Hybrid Senior AppSec Engineer

Posted yesterday

Apply now

About the role

  • Senior AppSec Engineer securing applications and CI/CD pipelines at ShyftLabs, a data product company for Fortune 500 clients.

Responsibilities

  • Implement, configure, and manage Application Security Testing (AST) tools across platforms
  • Integrate security tools and automated checks into CI/CD pipelines (GitLab preferred)
  • Perform hands-on validation of vulnerabilities using tools like Burp Suite
  • Analyze and triage security findings, eliminating false positives
  • Drive end-to-end vulnerability lifecycle from identification to closure
  • Collaborate with development teams to ensure secure coding practices
  • Conduct targeted application security testing on specific components or flows
  • Manage and coordinate internal and third-party penetration testing activities
  • Monitor emerging threats, including zero-day and supply chain risks
  • Work with vendors and stakeholders to enhance AppSec tools and processes

Requirements

  • 6+ years of dedicated experience in Application Security, DevSecOps, or SSDLC engineering.
  • Hands-on experience implementing and managing a combination of ASPM, DAST, IAST, SCA, and Secret Detection tooling. Familiarity with platforms such as OX Security, Invicti, Veracode, Checkmarx, or equivalents.
  • Comfort using Burp Suite (or similar web application testing tools) to manually validate vulnerabilities, reproduce issues, and assess exploitability.
  • Proven track record integrating security tools and gates into GitLab CI/CD pipelines.
  • Strong ability to analyse vulnerability findings, distinguish true positives from false positives, and communicate risk clearly to both technical and non-technical audiences.
  • Experience managing the full lifecycle of penetration test engagements (internal and vendor-led).
  • Excellent English communication skills; comfortable working asynchronously across time zones.

Benefits

  • Competitive salary
  • Strong insurance package
  • Extensive learning and development resources

Job title

Senior AppSec Engineer

Job type

Experience level

Senior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job