Applications Security Solutions Engineer
Job description
Application Security Engineer (Contract-to-Hire, Hybrid)
Our client, a leading financial institution, is seeking an experienced Application Security Engineer for a 6-month contract-to-hire opportunity in the Columbus, OH market. This role follows a hybrid schedule with four days onsite and one day remote each week. The ideal candidate will play a key role in securing internally developed, acquired, and third-party applications while partnering closely with development, DevOps, risk management, and information security teams.
Key Responsibilities - Perform and support application security testing, including SAST, DAST, and SCA.
- Review, validate, and track remediation of identified vulnerabilities.
- Conduct and support application penetration testing, including oversight of remediation efforts and reporting of metrics.
- Coordinate internal and third-party penetration tests; review findings and contribute to remediation planning.
- Mentor development teams on secure coding practices and embed security throughout the SDLC.
- Provide threat modeling support and secure design guidance.
- Assist in securing AI-enabled applications, including evaluating data and model risks.
- Review application architectures for security vulnerabilities and compliance risks.
- Support audits and ensure adherence to regulatory requirements.
- Maintain and enhance application security standards and best practices.
Additional Responsibilities - Ensure compliance with organizational policies, procedures, and federal/state regulations.
- Utilize Microsoft Office and relevant tools to improve workflow efficiency.
- Collaborate effectively within a team environment.
- Work with on-site systems and equipment as required.
Qualifications - High School Diploma or equivalent required.
- 5–6 years of experience in application security.
- 5–6 years of experience within the financial services industry.
- 5–6 years of hands-on or supporting experience with penetration testing.
Certifications - CSSLP, GWAPT, or OSCP (required upon hire).
- CompTIA Security+ or CISSP (required upon hire).
Additional Requirements - This role is not open to C2C, third-party vendors, visa sponsorship, or student EAD candidates.
first seen 2026-07-24 08:40:01 · last verified 2026-07-24 08:40:01
pentestcareers.com // breach the job market