Source description
About the role
The team is looking for candidates with a background in managing security and vulnerability products (e.g., Snyk) within environments spanning multiple business units. This individual should take ownership of both the security tooling and the vulnerability backlog, driving issues through to full resolution rather than stopping at triage. Ideal candidates have a hybrid skill set, having supported both product and security responsibilities, and must be capable of hands-on remediation and coding, not just governance or reporting.
Title: Application Security Engineer
Location: Hybrid to Woonsocket Office
Day to Day:
This role focuses on identifying, prioritizing, and resolving application- and dependency-level security vulnerabilities across a large, primarily legacy codebase. While most vulnerabilities are well understood and straightforward to fix, the challenge lies in the volume, downstream impact, and coordination with multiple code owners. The successful candidate will significantly reduce manual security workload by addressing high-volume, low-complexity issues and supporting automation efforts, freeing senior engineers to focus on complex and high-risk vulnerabilities.
Key Responsibilities
Monitor and manage application security vulnerabilities across multiple repositories using tools such as Snyk.
Review, triage, and remediate vulnerabilities related to:
Legacy code
Outdated libraries and dependencies
Known security issues (e.g., SQL injection risks)
Partner with repository owners and DevOps teams to:
Communicate required fixes
Determine whether findings should be remediated, deferred, or formally ignored
Execute and track vulnerability remediation to meet established SLAs (typically 15 days)
Support and maintain CI/CD security scanning within pipelines (e.g., Jenkins)
Manually resolve high-volume, low-complexity issues caused by tool permissions or process limitations
Assist with onboarding and scanning of legacy code being migrated into GitHub
Identify and help reduce false positives generated by automated or AI-based security tools
Contribute to automation initiatives to:
Implement Snyk-recommended fixes
Introduce safeguards to prevent recurring issues
Reduce the backlog requiring human review
Required Technical Skills
Strong understanding of application security fundamentals
Proficiency with GitHub / Git
Hands-on experience with vulnerability scanning tools, especially Snyk
Familiarity with CI/CD pipelines and tooling (e.g., Jenkins)
Working knowledge of:
Python
SQL, including awareness of SQL injection risks
Ability to read, understand, and modify existing codebases
More at 3B Staffing