Security Engineer
AttainXAbout the role
Job Title: Security Engineer
Location: Must reside within a commutable distance of Asheville, NC, or Boulder, CO to work onsite as required. Hybrid/onsite
Clearance: Must have an active NOAA Public Trust clearance or active Secret security clearance.
Citizenship: US Citizenship Required
Position Type: Full Time/Exempt
Salary Range: US market data minimum $115,000.00 - $145,000.00 maximum wage range. You will receive a competitive total rewards package that is applicable to the U.S. only. The salary range may vary based on experience, skillset, and geographical location.
AttainX, Inc. is seeking a detail-oriented and highly skilled Application Security Analyst to join our federal cybersecurity team. The ideal candidate will have hands-on experience integrating security tools in CI/CD pipelines and identifying vulnerabilities in web applications through both manual testing and automated analysis tools.
Qualifications and Education Requirements:
Basic Minimum Qualifications:
- 5+ years of experience in application security or a related field.
- Identify, analyze, and mitigate application security vulnerabilities using tools like Checkmarx, Invicti, Black Duck, etc.
- Collaborate with development teams to integrate secure coding practices and prioritize vulnerability remediation throughout the SDLC.
- Maintain container images supporting different automated CI/CD security scanning phases.
- Hands-on experience with static and dynamic application security testing (SAST/DAST).
- Familiarity with tools such as Invicti, Checkmarx, Black Duck, and similar platforms.
- Strong understanding of secure coding practices and application vulnerabilities (e.g., OWASP Top 10).
- Experience working within a Cloud Environment required. (AWS experience preferred)
- Experience with CI/CD tools and pipelines, integrating security throughout the software development lifecycle (SDLC).
- Ability to interpret and explain security findings to developers and provide remediation guidance.
- Excellent communication skills and strong documentation ability.
- Possess at least ONE (1) of the following professional certifications:
- CompTIA Security+
- Electronic Commerce Council Certified Ethical Hacker (CEH)
- Certified Information Systems Security Professional (CISSP)
Preferred Qualifications:
- Experience working in Agile development environments with DevSecOps practices.
- Experience supporting application security for federal agencies.
Education / Experience:
5+ years of relevant experience in application security, software development, or DevSecOps.
Skills:
Application Security, Static & Dynamic Analysis, CI/CD Integration, OWASP Top 10,
Security Tooling: Invicti, Checkmarx, Black Duck, GitLab CI/CD
Duties:
We are searching for an Application Security Analyst to support secure development and implementation of applications. Duties include:
- Conduct security reviews and static code analysis to identify application vulnerabilities.
- Integrate SAST, DAST, and SCA tools into CI/CD pipelines.
- Collaborate with developers to remediate vulnerabilities and promote secure coding practices.
- Generate and present risk-based security reports to engineering and management teams.
- Maintain security tooling configurations and ensure up-to-date signatures and policies.
Non-Essential Functions:
- General Duty Requirements
About Us:
AttainX Inc. is SBA Certified 8(a), Women Owned Small Business (WOSB), Economically Disadvantaged WOSB (EDWOSB), CMMI Level 3, ISO 9001:2015 certified QMS and Silver Level SaFe Partner. For more than 12 years, AttainX, Inc. has delivered emergent technologies, software products
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s