Job Summary:
Alpha Consulting Corp. is seeking an Application Security Engineer to join Hearst Technology’s Cybersecurity Organization. This role involves managing the application security program, including tooling implementation and embedding security into DevOps pipelines, while fostering relationships with various business units.
Responsibilities:
• Application discovery and inventory across all business units, including ownership mapping, technology stack profiling, and risk tiering.
• Standing up and operating the AppSec tooling stack — SAST, SCA, secrets scanning, and container/IaC scanning — integrated into business unit CI/CD pipelines.
• Designing and implementing AI-assisted triage workflows on top of AppSec tooling to manage finding volume and filter false positives.
• Defining secure SDLC requirements, threat modeling practices, and security gates that business units adopt as part of their standard development process.
• Partnering with business unit development leaders to build relationships and shared playbooks needed to operationalize AppSec without becoming a blocker to delivery.
• Contributing to AI security strategy — evaluating emerging tools and recommending what to operationalize and what to defer.
• Producing executive-ready metrics and reporting that connect AppSec activity to business risk reduction.
Qualifications:
Required:
• 7 years in application security, product security, or security engineering, with at least 3 years in environments with multiple independent business units, brands, or product lines.
• Hands-on experience deploying and operating modern AppSec tooling (e.g., Semgrep, Snyk, Checkmarx, Veracode, Apiiro, Ox Security, GitHub Advanced Security).
• Working code-level proficiency in at least three commonly-used languages (e.g., Python, JavaScript/TypeScript, Java, C#, Go) sufficient to read, review, and triage findings.
• Strong scripting and automation skills in Python or equivalent; comfortable building integrations against REST APIs and operating in CI/CD environments (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
• Demonstrated ability to influence engineering organizations without direct authority — negotiating standards, driving adoption, and partnering with development leaders.
• Practical understanding of OWASP Top 10, threat modeling methodologies (STRIDE, PASTA, or equivalent), and modern attack patterns including supply chain risks.
• Prior work experience at client or in client's Industry.
• Applicants must be able to work directly for Artech on W2.
Preferred:
• Experience integrating LLM-based tooling into security workflows (alert triage, finding summarization, remediation guidance generation).
• Familiarity with one or more compliance frameworks relevant to our environment (HITRUST, HIPAA, NIST AI RMF, SOC 2).
• Prior experience working in a regulated or healthcare-adjacent environment.
• Cloud security depth in at least one major provider (AWS, Azure, GCP).
• Public contribution to AppSec community — OSS, conference talks, published research, or detection/rule contributions.
Company:
Alpha Consulting Corp. has been exceeding expectations in the IT, pharmaceutical, and clinical staffing business since 1994. Founded in 1994, the company is headquartered in East Brunswick, USA, with a team of 201-500 employees. The company is currently Growth Stage.