1

Appsec Jobs in Missouri (NOW HIRING)

*Senior Software Engineer

Kansas City, MO · On-site

$119K - $157K/yr

Implement application security (AppSec) recommendations by remediating insecure data handling and enforcing secure coding practices in alignment with internal security standards. Required ...

Develop an AppSec pipeline and integrate it into the agile software development process. Required Qualifications: BA/BS degree in Computer Science, Information Systems, Cyber Security or a related ...

Appsec information

Is Appsec entry level?

Application security (AppSec) roles can be entry-level or require experience, depending on the position. Entry-level AppSec jobs typically focus on basic security practices, vulnerability assessments, and may require foundational knowledge of networking, coding, or security tools. More advanced roles often demand prior experience, certifications, or specialized skills.

Is application security in demand?

Application security (AppSec) professionals are in high demand due to increasing cyber threats and the widespread adoption of digital services. Organizations seek skilled experts to identify vulnerabilities, implement security measures, and ensure compliance, often requiring knowledge of security tools, coding, and certifications like CISSP or CEH.

What is the difference between Appsec vs Security Analyst?

AspectAppsecSecurity Analyst
Required CredentialsCertifications like CISSP, CEH, OSCP; knowledge of secure codingCertifications such as Security+, CISSP; threat analysis skills
Work EnvironmentDevelopment teams, secure coding practices, application testingMonitoring security systems, incident response, risk assessment
Employer & Industry UsageTech companies, software firms, organizations with application security needsAll industries, including finance, healthcare, government, focusing on security monitoring

Appsec professionals focus on securing applications through secure coding, testing, and vulnerability management, while Security Analysts monitor and respond to security threats across systems. Both roles require security certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

What are popular job titles related to Appsec jobs in Missouri? For Appsec jobs in Missouri, the most frequently searched job titles are:
What job categories do people searching Appsec jobs in Missouri look for? The top searched job categories for Appsec jobs in Missouri are:
Infographic showing various Appsec job openings in Missouri as of August 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 50% In-person, and 50% Remote job distribution.

Only W2- Application Security (AppSec) Engineer

Digitive LLC

Creve Coeur, MO • On-site

$57.25 - $76.50/hr

Other

Posted 2 days ago

New


Job description

Job Title- Application Security (AppSec) Engineer
Location: Onsite - Maryland Heights, MO
Only W2 (No C2C)

What are the top 3 skills required for this role?
• Application Security (AppSec)
• Secure SDLC / DevSecOps
• SAST, DAST, IAST, SCA
• Web, Mobile & API Security Testing
• Manual Penetration Testing & Business Logic Testing
• Threat Modelling
• Vulnerability Management
• Secure Code Review
• CI/CD Security Integration
Job Description/ Responsibilities
The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD pipelines and post-deployment processes, ensuring comprehensive security coverage without impacting engineering velocity.
The ideal candidate will combine expertise in secure SDLC, automated security testing, DevSecOps, cloud-native applications, APIs, and manual penetration testing to improve application security posture across web, mobile, and microservices architectures. This aligns with Secure SDLC requirements, including SAST, DAST, SCA, and manual validation activities integrated throughout the development lifecycle.
________________________________________
Key Responsibilities
Application Security Engineering
• Design and implement enterprise-wide Application Security programs for web, mobile, and API-based applications.
• Integrate security controls and testing activities into Agile, DevOps, and CI/CD pipelines.
• Establish automated security gates using SAST, DAST, SCA, IAST, secret scanning, and container security tools.
• Enable continuous post-deployment security validation and risk monitoring.
Security Testing & Validation
• Conduct manual penetration testing and business logic testing to identify vulnerabilities beyond automated scanning capabilities.
• Perform authenticated and unauthenticated security assessments of applications and APIs.
• Execute threat modeling, attack-path analysis, and architecture reviews for new applications and platform services.
• Validate remediation effectiveness and secure deployment practices.
DevSecOps Integration
• Embed security testing into GitHub Actions, Azure DevOps, Jenkins, GitLab, or similar CI/CD platforms.
• Automate vulnerability triage, prioritization, and remediation workflows.
• Develop security-as-code controls and policy enforcement mechanisms.
• Collaborate with engineering teams to implement secure coding practices and shift-left security initiatives.
Vulnerability Management
• Analyze findings from multiple security tools and eliminate false positives.
• Prioritize vulnerabilities based on business risk, exploitability, and application criticality.
• Track remediation efforts through SDLC and release cycles.
• Develop security metrics, dashboards, and executive reporting.
Developer Enablement
• Conduct secure coding reviews and developer education sessions.
• Establish security champions programs across engineering teams.
• Provide remediation guidance and hands-on support during application releases.
• Drive adoption of secure development standards and best practices.
Cloud & API Security
• Assess cloud-native applications deployed across AWS, Azure, GCP, Kubernetes, and container platforms.
• Secure REST, GraphQL, and microservice-based APIs.
• Evaluate infrastructure-as-code (Terraform, ARM, CloudFormation) and container security controls.
• Support software supply chain security initiatives, including SBOM/SCA validation.
• 8–15 years of experience in Application Security, DevSecOps, or Security Architecture.
• Experience securing large-scale enterprise applications across cloud and hybrid environments.
• Relevant certifications preferred:
o CISSP
o CSSLP
o GWAPT
o OSCP
o CEH
o Azure/AWS Security Certifications