Prudent Technologies and Consulting
Prudent Technologies and ConsultingVerified Source

Cybersecurity Engineer, Vulnerability Management & SAST

Onsite · New York, New York
Posted August 12, 2026
contract

Overview

You will own the vulnerability identification and triage process across the product portfolio at a scale of 10,000+ assets. Your stack includes SAST, DAST, and SCA tools like AppScan, Fortify, and Checkmarx, alongside Burp and Snyk. Working with the security engineering team, you will reduce false positives and prioritize real risk. This role stands out by focusing on the intelligence layer between scanning and remediation, using ASPM tools like Vulcan and Brinqa.

What You'll Do8

  • 1Drive the weekly scan cycle across SAST and DAST platforms, ensuring coverage of all critical applications.
  • 2Analyze SAST and DAST outputs to eliminate false positives and consolidate duplicate findings.
  • 3Classify each vulnerability by severity, exploitability, and business impact using CVSS and threat intelligence.
  • 4Operate ASPM tools such as Vulcan and Brinqa to aggregate findings from multiple sources into a single view.
  • 5Automate the deduplication and enrichment process using scripts to cut manual effort by 30%.
  • 6Partner with development teams to validate exploitable paths and provide actionable remediation guidance.
  • 7Track vulnerability lifecycle and produce weekly metrics for leadership, highlighting trends and risk changes.
  • 8Tune scanner policies to match the tech stack, reducing noise from irrelevant checks in Java and JavaScript.

Requirements8

  • 13+ years hands-on with SAST, DAST, and SCA tools including AppScan, Fortify, or Checkmarx.
  • 2Experience running Burp Suite for manual web application testing and API security.
  • 3Proficiency with vulnerability management platforms like Qualys, Tenable, or Rapid7.
  • 4Familiarity with ASPM tools such as Vulcan, Brinqa, or ArmorCode.
  • 5Strong analytical skills to interpret scan results and reduce false positives and duplicates.
  • 6Working knowledge of OWASP Top 10 and CWE classification for effective prioritization.
  • 7Experience in a DevOps environment with CI/CD pipelines and integrating security tools.
  • 8Certification such as CEH, CISSP, or OSCP is a plus.

Salary Insight

Salary not disclosed in listing

Location

Typeonsite
LocationNew York, New York

Required Skills

SASTDASTSCAAppScanFortifyCheckmarxBurpSnykQualysTenableRapid7VulcanBrinqaArmorCodeinterpret tool outputsreduce false positivesanalyze scan resultsclassify vulnerabilities
Share:

Similar open positions

Explore active roles that match your skills and interests.

Bright Vision Technologies

Bright Vision Technologies

16h agoRemotepayroll

Application Security Engineer Bright Vision Technologies

Lead security integration across software development lifecycles for a remote full-time role at Bright Vision Technologies. Own security practices while collaborating with engineering teams to build resilient applications. Drive measurable risk reduction through proactive threat mitigation and secure coding standards.

100K–160K
SASTDASTIAST+4 more
Motion Recruitment Partners, LLC

Motion Recruitment Partners, LLC

16h agoCharlotte, North Carolinacontract

Principal Application Security Engineer

You will own application security for a major financial services firm with over 150 years of market presence, hardening Java and .NET applications across a global portfolio. You will lead security reviews, threat modeling, and code analysis while partnering with DevOps to embed security into CI/CD pipelines. This hybrid role in Charlotte, NC offers direct impact on high-velocity releases and access to cutting-edge cloud infrastructure.

89K–101K
java.netsast+2 more

SPAHR SOLUTIONS GROUP LLC

11h agoWashington, District of Columbiapayroll

Cybersecurity Protect Analyst

Lead technical cybersecurity liaison for subscriber organizations delivering advanced guidance on resolving complex security posture issues and patching delays. Serve as primary auditor for Data Element Dictionary governance overseeing validation rules for identity-attributed network and object-access events. Manage vulnerability tracking and KEV mitigation leveraging CVE NVD CVSS and CWE classifications. Conduct vulnerability assessments using ACAS and other enterprise scanning tools to provide prioritized remediation steps.

Competitive salary
pythonawsreact+2 more

Garmin International, Inc.

16h agoKansas City, Missouripayroll

Cyber Security Vulnerability Analyst 2

Garmin seeks a full-time Cyber Security Vulnerability Analyst 2 to operate independently configuring vulnerability scanning and assessments supporting risk identification analysis and remediation across networks operating systems applications and information system components. This role requires ownership of scanning processes stakeholder collaboration and execution of remediation plans based on data and experience.

Competitive salary
Vulnerability ScanningCVSSNIST 800-53+2 more
Visionaire Partners

Visionaire Partners

11h agoAtlanta, Georgiapayroll

Senior Cybersecurity Engineer, Cloud Security

You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.

100K–147K
defensive operationsthreat detectionrisk mitigation+7 more

NetJets

11h agoColumbus, Ohiopayroll

Cybersecurity Engineer NJUS

Lead technical design and implementation of security solutions for enterprise systems. Own development lifecycle from code creation to deployment, focusing on automation and integration across security domains.

Competitive salary
pythonpowershelljava+2 more