Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Auditor

Xcelo Group

Hi,

We are having urgent requirement for the below mentioned role:

Job Title: IT Secuity Auditor (Senior Application Security Auditor / DevSecOps Security Engineer)
Work Location: Dimondale, MI – (Hybrid)
Work Auth: All visas accepted (No h1 and No Fake profiles)

Candidate Location Requirement

  • Candidates must currently be located within approximately 90–100 miles of Dimondale, MI at the time of submission.

  • Must be available for an in-person interview .

Experience Required

  • 7+ years of overall IT / Application Security experience preferred

  • Minimum 5+ years of total IT experience

  • At least 3+ years of hands-on Application Security, Secure Coding, and DevSecOps experience

Job Summary

We are seeking a highly experienced Senior Application Security Auditor with strong expertise in application security testing, secure software development, DevSecOps, API security, vulnerability assessment, and secure coding practices .

This is not a traditional SOC-focused role. The position will work directly with software engineering teams to identify and remediate security vulnerabilities across front-end, back-end, API, cloud, containerized, and distributed applications .

The ideal candidate should have hands-on experience with SAST, DAST, SCA, ASOC, API security, OWASP vulnerabilities, secure coding frameworks, and security automation .

Required Skills

  • Hands-on experience with Application Security scanning tools , including:

    • SAST

    • DAST

    • SCA

    • ASOC

    • Container Security

    • Cloud Security

  • Strong understanding of request/response headers for web applications and REST APIs.

  • Deep understanding of the OWASP Top 10 , including the ability to explain vulnerabilities, attack vectors, and remediation approaches.

  • Experience identifying and mitigating vulnerabilities such as:

    • Cross-Site Scripting (XSS)

    • Injection attacks

    • Server-Side Request Forgery (SSRF)

    • Cross-Site Request Forgery (CSRF)

    • XML External Entity (XXE)

    • Authentication and authorization vulnerabilities

    • API security vulnerabilities

  • Experience implementing secure coding standards and security guidance including:

    • OWASP Top 10

    • SANS

    • CERT Secure Coding

    • CWE Top 25

    • CIS Critical Security Controls

    • Cloud Security Alliance

    • SAFECode

  • Strong understanding of secure software development practices across technologies such as:

    • Angular

    • React

    • Node.js

    • Java

    • Spring Boot

    • IBM WebSphere Application Server

    • Oracle

    • JBoss

    • .NET

  • Experience with both compiled and interpreted programming environments .

  • Experience with:

    • Secure application development

    • Networking infrastructure

    • Security automation

    • DevSecOps

    • Secure SDLC

  • Hands-on experience designing, developing, assessing, or securing distributed web and mobile applications .

  • Ability to use browser developer tools such as Chrome, Firefox, and Microsoft Edge DevTools to analyze requests, responses, headers, cookies, and application behavior.

Preferred Skills

  • Experience with security tools such as:

    • Coverity

    • Black Duck

    • Fortify

    • SRM

  • Strong knowledge of API Security .

  • Experience with:

    • JWT

    • OAuth 2.0

    • OpenID Connect (OIDC)

    • PKCE

    • API replay attack prevention

  • Understanding of container technologies and container security.

  • Cloud development or security experience with:

    • Microsoft Azure

    • AWS

    • Google Cloud Platform (GCP)

Key Responsibilities

  • Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) across enterprise applications.

  • Conduct security assessments of web, mobile, API, cloud, and distributed applications.

  • Work closely with development teams to identify vulnerabilities and recommend secure coding remediation strategies.

  • Review application architecture, code, APIs, authentication, authorization, and data flows from a security perspective.

  • Guide developers on secure coding standards, OWASP vulnerabilities, threat mitigation, and secure SDLC practices .

  • Partner with front-end, back-end, API, cloud, and platform engineering teams to integrate security throughout the software development lifecycle.

  • Implement and promote reusable application security patterns and secure development practices .

  • Integrate security scanning and validation into DevSecOps and CI/CD pipelines .

  • Automate secure configuration validation, compliance checks, application security testing, and authorization processes.

  • Evaluate REST APIs for authentication, authorization, token management, JWT, OAuth/OIDC, replay attacks, and common API vulnerabilities.

  • Analyze requests and responses to identify security weaknesses.

  • Help mature the organization's Secure Software Development Lifecycle (SSDLC) .

  • Support continuous compliance and application risk mitigation initiatives.

  • Collaborate with distributed engineering teams to improve how applications are designed, developed, secured, deployed, and operated.

  • Provide technical guidance on vulnerability remediation and security best practices.

Key Skills

Application Security | SAST | DAST | SCA | ASOC | DevSecOps | OWASP Top 10 | API Security | Secure Coding | Fortify | Coverity | Black Duck | JWT | OAuth | OIDC | PKCE | XSS | SSRF | CSRF | XXE | Java | Spring Boot | Angular | React | Node.js | .NET | WebSphere | JBoss | REST API Security | Cloud Security | AWS | Azure | GCP | Secure SDLC

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Security Auditor in Dimondale, MI vacancy
  •  ...Senior Full Stack Security Auditor Senior Full Stack Security Auditor who is passionate about designing and building secure platforms and applications through dynamic, static and software composition analysis assessments. This position is not a member of the security... 
    Suggested

    Samprasoft

    Dimondale, MI
    2 days ago
  •  ...IT Security Auditor We are from US IT Solutions, an ISO Certified, E-Verify, WMBE Certified organization established in 2005 in CA. Our company is serving various State, Local and County Departments for over 10 years. USITSOL has been helping clients innovate across... 
    Suggested
    Local area

    US IT Solutions Inc

    Lansing, MI
    4 days ago
  •  ...Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications...  ...Requirements Minimum Qualifications: ~5+ years of total IT-related experience ~3+ years implementing/utilizing Federal,... 
    Suggested
    Local area

    Stafford Gray

    Lansing, MI
    7 hours ago
  •  ...Job Description Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms...  ...experience (Azure, AW Requirements 5+ years: ~ Total IT related experience. 3+ years: Implementing/utilizing... 
    Suggested
    Local area
    Remote work
    Monday to Friday
    2 days per week
    1 day per week

    Zenfreed, LLC

    Dimondale, MI
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Auditor. Be the first to apply!