Summary
CivicPlus is a company focused on serving local governments and the residents they support through innovative software and collaboration. The Application Security Engineer will embed security throughout the software development lifecycle by leading application security testing, reviewing designs and code, identifying vulnerabilities, and coordinating remediation and penetration testing.
Responsibilities
- Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC)
- Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC
- Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements
- Coordinate external, independent penetration testing of production environments
- Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST)
- Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats
Skills
- Applicants must be authorized to work in the US
- 3–7 years of experience in application security, secure development, penetration testing, or a related field
- Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST)
- Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations
- Security+, GSEC, GSSP, or equivalent certification
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred)
- Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments
- AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality
- Demonstrated ability to effectively use AI tools to enhance productivity and outcomes
Qualifications
Must Haves
- Applicants must be authorized to work in the US
Nice to Haves
- 3–7 years of experience in application security, secure development, penetration testing, or a related field
- Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST)
- Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations
- Security+, GSEC, GSSP, or equivalent certification
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred)
- Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments
- AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality
- Demonstrated ability to effectively use AI tools to enhance productivity and outcomes
Benefits
- Comprehensive health insurance
- Dental insurance
- Vision insurance
- Flexible Time Off
- 401(k) plan