1

Trainee Application Security Engineer Jobs in Raleigh, NC

Application Security Engineer

Raleigh, NC ยท On-site

$57 - $76.25/hr

Integrate DAST scanning into CI/CD pipelines to enable continuous security testing within DevOps workflows * Stay current on emerging web application and API vulnerabilities, OWASP Top 10 and API Top ...

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

Senior Product Security Engineer

Raleigh, NC ยท On-site

$168K - $210K/yr

You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.

Senior Product Security Engineer

Raleigh, NC ยท Hybrid

$168K - $210K/yr

You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.

next page

Showing results 1-20

Trainee Application Security Engineer information

See Raleigh, NC salary details

$28

$64

$93

How much do trainee application security engineer jobs pay per hour?

As of Jun 13, 2026, the average hourly pay for trainee application security engineer in Raleigh, NC is $64.55, according to ZipRecruiter salary data. Most workers in this role earn between $54.90 and $73.37 per hour, depending on experience, location, and employer.

What is the difference between Trainee Application Security Engineer vs Junior Application Security Engineer?

AspectTrainee Application Security EngineerJunior Application Security Engineer
CertificationsEntry-level, often no certifications required or basic security certificationsSome certifications preferred, such as CompTIA Security+ or CEH
Work EnvironmentTraining-focused, supervised tasks, learning phaseMore independent, handling security assessments and vulnerability testing
ResponsibilitiesAssisting in security audits, learning security tools, basic analysisConducting security scans, analyzing vulnerabilities, supporting security projects

While both roles involve security tasks, a Trainee Application Security Engineer is typically in a learning phase with supervised duties, whereas a Junior Application Security Engineer handles more independent security assessments and analysis, requiring some experience and certifications.

What are the most commonly searched types of Application Security Engineer jobs in Raleigh, NC? The most popular types of Application Security Engineer jobs in Raleigh, NC are:
What are popular job titles related to Trainee Application Security Engineer jobs in Raleigh, NC? For Trainee Application Security Engineer jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Trainee Application Security Engineer jobs in Raleigh, NC look for? The top searched job categories for Trainee Application Security Engineer jobs in Raleigh, NC are:
Application Security Engineer

Application Security Engineer

IT First Source

Raleigh, NC โ€ข On-site

$57 - $76.25/hr

Other

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Job Title: Application Security Specialist โ€“ Invicti

Fulltime

Job Summary

We are seeking an experienced Application Security Specialist to strengthen the security posture of web applications and APIs through Dynamic Application Security Testing (DAST), automated vulnerability scanning, and continuous security testing. This role will leverage Invicti Enterprise to support scalable application security testing across the secure SDLC, including integration within CI/CD pipelines. The ideal candidate will have strong hands-on experience configuring, operating, and optimizing Invicti (Acunetix/Netsparker) or comparable DAST platforms in an enterprise environment, with demonstrated ability to validate findings, troubleshoot scan issues, and partner effectively with development teams.

  1. Onboard web applications and APIs to the Invicti Enterprise platform for authenticated and unauthenticated DAST scans.
  2. Configure DAST scans using pre-request scripts and custom scan settings to support complex authentication and application flows.
  3. Monitor scan execution, status, and failures; troubleshoot issues related to authentication, session handling, crawl limitations, and coverage gaps
  4. Analyze, validate, and triage vulnerabilities identified by Invicti, distinguishing true positives from false positives and appropriately dispositioning findings
  5. Perform manual verification using Burp Suite, as needed, to reduce false positives and false negatives
  6. Integrate DAST scanning into CI/CD pipelines to enable continuous security testing within DevOps workflows
  7. Stay current on emerging web application and API vulnerabilities, OWASP Top 10 and API Top 10, and application security best practices

Required Skills & Qualifications

  1. Strong understanding of web technologies, including HTTP/S, requests and responses, headers, cookies, and session handling
  2. Hands on experience writing JavaScript for scan configuration and pre-request scripting
  3. 3โ€“5 years of hands-on experience with Invicti (Acunetix/Netsparker) or comparable enterprise DAST tools
  4. Solid understanding of OWASP Top 10, CWE, and common web and API vulnerabilities
  5. Experience with authentication mechanisms such as OAuth, SAML, JWT, and cookie based authentication
  6. Demonstrated ability to analyze scan results and confidently distinguish valid vulnerabilities from false positives
  7. Strong communication skills with the ability to collaborate effectively with developers, DevOps teams, and security stakeholders
  8. 3โ€“5 years of application security experience, with a focus on DAST and secure SDLC practices

Preferred Qualifications

  1. Experience with additional security tools (e.g., Burp Suite, OWASP ZAP, Snyk, HCL AppScan, Fortify Web Inspect).
  2. Scripting or programming experience (Python, Java, JavaScript, or similar languages).
  3. Experience with cloud platforms (AWS, Azure, Google Cloud Platform).
  4. Security certifications (e.g., CEH, GWAPT, OSCP).
  5. Knowledge of compliance frameworks (ISO 27001, SOC 2, PCI DSS).
  6. Experience with CI/CD tools such as Jenkins, GitHub, or Harness.
  7. Hands-on experience with web application and API security testing.