Open Role
GuidePoint Security

Remote opportunity at

GuidePoint Security

Application Security Engineer - North Central region

GuidePoint Security is looking for an Application Security Engineer to join its North Central regional team on a remote basis. Founded in 2011, the expanding firm…

View Company

Role Snapshot

Hiring Now

Remote from

Remote

Salary

Undisclosed

Department

General

Employment

Full-time

Experience

Not specified

Published3h ago
Listing Views1
Applications0
Apply BeforeNo deadline

Career Tools

About This Role

GuidePoint Security is looking for an Application Security Engineer to join its North Central regional team on a remote basis. Founded in 2011, the expanding firm currently employs over 1,300 professionals and provides specialized cybersecurity solutions and risk management expertise to Fortune 500 corporations, United States government agencies, and more than 6,200 total customers. In this position, you will support the firm's Application Security practice by helping clients establish and…

Job Description

GuidePoint Security is looking for an Application Security Engineer to join its North Central regional team on a remote basis. Founded in 2011, the expanding firm currently employs over 1,300 professionals and provides specialized cybersecurity solutions and risk management expertise to Fortune 500 corporations, United States government agencies, and more than 6,200 total customers.

In this position, you will support the firm's Application Security practice by helping clients establish and expand secure software development programs, integrate DevSecOps automation, and secure AI-enabled or agentic applications. Your day-to-day duties will involve managing security scanning technologies, embedding automated security checks into continuous integration and deployment pipelines, conducting threat modeling, and advising development teams on secure coding principles and remediation procedures.

This role is well-suited for professionals possessing early-career application security or software development experience who want to collaborate with skilled cybersecurity mentors and advance their careers within a growing organization. The position requires up to 10% travel and involves sedentary desk work with extended computer terminal usage. Employees working at GuidePoint benefit from a remote work model along with comprehensive health insurance plans, flexible time off, corporate holidays, retirement savings eligibility, stipends for mobile phones and home internet, and pet benefits.

Responsibilities

  • Operate and configure client static, dynamic, software composition analysis, secrets, and infrastructure-as-code scanning systems while eliminating false positives and delivering remediation advice
  • Integrate security tools and policy enforcement gates into continuous integration and deployment platforms, source control systems, integrated development environments, and ticketing software
  • Collaborate directly with software development groups to provide secure coding instructions, developer enablement, and vulnerability remediation guidance across the software development lifecycle
  • Evaluate and improve software supply chain defenses, including software bill of materials generation, dependency and container scanning, and artifact signing
  • Execute threat modeling and security architecture evaluations for cloud-native setups, microservices, container systems, and infrastructure-as-code environments
  • Utilize artificial intelligence and agentic tools to accelerate testing workflows and guide clients toward the secure adoption of AI coding assistants
  • Assist clients in maturing application security programs through metrics definitions, service level agreements, and alignment with frameworks like OWASP SAMM, BSIMM, and NIST SSDF
  • Draft clear client deliverables, present technical and executive findings, and contribute to practice development through new methodologies and knowledge sharing

Requirements

  • One to three or more years of professional experience in application security, DevSecOps, or software engineering with a security focus
  • Hands-on experience working with static, dynamic, and software composition analysis tools and embedding them into continuous integration and delivery pipelines
  • Familiarity with manual testing software such as Burp Suite Pro alongside a solid understanding of the OWASP Top 10 and OWASP API Security Top 10
  • Practical knowledge of secure development lifecycles and experience managing the remediation of vulnerabilities found by security tools
  • Ability to read and review source code written in languages such as JavaScript, TypeScript, Python, Java, C#, Go, PHP, or C/C++
  • Working familiarity with cloud computing environments, containers, and Git-based development workflows
  • Strong verbal and written communication capabilities capable of breaking down complex technical problems for both technical and executive stakeholders

Qualifications

  • Familiarity with Invicti for dynamic testing and Checkmarx for static or software composition analysis, plus additional platforms like Snyk, Veracode, Black Duck, Semgrep, or GitHub Advanced Security
  • Background in building agentic artificial intelligence workflows or automation scripts using Python, Bash, or PowerShell to scale testing and triage
  • Experience with software supply chain security standards including software bill of materials, SLSA, and Sigstore
  • Knowledge of infrastructure-as-code and container security scanners such as Checkov, Trivy, and Wiz
  • Familiarity with threat modeling structures like STRIDE and application security maturity models including OWASP SAMM, BSIMM, or NIST SSDF
  • Industry credentials such as GWAPT, OSWE, OSCP, CSSLP, Certified DevSecOps Professional, or AWS Certified Security Specialist
  • A bachelor degree in Computer Science, Information Security, or an aligned subject area, or equivalent practical experience

Core Skills

Benefits

  • Remote workforce model for United States based employees
  • Group Medical Insurance options including a zero deductible PPO plan or a high deductible health plan with health savings account contributions
  • Group Dental Insurance with employer premium coverage
  • Twelve corporate holidays and a Flexible Time Off program
  • Healthy mobile phone and home internet allowance
  • Eligibility to participate in the retirement plan after two months at open enrollment
  • Pet benefit option

Frequently Asked Questions

Is this position remote?

Yes, this is a remote role for U.S.-based workers, though up to 10% travel is required.

What level of experience is required for this role?

The posting requires 1-3 or more years of experience in Application Security, DevSecOps, or software development with a security focus.

What is the salary for this position?

The job posting does not specify the salary.

How can I apply for this job?

The employer uses Greenhouse Software for applicant tracking and Zoom Scheduler for interview scheduling.

Sample Interview Questions

AI-generated questions tailored to this specific role — a preview of the full practice set.

Search similar jobs

Related Jobs

Advertisement
320 × 50

Posted by GuidePoint Security

Source: Remote First Jobs — HR

2 sources detected for this job

GuidePoint Security

GuidePoint Security

7Open Jobs
—No reviews yet
View Company Profile