GuidePoint Security LLC
Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, DE, NJ, or DC)
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 3 weeks ago · Added 5 days ago
Been open since 3 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
United States only
Timezone
Not stated
Contract
Full-time
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $165k–$225k a year, a typical range taken from 598 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote, Mid-Atlantic"
- Job description states: "U.S. based"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
Required Experience :
Proficiency with the implementation, operationalization, and troubleshooting of Static Application Security Testing (SAST) tools such as Semgrep, Snyk, CodeQL, Checkmarx, Veracode, etc.
Understanding of Continuous Integration / Continuous Delivery (CI/CD) pipeline tools and processes (e.g. GitHub Actions, GitLab Runners, Azure DevOps, Jenkins, CircleCI, etc.)
Experience in software engineering, ideally full stack software development, including modern technologies and application architectures
Strong scripting and automation experience using one or more programming languages
Solid working knowledge of application security fundamentals including the OWASP Top 10, threat modeling, and implementing secure coding practices throughout the Software Development Lifecycle (SDLC)
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Excellent written and verbal communication skills
Preferred :
Experience writing or adapting custom SAST rules (Semgrep or CodeQL)
Familiarity with additional Application Security tools (e.g. Interactive (IAST), Dynamic (DAST) and API security, SCA, etc.)
Familiarity with API Security tools (e.g., NoName, Traceable, Salt, Cequence)
Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite
Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities identified by web application scanning tools
Understanding of automated security testing approaches and tools
Experience in building and operating security tools within CI/CD pipelines
Experience with proactive integration of security into the development process
Past experience as an application security practitioner or software engineer
Educational & Professional Credentials :
Bachelor’s degree in a relevant discipline or equivalent experience
5-7 years of security engineering experience in the Information Security industry
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint? GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Requirements
- ·Experience writing or adapting custom SAST rules (Semgrep or CodeQL)
- ·Familiarity with additional Application Security tools (e.g. Interactive (IAST), Dynamic (DAST) and API security, SCA, etc.)
- ·Familiarity with API Security tools (e.g., NoName, Traceable, Salt, Cequence)
- ·Practical hands-on experience validating vulnerabilities and proficiency with Burp Suite
- ·Strong working knowledge of Secure Development Lifecycles and experience triaging and remediating technical vulnerabilities identified by web application scanning tools
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at GuidePoint Security LLC, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $165k to $225k per year · You'll be taken to the employer's careers page.