Job Description
An Insight Global client is looking for an Application Security Engineer to join their Atlanta based team. This engagement is focused on reviewing security findings generated by application security scanning tools and driving remediation efforts across multiple technologies and frameworks. Initial efforts will center on WordPress-based applications, but the engineer will also support broader frontend and API security initiatives involving JavaScript, TypeScript, React, Angular, and related technologies. Candidates with a strong software development background who have transitioned into application security will be particularly successful in this role
• Assess, prioritize, and remediate application security vulnerabilities across web applications.
• Review, analyze, and remediate insecure code within WordPress, PHP, JavaScript, and related technologies.
• Collaborate with software engineers to implement secure coding standards and best practices.
• Address findings identified through vulnerability scans, penetration testing, and code reviews.
• Review and secure WordPress core functionality, custom themes, and third-party plugins.
• Evaluate vulnerable WordPress plugins, implement mitigations, apply patches, and recommend secure alternatives when necessary.
• Perform secure code reviews and identify vulnerabilities within PHP, JavaScript, and API integrations.
• Support PCI-DSS compliance initiatives, including requirements related to script integrity monitoring and payment page security.
• Monitor and remediate risks associated with malicious or unauthorized scripts on payment and checkout pages.
Help establish repeatable security processes to prevent future vulnerabilities.
Compensation:
$50/hr to $60/hr
Exact compensation may vary based on several factors, including skills, experience, and education.
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
• Experience developing and maintaining web applications using WordPress, PHP, and JavaScript.
• Hands-on experience remediating security vulnerabilities within web or frontend applications.
• Experience working with PCI-DSS compliance requirements, especially payment page security.
• Strong understanding of secure coding principles and application security best practices.
• Experience addressing vulnerabilities identified through:
○ Penetration testing
○ Vulnerability scanning tools
○ Secure code reviews
• Experience reviewing, modifying, and securing:
○ WordPress Core
○ Custom Themes
○ Third-Party Plugins
• Proven ability to assess vulnerable WordPress plugins, implement fixes, and deploy security patches.
• Experience performing secure code reviews and identifying security weaknesses in:
○ PHP
○ JavaScript
○ API integrations
• Ability to work across frontend and backend application stacks.
• Understanding of APIs and web application architecture.
Familiarity with Ruby-based environments is helpful
Nice to Have Skills & Experience
• Knowledge of cloud environments such as AWS and/or GCP.
• Understanding of CI/CD pipelines and security automation.
• Exposure to DevOps practices and tooling.
• Experience with modern frontend frameworks such as:
○ React
○ Angular
TypeScript
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.