reviews.
- Provide guidance on secure coding practices, OWASP Top 10, and OWASP API Security Top 10.
- Collaborate with development teams to improve security posture and adopt secure-by-design principles.
- Minimum 2 years of experience in Application Security, Dev Sec Ops , Secure Development, or Software Security.
- Strong understanding of:
- OWASP Top 10
- Secure SDLC
- Threat Modeling
- Secure Code Review
- API Security Fundamentals
- Familiarity with CI/CD platforms such as:
- Azure Dev Ops
- Git Hub Actions
- Jenkins
- Git Lab CI/CD
- Hands-on experience with one or more:
- SAST: Checkmarx, Veracode, Fortify, Sonar Qube
- DAST: Burp Suite, OWASP ZAP
- SCA: Snyk, Mend, Black Duck
- Knowledge of containers and Kubernetes security fundamentals.
- Basic scripting/programming skills (Python, Power Shell, JavaScript, Java, C#, etc.).
- Experience with Azure and/or AWS cloud environments.
- Knowledge of Dev Sec Ops automation and Infrastructure-as-Code security (Terraform, Bicep, ARM, Cloud Formation).
- Experience securing containerized and cloud-native applications.
- Familiarity with AI-assisted development tools (Git Hub Copilot, Amazon Q, Cursor, etc.).
- Understanding of AI/LLM security concepts, including prompt injection, sensitive data exposure, model misuse, and OWASP Top 10 for LLM Applications.
- Experience with vulnerability management and application security governance programs.
- Security+
- SSCP
- CySA+
- CEH
- CSSLP
- AZ-500
- AWS Certified Security - Specialty
- Relevant Application Security, Dev Sec Ops , or Cloud Security certifications
Application Security
• Dev Sec Ops
• Secure SDLC
• OWASP Top 10
• OWASP API Security Top 10
• AI Security
• Secure Code Review
• Threat Modeling
• SAST
• DAST
• SCA
• CI/CD Security
• Container Security
• Kubernetes Security
• Cloud Security (Azure/AWS)
• Vulnerability Management
• Security Automation
Job Level: P10
Focus Areas: Application Security, Dev Sec Ops , AI Security, Secure SDLC, CI/CD Security, Vulnerability Management, Container &…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).