Application Security (AppSec) / DevSecOps Engineer
FyerXMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessRemote mid-level role attracts broad applicant pools, though AppSec specialization and certifications moderate competition.
AppSec certifications and SDLC focus increase domain specificity, but skills remain transferable across industries.
Explicit years, mandatory AppSec certifications, and specific tooling requirements enforce strict shortlisting.
Job Description
Structured overview of role & requirementsAbout This Role
Design and integrate automated security testing gates into CI/CD pipelines using tools like GitHub Actions and Jenkins.
Lead threat modeling workshops and govern application security infrastructure including vulnerability dashboards and secret vaults.
Secure containerized application workloads and drive application layer incident investigations to identify and mitigate software vulnerabilities before production.
Minimum Requirements
4 to 8 years of core software engineering or cloud DevOps experience with 3+ years dedicated to application security/DevSecOps frameworks.
Mandatory certification: Certified Application Security Engineer (CASE), Certified DevSecOps Professional (CDP), CSSLP, or CEH.
Strong experience with automated security testing tools (e.g., Snyk, Checkmarx, Veracode, OWASP ZAP).
Knowledge of container security, OWASP Top 10 vulnerabilities, API security, and secure coding standards.
Ideal Candidate Profile
Experienced in designing and deploying DevSecOps pipelines integrating automated security testing within CI/CD environments.
Skilled in managing application security infrastructure and leading threat modeling for modern application architectures.
Familiar with container security best practices and proactive incident investigation of application layer threats.
