Bloomberg Industry Group, Inc.
Bloomberg Industry Group, Inc.Verified Source

Application Security Engineer I Job at Bloomberg Industry Group

Onsite · Washington, District of Columbia
Posted August 11, 2026
payroll

Overview

You will own application security testing and vulnerability management for Bloomberg Industry Group's internal and external applications. This entry-level role focuses on SAST, DAST, SCA, and penetration testing. You will collaborate with software engineers to embed security into the CI/CD pipeline and support incident response. The team uses modern security tools and provides growth paths into AI Security and Security Engineering. This role stands out for its hands-on exposure to automated security tooling and direct mentorship from senior engineers.

What You'll Do10

  • 1Run SAST and DAST scans on applications and triage findings to eliminate false positives.
  • 2Review SCA reports to identify vulnerable dependencies and coordinate fixes with developers.
  • 3Build scripts to automate security testing in CI/CD pipelines using GitLab and GitHub Actions.
  • 4Partner with developers to design and review secure authentication and authorization features.
  • 5Investigate and remediate security incidents as part of the incident response team.
  • 6Maintain vulnerability management workflows and track remediation progress.
  • 7Conduct manual penetration tests on web applications and APIs.
  • 8Document secure coding guidelines and provide training to engineering teams.
  • 9Monitor emerging threats and evaluate new security tools for adoption.
  • 10Contribute to open-source security projects or CTF events to sharpen skills.

Requirements9

  • 1Basic knowledge of security principles, standards, and best practices.
  • 2Familiarity with Python, Java, or JavaScript for scripting and code review.
  • 3Exposure to security testing tools such as SAST, DAST, SCA, or vulnerability management platforms.
  • 4An associate's degree in Information Security, Computer Science, or related field, or equivalent experience.
  • 51-2 years of relevant experience in application security or related roles.
  • 6Ambition to learn and grow into AI Security and Security Engineering.
  • 7Certifications such as CompTIA Security+, CompTIA Pentest+, or Certified DevSecOps Professional (CDP) are a plus.
  • 8Hands-on experience with CI/CD pipelines (GitLab, GitHub Actions, Jenkins) is preferred.
  • 9Experience with AWS cloud environments and security automation is a plus.

Salary Insight

Salary not disclosed in listing

Location

Typeonsite
LocationWashington, District of Columbia

Required Skills

SASTDASTSCAPenetration TestingVulnerability ManagementPythonJavaJavaScriptCI/CD PipelinesAWSSecurity AutomationCompTIA Security+CompTIA Pentest+Certified DevSecOps Professional
Share:

Similar open positions

Explore active roles that match your skills and interests.

Bright Vision Technologies

Bright Vision Technologies

12h agoRemotepayroll

Application Security Engineer Bright Vision Technologies

Lead security integration across software development lifecycles for a remote full-time role at Bright Vision Technologies. Own security practices while collaborating with engineering teams to build resilient applications. Drive measurable risk reduction through proactive threat mitigation and secure coding standards.

100K–160K
SASTDASTIAST+4 more
Motion Recruitment Partners, LLC

Motion Recruitment Partners, LLC

13h agoCharlotte, North Carolinacontract

Principal Application Security Engineer

You will own application security for a major financial services firm with over 150 years of market presence, hardening Java and .NET applications across a global portfolio. You will lead security reviews, threat modeling, and code analysis while partnering with DevOps to embed security into CI/CD pipelines. This hybrid role in Charlotte, NC offers direct impact on high-velocity releases and access to cutting-edge cloud infrastructure.

89K–101K
java.netsast+2 more

greenlight

9h agoAtlanta, Georgiapayroll

Staff Product Security Engineer, AI & Cloud Security

You will own end-to-end security for consumer products, a digital platform, and an emerging hardware line at Greenlight, a fintech serving 6.5 million family members. You will drive threat modeling, lead penetration testing, manage PSIRT operations, and champion secure AI adoption across the company. Collaborating with architects, product managers, and engineering, you will define security guardrails for AI-powered products and development workflows. This role offers a rare blend of hands-on technical work and strategic influence in a highly regulated financial environment.

Competitive salary
Burp SuiteMetasploitKali Linux+12 more

Risk Management Foundation

19d agoBoston, Massachusettspayroll

Security Engineer Boston

The Cybersecurity Engineer reports to the Chief Information Security Officer and leads security engineering and operations. This role owns security technologies and processes protecting organizational information assets. It involves assessing risks implementing safeguards supporting GRC and AI security initiatives. The position differs by focusing on AI governance and cross-functional collaboration.

90K–106K
pythonawsreact+2 more
DMS Vision Inc.

DMS Vision Inc.

12h agoHouston, Texaspayroll

Application Security Engineer DMS Vision Inc.

Lead ownership of application security initiatives scaling across hybrid environments. Drive security posture through innovative solutions. Shape future direction of security practices. Differentiate by delivering cutting edge protection strategies.

Competitive salary
javapythonaws+2 more
Innova Solutions, Inc

Innova Solutions, Inc

7h agoCharlotte, North Carolinacontract

Lead Application Security Engineer AI

As a Lead Application Security Engineer, you will own the application security strategy for DCMS in-scope applications, defining tier-based control models that scale across the portfolio. You will evaluate existing AppSec control coverage, establish baseline mappings, and drive remediation of critical gaps. Reporting to the security leadership, you will collaborate with engineering teams to embed security into the SDLC, focusing on cloud-native environments and AI applications. This role offers the chance to shape security posture for a major financial client, with a 12+ month contract and hybrid work in Charlotte, NC.

Competitive salary
Application SecurityAI