Applications Security Solutions Engineer

Vaco by Highspring·Warren·Posted 2h ago·via Dice

RegionUSA
Apply Now

Job description

Application Security Engineer (Contract-to-Hire, Hybrid)

Our client, a leading financial institution, is seeking an experienced Application Security Engineer for a 6-month contract-to-hire opportunity in the Columbus, OH market. This role follows a hybrid schedule with four days onsite and one day remote each week. The ideal candidate will play a key role in securing internally developed, acquired, and third-party applications while partnering closely with development, DevOps, risk management, and information security teams.

Key Responsibilities - Perform and support application security testing, including SAST, DAST, and SCA.

  • Review, validate, and track remediation of identified vulnerabilities.
  • Conduct and support application penetration testing, including oversight of remediation efforts and reporting of metrics.
  • Coordinate internal and third-party penetration tests; review findings and contribute to remediation planning.
  • Mentor development teams on secure coding practices and embed security throughout the SDLC.
  • Provide threat modeling support and secure design guidance.
  • Assist in securing AI-enabled applications, including evaluating data and model risks.
  • Review application architectures for security vulnerabilities and compliance risks.
  • Support audits and ensure adherence to regulatory requirements.
  • Maintain and enhance application security standards and best practices.

Additional Responsibilities - Ensure compliance with organizational policies, procedures, and federal/state regulations.

  • Utilize Microsoft Office and relevant tools to improve workflow efficiency.
  • Collaborate effectively within a team environment.
  • Work with on-site systems and equipment as required.

Qualifications - High School Diploma or equivalent required.

  • 5–6 years of experience in application security.
  • 5–6 years of experience within the financial services industry.
  • 5–6 years of hands-on or supporting experience with penetration testing.

Certifications - CSSLP, GWAPT, or OSCP (required upon hire).

  • CompTIA Security+ or CISSP (required upon hire).

Additional Requirements - This role is not open to C2C, third-party vendors, visa sponsorship, or student EAD candidates.

first seen 2026-07-24 08:40:01 · last verified 2026-07-24 08:40:01


pentestcareers.com // breach the job market