1

Checkmarx Jobs in Pennsylvania (NOW HIRING)

Hands-on experience with application security testing tools such as Burp Suite, Fortify, Checkmarx, Veracode, and ZAP. * Experience conducting threat modeling, penetration testing, secure software ...

Hands-on experience with application security testing tools such as Burp Suite, Fortify, Checkmarx, Veracode, and ZAP. * Experience conducting threat modeling, penetration testing, secure software ...

Sr. Azure Cloud Engineer

Conshohocken, PA · On-site

$54.75 - $73.25/hr

Checkmarx etc.). * Experience of single sign-on products (e.g. SAP Gigya/CDC) What Cencora offers We provide compensation, benefits, and resources that enable a highly inclusive culture and support ...

New

Checkmarx information

See Pennsylvania salary details

$17

$51

$83

How much do checkmarx jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for checkmarx in Pennsylvania is $51.21, according to ZipRecruiter salary data. Most workers in this role earn between $43.85 and $61.44 per hour, depending on experience, location, and employer.

What is Checkmarx?

Checkmarx is a software security platform that specializes in application security testing. It helps developers and security teams identify vulnerabilities in their code through automated static and interactive application security testing (SAST and IAST). Checkmarx integrates with development pipelines to scan source code, open-source libraries, and APIs, enabling teams to find and fix security issues early in the software development lifecycle. The platform supports a wide range of programming languages and frameworks, making it a popular choice for organizations focused on secure software development.

What are the key skills and qualifications needed to thrive as a Checkmarx application security engineer?

To thrive as a Checkmarx Application Security Engineer, you need a solid understanding of secure software development, vulnerability assessment, and application security principles, often supported by a degree in computer science or related field. Experience with the Checkmarx SAST platform, knowledge of CI/CD pipelines, and relevant certifications such as CISSP or CEH are typically required. Strong analytical thinking, communication skills, and the ability to work collaboratively with development teams make someone stand out in this position. These skills are vital for effectively identifying and mitigating security risks in the software development lifecycle, ensuring robust protection of organizational assets.

What are some common challenges faced by professionals working with Checkmarx in an application security role?

Professionals working with Checkmarx often encounter challenges such as integrating the tool into existing CI/CD pipelines, managing false positives in scan results, and maintaining clear communication between security and development teams. Staying up-to-date with evolving vulnerabilities and ensuring that all codebases are consistently scanned can also be demanding. However, these challenges are typically addressed through strong collaboration, continuous learning, and leveraging Checkmarx's robust reporting and integration features.

What is the difference between Checkmarx vs SAST Developer?

AspectCheckmarxSAST Developer
CredentialsSecurity certifications, coding knowledgeSecurity certifications, coding knowledge
Work EnvironmentSecurity teams, development teamsDevelopment teams, security teams
Industry UsageApplication security testing toolsDeveloping and integrating SAST tools
Search IntentCompare security tools and rolesRoles involving static application security testing

Checkmarx professionals focus on using security testing tools like Checkmarx to identify vulnerabilities, while SAST Developers develop and maintain static application security testing (SAST) tools and integrations. Both roles require security and coding expertise but differ in their primary focus—one on utilizing security solutions, the other on creating them.

What cities in Pennsylvania are hiring for Checkmarx jobs?

Cities in Pennsylvania with the most Checkmarx job openings:

Infographic showing various Checkmarx job openings in Pennsylvania as of August 2026, with employment types broken down into 83% Full Time, 8% Part Time, and 9% Contract. Highlights an 57% Physical, 15% Hybrid, and 28% Remote job distribution, with an average salary of $106,513 per year, or $51.2 per hour.

IT Application Security Analyst

Scandinavian Tobacco Group

Bethlehem, PA • On-site

$125K - $135K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 29 days ago


Job description

IT Application Security Analyst
Posting Start Date: 7/14/26
Bethlehem, Pennsylvania, 18015,
Salary Range: $125,000-$135,000/yr
ABOUT THE ROLE...
The IT Application Security Analyst plays a key role in embedding security by design across the enterprise software development lifecycle (SDLC). This position partners closely with development, DevOps, QA, and IT Operations teams to integrate secure development frameworks, tooling, and practices that strengthen the security, resilience, and compliance of STG's applications and platforms.
The role focuses on advancing application security maturity by aligning development practices with industry standards such as NIST SSDF and OWASP ASVS, while enabling teams to deliver software securely and efficiently.
WHAT WILL YOU BE RESPONSIBLE FOR?
Secure SDLC & Governance
  • Assess and continuously improve SDLC processes, tools, and release workflows from a security perspective.
  • Perform gap analyses against secure-development frameworks including NIST SSDF and OWASP ASVS.
  • Define, maintain, and evolve secure development standards and procedures aligned with regulatory requirements such as PCI DSS and CCPA/GDPR.
  • Partner with engineering teams to recommend and implement practical security improvements across the SDLC.

Application Security Enablement
  • Embed security controls across all SDLC phases, including planning, design, coding, testing, deployment, and maintenance.
  • Deliver threat modeling, secure-design guidance, and application architecture reviews.
  • Establish and support secure design and code-review practices, coaching developers on security best practices.
  • Balance security requirements with developer experience and business requirements to reduce friction while increasing security maturity.

AppSec Tooling & Automation
  • Implement, operate, and optimize application security tooling including SAST, DAST, and SCA solutions.
  • Integrate security tooling (e.g., Snyk, Checkmarx) into CI/CD pipelines to enable automated vulnerability detection.
  • Define and enforce security gates or holds at key points within development and release workflows.
  • Ensure vulnerability findings are actionable, prioritized, and integrated into remediation processes.

Testing, Monitoring & Vulnerability Management
  • Support static, dynamic, and penetration testing activities in partnership with internal and external resources.
  • Integrate vulnerability management, continuous monitoring, and remediation tracking into the SDLC.
  • Provide application-security support during security incidents and assist teams with investigation and remediation.

Platform & Architecture Security
  • Support secure platform and environment modernization efforts, including container security, OS hardening, and secrets management (e.g., Vault, Azure Key Vault).
  • Contribute to application and platform architecture improvements focused on security, stability, and resilience.

REQUIREMENTS:
  • 3+ years of experience in Application Security or Software Engineering with a focus on secure development practices.
  • Hands-on experience implementing secure SDLC frameworks such as NIST SSDF and OWASP ASVS.
  • Practical experience integrating SAST/DAST tools into CI/CD pipelines and workflows.
  • Working knowledge of PCI DSS and privacy regulations (CCPA/GDPR) as they impact software development.
  • Strong communication skills with the ability to influence and collaborate with engineering teams.

PREFERRED QUALIFICATIONS
  • Experience with container security, image hardening, and secrets management technologies.
  • Familiarity with the OWASP Top 10, API security, and modern application security practices.
  • Experience coordinating or supporting penetration testing or DAST programs.
  • Relevant certifications such as CSSLP, CISSP, GWAPT, GCSA, or similar.

WHAT'S IN AN OFFER?
As a colleague at Scandinavian Tobacco Group, you will receive a comprehensive compensation package as a generous benefits package.
• Comprehensive Health Care, Vision & Dental Plan
• Flexible Spending Account
• Disability Plans
• Basic & Supplemental Life Insurance
• Additional Supplemental Benefits
• Paid Vacation, Paid Time Off (PTO) days, Holidays
• 401(k) Retirement Saving Plan including a generous Company match
Our company uses E-Verify to confirm the employment eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit www.e-verify.gov.
*Please be informed that this Direct Search is conducted exclusively by the Scandinavian Tobacco Group. We do not accept applications from agencies, and we will not provide compensation for unsolicited CVs.
**This position does not offer Visa sponsorship. Candidates must have valid work authorization in the United States and only qualified candidates will be contacted.