Application Security Engineer (Hybrid)
resolution technologiesAtlanta (GA)
Application Security Engineer (Hybrid)
Posted today
resolution technologiesAtlanta (GA)
SENIORITY
Lead
About the role
Application Security Engineer Career Opportunity We are seeking a skilled and proactive Application Security Engineer to join our security team. This role is critical in ensuring the security of our applications across platforms including Salesforce,.NET applications, and Azure App Services. The ideal candidate will have a strong background in secure coding practices, Dev Sec Ops, and penetration testing, with hands-on experience managing security tools and integrating them into CI/CD pipelines using Git and Azure Dev Ops. Familiarity with NIST cybersecurity controls and secure design principles is essential. Application Security Engineer Role and Responsibilities Salesforce Security: Review Apex code, Visualforce pages, and Lightning components for security vulnerabilities. Ensure proper configuration of Salesforce security settings including profiles, permission sets, role hierarchies, and sharing rules. Implement and monitor field-level security, object-level access, and record-level access controls. Validate secure integration patterns for external APIs and third-party apps within Salesforce. Enforce OAuth scopes, connected app policies, and IP restrictions. Conduct regular security health checks and Salesforce Shield audits. Align Salesforce security architecture with NIST 800-53 and NIST CSF controls. Secure Development Lifecycle (SDLC): Collaborate with development teams to integrate security best practices into the SDLC. Conduct secure code reviews for applications built on Salesforce,.NET, and Azure platforms. Design and review application architectures to ensure alignment with NIST controls. Perform threat modeling and risk assessments for new and existing applications. Maintain and enhance security integrations with Git, Azure Dev Ops, and other version control systems. Application Security Testing: Perform manual and automated penetration testing of web applications and APIs. Identify and remediate vulnerabilities in Salesforce customizations,.NET codebases, and Azure-hosted services. Tool Management: Own the configuration, tuning, and maintenance of Dev Sec Ops tools (e.g., Sonar Qube, Checkmarx, Veracode, Fortify). Monitor and report on security tool performance and coverage. Governance, Risk & Compliance: Map application security controls to NIST standards and support audit readiness. Document security requirements and ensure traceability to NIST control families. Collaboration & Training: Partner with engineering, QA, and operations teams to drive security awareness and training. Provide guidance on secure coding standards and remediation strategies. Incident Response & Risk Management: Support incident response efforts related to application vulnerabilities. Contribute to risk assessments and mitigation planning for new and existing applications.
Application Security Engineer Required Qualifications:
Bachelor degree in Computer Science, Information Security, or related field (or equivalent experience). 7+ years of experience in application security, Dev Sec Ops, or related roles. Strong understanding of secure coding practices in. NET and Apex (Salesforce). Experience with Salesforce security architecture and Azure App Services. Proficiency in CI/CD pipelines and integrating security tools into Git and Azure Dev Ops workflows. Familiarity with NIST 800-53, NIST CSF, and other cybersecurity frameworks. Hands-on experience with SAST, DAST, SCA, and container security tools. Strong scripting skills (e.g., Power Shell, Python, Bash) for automation.
Preferred Qualifications:
Certifications such as OSCP, GWAPT, CSSLP, or Salesforce Security Specialist. #RT #MCB #DICEJOBS
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
