
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Role
Summary
We
are looking for an Application Security Engineer to support Static and Dynamic
Application Security Testing (SAST/DAST) scan and triage activities, while also
providing hands-on outage support for the security tooling ecosystem —
including AppScan, Checkmarx, Cycode, and GCP Model Armor. This role combines
day-to-day vulnerability triage and remediation guidance with structured,
SOP-driven incident response when scanning tools are degraded or unavailable,
including support during scheduled patching windows and off-business-hours
coverage.
Key
Responsibilities
SAST & DAST Testing and
Triage
•
Perform and support
Static (SAST) and Dynamic (DAST) application security testing across in-scope
applications.
•
Triage scan findings
across SAST, DAST, SaaS, Secrets, and API security scan results, distinguishing
false positives from confirmed vulnerabilities.
•
Provide developers with
clear, actionable remediation guidance for validated vulnerabilities.
•
Support application
onboarding into scan tooling and manage Penalty-Box exception handling and
unblock decisions.
•
Provide security support
during production release ACAB reviews and Breakglass approvals.
•
Create, validate, and
drive Vulnerability Information Tracker (VIT) and defect records through to
closure.
AppScan & Checkmarx
Windows Server Patching Outage Support
•
Provide support during
scheduled monthly Windows Server patching windows to ensure AppScan and
Checkmarx remain available and operational after server restarts.
•
Validate application
access for AppScan and Checkmarx following patching.
•
Use RDP to connect to
in-scope management servers for troubleshooting.
•
Check IIS Manager to
confirm required application pools are in Started status; verify all required
HCL AppScan and Cx services are in Running status.
•
Start any stopped
services or application pools; reboot the AppScan management server when
required for database-related errors.
•
Revalidate application
login pages after restart and escalate unresolved issues via email or Microsoft
Teams.
Cycode Tool Outage Support
•
Support Cycode-related
issues, primarily stuck or delayed pull requests during the secret-scanning
process.
•
Review incident details
and validate pull request scan history in Cycode; check for missing or delayed
pull requests.
•
Coordinate with the E3
team to verify Azure DevOps webhooks and recent ADO changes, and confirm branch
policy settings.
•
Validate whether an
actual secret is blocking the pull request and raise a vendor support ticket
with Cycode when required.
•
Coordinate unresolved
issues with the appropriate internal teams and Cycode Support until resolution.
GCP Model Armor Support
•
Provide
off-business-hours support for managing Google Cloud Model Armor
configurations.
•
Enable or disable Model
Armor for required projects and switch configurations between Inspect Only mode
and Inspect and Block mode.
•
Update the necessary
Terraform configuration, create pull requests, coordinate approvals, and
trigger pipeline deployments.
•
Approve Terraform runs
in accordance with the SOP, coordinating with reviewers and approvers as
needed.
Required
Skills & Experience
•
Hands-on experience with
SAST and DAST tools and processes (e.g., Checkmarx, HCL AppScan, or
equivalent), including scan triage and false-positive analysis.
•
Basic Windows Server
support knowledge, with experience using RDP for remote troubleshooting.
•
Working knowledge of IIS
Manager and Windows Services, including starting/stopping services and
application pools.
•
Basic knowledge of
Cycode or similar secret-scanning tools, Azure DevOps, pull request workflows,
webhooks/service hooks, and branch policies.
•
Basic knowledge of
Google Cloud Platform (GCP), Terraform, Git repositories, pull request
processes, pipeline deployments, and HCP Terraform workspace approvals.
•
Experience with incident
handling, vendor coordination, and SOP-based outage support procedures.
•
Strong written and
verbal communication skills, including the ability to escalate and coordinate
via email and Microsoft Teams.
•
Willingness to support
scheduled patching windows and off-business-hours / on-call activities as
needed.
Preferred
Qualifications
•
Prior experience in an
Application Security Testing (AST), DevSecOps, or security operations support
role.
•
Familiarity with
vulnerability management workflows (VIT/defect lifecycle: creation, validation,
closure).
•
Exposure to CI/CD
pipelines and infrastructure-as-code approval workflows.
•
Relevant certifications
(e.g., Security+, GCP Associate/Professional, or vendor-specific tool
certifications) are a plus.
Soft
Skills
•
Strong attention to
detail when following SOP-based procedures under time pressure.
•
Clear, calm
communication during live outage or incident scenarios.
•
Ability to work
independently during off-hours support windows while knowing when to escalate.

Successful companies gain back 30% of their budget & time each year. How?
They partner with Alignity to solve their challenges in
- Digital Transformation
- Employer Branding & Hiring
- Performance Innovation
See others share their specific benefits by partnering with us:
Clients: https://alignity.io/talent-acquisition/#WhyClientsTrustUs
Employees: https://alignity.io/candidate-services/#WhyEmployeesLoveUs
Connect with us if you are looking for Outsourcing, Staffing solutions in below niches
- Cloud/Data
- Cybersecurity
- AI/ML
- Fullstack
- Agile
- SAP