×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer

Job in Jacksonville, Duval County, Florida, 32290, USA
Listing for: Corps Team
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 92000 - 107000 USD Yearly USD 92000.00 107000.00 YEAR
Job Description & How to Apply Below

Our client, a diversified financial services company providing banking and investing services, is seeking a Senior Application Security Engineer for a 6 month contract role ocated in Jacksonville, FL. This role is fully onsite.

POSITION

PURPOSE:

Own and optimize application security testing capabilities across the software development lifecycle, with emphasis on SAST, DAST, SCA, Sonar Qube, scanning configuration, vulnerability triage, and actionable reporting.

Position Summary:

The Senior Application Security Engineer is responsible for designing, implementing, and optimizing application security capabilities across the software development lifecycle. Working under limited supervision, this individual contributor partners with development, Dev Ops, architecture, risk, and cybersecurity teams to integrate security testing into delivery processes, identify application vulnerabilities, and improve secure development practices. The role provides technical expertise for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secure code review, and code quality analysis.

The engineer configures and tunes scanning technologies, validates findings, supports remediation, and develops meaningful reporting for technical and executive stakeholders.

Key

Responsibilities and Duties:
  • Administer, configure, tune, and optimize application security platforms supporting SAST, DAST, and SCA capabilities.
  • Manage and maintain Sonar Qube and similar code analysis technologies, including scanning configurations, rule profiles, quality gates, access, integrations, and reporting.
  • Develop and maintain application security scanning standards, procedures, runbooks, and operating documentation.
  • Integrate application security testing into CI/CD pipelines and Dev Sec Ops  workflows in partnership with development and platform engineering teams.
  • Triage and validate security findings, reduce false positives, document risk decisions, and improve the accuracy and usefulness of scan results.
  • Partners with application teams to prioritize and remediate vulnerabilities based on exploitability, business context, compensating controls, and organizational risk criteria.
  • Provide secure coding guidance and technical consultation aligned with OWASP practices, the NIST Secure Software Development Framework, and internal security standards.
  • Create dashboards, metrics, and key risk indicators that communicate application security coverage, finding trends, remediation performance, scan health, and control effectiveness.
  • Analyze recurring vulnerability patterns and recommend preventive controls, developer education, rule changes, or pipeline improvements.
  • Support threat modeling, architecture reviews, secure design assessments, and targeted code reviews for new and existing applications.
  • Assist with audit, examination, and risk assessment requests by providing accurate evidence and documentation for application security controls.
  • Research emerging application security threats, vulnerabilities, attack techniques, and testing methods to continuously improve the program.
  • Serve as a senior technical subject matter expert and mentor, without formal responsibility for assigning, reviewing, or delegating the work of other employees.
Minimum Qualifications

Bachelor’s degree in Information Security, Computer Science, Software Engineering, or a related field preferred, or equivalent relevant experience. 5 or more years of cybersecurity, software engineering, Dev Sec Ops , vulnerability management, or application security experience. 3 or more years of direct experience operating, administering, or integrating application security scanning technologies. Hands-on experience with SAST and DAST scanning configuration, execution, tuning, triage, and reporting.

Working knowledge of SCA, secure code review, vulnerability management, and remediation practices. Experience with Sonar Qube or a comparable code quality and security analysis platform. Understanding of modern application architectures, APIs, containers, microservices, and cloud-native delivery patterns. Familiarity with CI/CD platforms, source code management, build automation, and Dev Sec Ops  processes. Ability to communicate technical risk and remediation guidance clearly to developers, engineers, managers, and nontechnical stakeholders.

Preferred Qualifications

7 or more years of cybersecurity, software security, software engineering, or application security experience. Advanced experience with Sonar Qube administration, custom rule profiles, quality gates, project onboarding, integration, and reporting. Experience with commercial application security technologies such as Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or comparable platforms. Experience integrating security testing into Git Hub, Git Lab, Azure Dev Ops, Jenkins, or similar CI/CD platforms.

Knowledge of OWASP Top 10, OWASP ASVS, NIST SSDF, secure SDLC practices, and…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary