GuidePoint Security
Application Security Engineer - Northeast region
About this role
GuidePoint Security seeks an Application Security Engineer to implement and operationalize SAST tools, integrate security testing into CI/CD pipelines, and advance secure development practices for Fortune 500 and government clients across the Northeast region.
What you'll do
- Deploy, configure, and troubleshoot SAST platforms like Semgrep, CodeQL, Checkmarx, and Veracode in client environments
- Design and integrate automated security testing into CI/CD pipelines across multiple platforms
- Author, customize, and maintain SAST detection rules; triage vulnerabilities and guide remediation efforts
- Advise development teams on OWASP Top 10, threat modeling, and secure coding practices
- Build reusable pipeline patterns, rule libraries, and delivery accelerators for the AppSec practice
- Support client engagements across Northeast/Mid-Atlantic region with occasional on-site visits
What they're looking for
- SAST tool implementation (Semgrep, CodeQL, Checkmarx, Veracode, Snyk)
- CI/CD pipeline integration (GitHub Actions, GitLab, Azure DevOps, Jenkins, CircleCI)
- Custom rule writing and vulnerability triage
- Software engineering and full-stack development
- Scripting and automation with multiple programming languages
- OWASP Top 10 and threat modeling
- Application security fundamentals and SDLC practices
- AI-assisted tools for security automation
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
GuidePoint Security
GuidePoint Security builds and deploys security infrastructure and automation solutions for federal government, intelligence community, and enterprise clients. The company is hiring for specialized security engineering roles including cloud security architects, network security engineers, Linux automation specialists, and security operations professionals with expertise in platforms like Splunk, Zscaler, and firewall technologies.
View all jobs at GuidePoint SecurityLikely interview questions
- Walk us through your experience implementing and operationalizing a SAST tool in a production environment—what challenges did you encounter and how did you resolve them?
- Describe your approach to integrating security testing into a CI/CD pipeline while minimizing false positives and developer friction.