AttainX, Inc.

Security Engineer

AttainX, Inc.

full-time

Posted on:

Origin:  • 🇺🇸 United States

Visit company website
AI Apply
Apply

Salary

💰 $115,000 - $145,000 per year

Job Level

Mid-LevelSenior

Tech Stack

AWSCloudCyber SecuritySaltStackSDLCSpring

About the role

  • Conduct security reviews and static code analysis to identify application vulnerabilities
  • Integrate SAST, DAST, and SCA tools into CI/CD pipelines
  • Collaborate with developers to remediate vulnerabilities and promote secure coding practices
  • Generate and present risk-based security reports to engineering and management teams
  • Maintain security tooling configurations and ensure up-to-date signatures and policies
  • Support secure development and implementation of applications

Requirements

  • Must have an active NOAA Public Trust clearance or active Secret security clearance
  • US Citizenship Required
  • 5+ years of experience in application security or a related field
  • Identify, analyze, and mitigate application security vulnerabilities using tools like Checkmarx, Invicti, Black Duck, etc.
  • Collaborate with development teams to integrate secure coding practices and prioritize vulnerability remediation throughout the SDLC
  • Maintain container images supporting different automated CI/CD security scanning phases
  • Hands-on experience with static and dynamic application security testing (SAST/DAST)
  • Familiarity with tools such as Invicti, Checkmarx, Black Duck, and similar platforms
  • Strong understanding of secure coding practices and application vulnerabilities (e.g., OWASP Top 10)
  • Experience working within a Cloud Environment required (AWS experience preferred)
  • Experience with CI/CD tools and pipelines, integrating security throughout the SDLC
  • Ability to interpret and explain security findings to developers and provide remediation guidance
  • Excellent communication skills and strong documentation ability
  • Possess at least ONE (1) of the following professional certifications: CompTIA Security+; CEH; CISSP