Application Security Remediation Engineer
Company Overview
Position Overview
Responsibilities
- Analyze and remediate application-level vulnerabilitiesidentifiedby Wiz.
- Resolve code vulnerabilities within .NET, Java, PHP, Go, and Node.js applications.
- Upgrade vulnerable libraries, frameworks, packages, and third-party dependencies.
- Perform compatibility and regression testing for upgraded software components.
- Remediate container image vulnerabilities and insecure build configurations.
- Modernize and rebuild affected images tocomply withorganizational security standards.
- Work with development teams to incorporate secure coding practices.
- Address insecure configurations within application runtimes and frameworks.
- Validate completed remediations and ensure findings are accurately resolved within Wiz.
- Design and document reusable remediation patterns for recurring vulnerability classes.
- Support secure software delivery throughDevSecOpsand CI/CD integration.
- Collaborate with SRE, cloud, platform, and security teams throughout remediation activities.
Qualifications
- Strong software engineering experience in one or more of .NET/C#, Java, Go, PHP, or Node.js.
- Experience working with enterprise-scale application environments.
- Experience remediating application vulnerabilities and applying secure coding practices.
- Strong understanding of OWASP Top 10 vulnerabilities and softwaresupply-chainsecurity.
- Experience upgrading third-party libraries, frameworks, packages, and application dependencies.
- Docker and container image remediation experience.
- Kubernetes application deployment and container security experience.
- Experience with SQL Server and/or MySQL, including application-to-database security fundamentals.
- CI/CD pipeline integration, Git-based workflows, and Secure Software Development Lifecycle practices.
- Experience with automated security testing, SAST, SCA, and dependency-management tooling.
- Experience with vulnerability management programs and prioritization of Critical and High findings.
- Experience using Wiz,Snyk, Veracode,Checkmarx, SonarQube, or similar tools.
- Strong debugging, analytical, root-cause investigation, documentation, and communication skills.
Preferred Qualifications
- Hands-on Wiz experience.
- Experience securing containerizedmicroservicesarchitectures.
- Cloud-native application development experience.
- Experience with Amazon EKS and Kubernetes.
- Secure coding orapplication-securitycertifications.
- Experience in healthcare, payments, or other regulated industries.
Tools and Technologies
- Wiz
- .NET / C#
- Java
- PHP
- Go
- Node.js
- SQL Server
- MySQL
- Docker
- Kubernetes
- Amazon EKS
- Git
- GitHub / GitLab
- CI/CD platforms
- Dependency scanning tools
- SAST / SCA platforms
- OWASP tooling
- DevSecOpstoolchains
Arctiq is an equal opportunity employer. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know. We celebrate our inclusive work environment and welcome members of all backgrounds and perspectives to apply. We thank you for your interest in joining the Arctiq team! While we welcome all applicants, only those who are selected for an interview will be contacted. Originally posted on Himalayas
Not included in the source posting: benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.