TalentBurst · murray, Utah, US

Application Security Engineer

OpenContract50.00 - 60.00

Open — TalentBurst has a posting for this job. Posted 30 Sep 2026.

This posting

Posted 30 Sep 2026 · Contract · 50.00 - 60.00

Apply on the employer's site

Opens www1.jobdiva.com. Talentify has not checked who owns that address. You apply there — Talentify never asks for an account or a CV.

About this job

Job Title: Application Security Engineer
Location: Remote
Contract: 3-Month Contract

This is a 3-Month, fully remote contract role supporting a focused application security remediation initiative. This role is intended to address an existing backlog of application security work the current team does not have the capacity to complete. This is solely a 3-month engagement and will likely not extend or convert to a full-time position.

Interview Process (1 panel interview)

Video panel interview with the Hiring Manager and technical team members (technical/behavioral)

Top Technical Requirements
• 3+ years of hands-on application security experience; general cybersecurity alone will not be sufficient, as the hiring manager is specifically targeting individuals with application security experience specifically
• Experience investigating and remediating security findings involving hard-coded credentials/secrets within source code repositories.
• Strong scripting/automation experience with PowerShell, Bash and/or Python; experience with at least two of these is a requirement
• Strong Git/GitHub knowledge and experience working with engineering teams on remediation projects

Top Soft Skills
• Ability to work effectively across multiple teams and personalities within a large engineering
• Comfortable engaging directly with internal software engineering stakeholders to drive findings through resolution
• Strong follow-through and ability to work independently manage work within a short, project-based engagement

Position Summary
These Application Security Engineers will be focused on a security remediation initiative addressing an existing backlog of hardcoded secrets and credential exposure findings across GitHub source-code repositories. Automated detection is already in place through GitHub Advanced Security (Enterprise) Secret Scanning. The focus is not building a new detection solution, but taking existing findings through investigation, validation, remediation coordination, documentation, and final disposition. Additionally, these engineers will partner with application security, software development, platform engineering, application owners, and other stakeholders to assess risk, determine ownership, coordinate remediation, and drive findings to documented closure. Successful candidates must be able to contribute meaningfully from day one.

What this individual will be working on
The project is specifically focused on secret and credential exposure within static source code. This is not a traditional vulnerability scanning, SOC, or runtime application-security role. The backlog contains hundreds of findings with different remediation paths based on credential type, validity, environment, privilege level, ownership, and potential exposure. The strongest candidate combines technical Application Security expertise with strong stakeholder management: independently investigating an issue, determining ownership, engaging the appropriate engineering or platform team, explaining the risk, helping determine the remediation path, and following the issue through closure. Executive and VIP Technology Support

• Hard-coded credentials/passwords; AWS/API access keys; tokens and personal access tokens
• Private/asymmetric keys; OAuth credentials; database credentials and connection strings
• Certificates and other sensitive values committed to source code or repository history

Key Responsibilities
• Review and triage automated secret-scanning findings generated through GitHub Advanced Security.
• Investigate GitHub repositories and repository history to determine validity, ownership, environment, privilege level, and potential risk.
• Determine whether exposed credentials remain active and identify the appropriate remediation path.
• Partner with development, platform engineering, application owners, and security stakeholders to drive remediation.
• Coordinate credential revocation, rotation, secure replacement, and removal from source code, then validate successful closure.

Application Security Engineer | Confidential Job Profile
• Document false positives, test credentials, revoked credentials, accepted risks, and other outcomes with consistent, auditable rationale.
• Escalate high-risk, privileged, production, externally exposed, or potentially misused credentials through established processes.
• Use the GitHub REST API and scripting to retrieve, enrich, correlate, assign, update, and report on findings at scale.
• Work with existing credential-validation scripts and modify, extend, or improve automation where useful.
• Manage a large remediation backlog independently and drive findings through documented closure. Conduct post-event reviews for material issues and implement corrective actions to prevent recurrence.

Required Skills
• 3+ years of hands-on Application Security experience in an AppSec or DevSecOps environment.
• Strong understanding of secrets exposure, credential risk, secure validation, revocation/rotation, and secrets-management practices.
• Strong knowledge of GitHub and Git source control, including repositories, branches, commits, pull requests, permissions, and repository history.
• Practical experience integrating with or working through GitHub REST APIs.
• Hands-on scripting experience with at least two of the following strongly preferred: PowerShell, Bash, Python.
• Ability to understand, modify, and extend existing scripts rather than relying solely on prebuilt tooling.
• Ability to prioritize a large, potentially ambiguous remediation backlog and drive findings to documented closure.
• Strong written/verbal communication and the ability to work directly with software engineers, platform teams, and technical stakeholders.
• High attention to detail and sound judgment when handling sensitive security information.
• Ability to work independently and hit the ground running in a short-duration engagement.

Preferred Qualifications
• Hands-on experience with GitHub Advanced Security (Enterprise) and Secret Scanning.
• Experience remediating hard-coded secrets or exposed credentials within source-code repositories.
• Familiarity with AWS and Azure security environments, including AWS Secrets Manager and Azure Key Vault concepts.
• Experience with CI/CD pipelines, cloud identity services, security ticketing, and governance workflows.
• Familiarity with cloud access keys, PATs, OAuth credentials, SSH/private keys, database credentials, and certificates.
• Experience with AppSec remediation metrics, backlog reporting, or workflow automation.
• Experience partnering across large software engineering organizations.

Why TalentBurst?
At TalentBurst, we deliver more than talent, we deliver outcomes. We partner with you to move quickly and connect you to opportunities aligned with your skills and long term growth.

Backed by precision, transparency, and results, we connect top talent with leading organizations through trusted partnerships.

We offer competitive compensation and comprehensive benefits, including medical, dental, vision, and retirement options.

TalentBurst is an equal opportunity employer committed to an inclusive and diverse workforce.

Read the full posting

Also open

Also open at TalentBurst

TalentBurst's other jobs that have a page here. Each page says open or closed for itself.