Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Auditor

Xcelo Group

Hi,

We are having urgent requirement for the below mentioned role:

Job Title: IT Secuity Auditor (Senior Application Security Auditor / DevSecOps Security Engineer)
Work Location: Dimondale, MI – (Hybrid)
Work Auth: All visas accepted (No h1 and No Fake profiles)

Candidate Location Requirement

  • Candidates must currently be located within approximately 90–100 miles of Dimondale, MI at the time of submission.

  • Must be available for an in-person interview .

Experience Required

  • 7+ years of overall IT / Application Security experience preferred

  • Minimum 5+ years of total IT experience

  • At least 3+ years of hands-on Application Security, Secure Coding, and DevSecOps experience

Job Summary

We are seeking a highly experienced Senior Application Security Auditor with strong expertise in application security testing, secure software development, DevSecOps, API security, vulnerability assessment, and secure coding practices .

This is not a traditional SOC-focused role. The position will work directly with software engineering teams to identify and remediate security vulnerabilities across front-end, back-end, API, cloud, containerized, and distributed applications .

The ideal candidate should have hands-on experience with SAST, DAST, SCA, ASOC, API security, OWASP vulnerabilities, secure coding frameworks, and security automation .

Required Skills

  • Hands-on experience with Application Security scanning tools , including:

    • SAST

    • DAST

    • SCA

    • ASOC

    • Container Security

    • Cloud Security

  • Strong understanding of request/response headers for web applications and REST APIs.

  • Deep understanding of the OWASP Top 10 , including the ability to explain vulnerabilities, attack vectors, and remediation approaches.

  • Experience identifying and mitigating vulnerabilities such as:

    • Cross-Site Scripting (XSS)

    • Injection attacks

    • Server-Side Request Forgery (SSRF)

    • Cross-Site Request Forgery (CSRF)

    • XML External Entity (XXE)

    • Authentication and authorization vulnerabilities

    • API security vulnerabilities

  • Experience implementing secure coding standards and security guidance including:

    • OWASP Top 10

    • SANS

    • CERT Secure Coding

    • CWE Top 25

    • CIS Critical Security Controls

    • Cloud Security Alliance

    • SAFECode

  • Strong understanding of secure software development practices across technologies such as:

    • Angular

    • React

    • Node.js

    • Java

    • Spring Boot

    • IBM WebSphere Application Server

    • Oracle

    • JBoss

    • .NET

  • Experience with both compiled and interpreted programming environments .

  • Experience with:

    • Secure application development

    • Networking infrastructure

    • Security automation

    • DevSecOps

    • Secure SDLC

  • Hands-on experience designing, developing, assessing, or securing distributed web and mobile applications .

  • Ability to use browser developer tools such as Chrome, Firefox, and Microsoft Edge DevTools to analyze requests, responses, headers, cookies, and application behavior.

Preferred Skills

  • Experience with security tools such as:

    • Coverity

    • Black Duck

    • Fortify

    • SRM

  • Strong knowledge of API Security .

  • Experience with:

    • JWT

    • OAuth 2.0

    • OpenID Connect (OIDC)

    • PKCE

    • API replay attack prevention

  • Understanding of container technologies and container security.

  • Cloud development or security experience with:

    • Microsoft Azure

    • AWS

    • Google Cloud Platform (GCP)

Key Responsibilities

  • Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) across enterprise applications.

  • Conduct security assessments of web, mobile, API, cloud, and distributed applications.

  • Work closely with development teams to identify vulnerabilities and recommend secure coding remediation strategies.

  • Review application architecture, code, APIs, authentication, authorization, and data flows from a security perspective.

  • Guide developers on secure coding standards, OWASP vulnerabilities, threat mitigation, and secure SDLC practices .

  • Partner with front-end, back-end, API, cloud, and platform engineering teams to integrate security throughout the software development lifecycle.

  • Implement and promote reusable application security patterns and secure development practices .

  • Integrate security scanning and validation into DevSecOps and CI/CD pipelines .

  • Automate secure configuration validation, compliance checks, application security testing, and authorization processes.

  • Evaluate REST APIs for authentication, authorization, token management, JWT, OAuth/OIDC, replay attacks, and common API vulnerabilities.

  • Analyze requests and responses to identify security weaknesses.

  • Help mature the organization's Secure Software Development Lifecycle (SSDLC) .

  • Support continuous compliance and application risk mitigation initiatives.

  • Collaborate with distributed engineering teams to improve how applications are designed, developed, secured, deployed, and operated.

  • Provide technical guidance on vulnerability remediation and security best practices.

Key Skills

Application Security | SAST | DAST | SCA | ASOC | DevSecOps | OWASP Top 10 | API Security | Secure Coding | Fortify | Coverity | Black Duck | JWT | OAuth | OIDC | PKCE | XSS | SSRF | CSRF | XXE | Java | Spring Boot | Angular | React | Node.js | .NET | WebSphere | JBoss | REST API Security | Cloud Security | AWS | Azure | GCP | Secure SDLC

Vacancy posted 9 days ago
Similar jobs that could be interesting for youBased on the IT Security Auditor in Dimondale, MI vacancy
  •  ...Security Comments : Position Description : Please ensure you attach the Cover Sheet (attached), valid Right to Represent...  .... This is REQUIRED. The State of Michigan is looking for an IT Security Auditor Max Bill : NA - Will close submissions on: 9/14/ at 10am EST... 
    Suggested
    Work at office
    Local area
    Remote work
    2 days per week
    1 day per week

    RICEFW Technologies Inc

    Dimondale, MI
    2 days ago
  •  ...States Job Description Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure...  ...level understanding of containers Requirements 5+ years: Total IT related experience. 3+ years: Implementing/utilizing Federal... 
    Suggested
    Local area
    Remote work
    2 days per week
    1 day per week

    Zenfreed, LLC

    Dimondale, MI
    2 days ago
  •  ...candidates must be direct W-2 employees of your company; layered subcontractors are not accepted. ***Only qualified IT Security Auditor candidates located near the Dimondale MI area to be considered due to the position requiring an onsite presence*** REQUIRED... 
    Suggested
    For subcontractor
    Local area

    UniQtal Solutions LLC

    Dimondale, MI
    6 days ago
  •  ...Hi, We are having urgent requirement for the below mentioned role: Job Title: IT Secuity Auditor (Senior Application Security Auditor / DevSecOps Security Engineer) Work Location: Dimondale, MI – (Hybrid) Work Auth: All visas accepted (No h1 and No Fake profiles... 
    Suggested
    Work visa

    Xcelo Group

    Dimondale, MI
    10 days ago
  •  ...Job Summary for IT Security Auditor (Dimondale, MI) - Serve as a Senior Full Stack Application Development Security Auditor focused on secure platform and application design. - Conduct Dynamic, Static, and Software Composition Analysis (DAST, SAST, SCA) assessments... 
    Suggested
    Local area
    2 days per week

    Shree Narayani Networking Solutions Pvt Ltd

    Dimondale, MI
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Auditor. Be the first to apply!