Arctiq

Application Security Remediation Engineer

Arctiq New York, New York, United States

IT Services and IT Consulting · 501-1,000 employees

19 h ago
Remote security Senior (5-10 yrs) Contractor United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The engineer will analyze and remediate application-level vulnerabilities across various technology stacks to ensure software security and stability. They will collaborate with software engineering teams to upgrade dependencies, secure container images, and implement sustainable remediation patterns.

What they look for

Application Security Vulnerability Remediation C# Java Go PHP Node.js Docker Kubernetes Wiz CI/CD DevSecOps SQL Server MySQL Secure Coding OWASP Top 10

Requirements

Candidates must have strong software engineering experience in languages such as .NET, Java, Go, PHP, or Node.js and experience with vulnerability management. Proficiency in container security, CI/CD integration, and familiarity with security tools like Wiz or Snyk is required.

Full description

Company Overview:

Arctiq is a global, intelligence-driven technology services company delivering professional and managed services across Hybrid Cloud Infrastructure, Networking & Connected Experiences, Cybersecurity, Data & AI, Autonomous Operations & Intelligence, and Enterprise Service Management. We help organizations operate, secure, and modernize complex environments by unifying infrastructure, networking, data, security, automation, and observability under a single, integrated operating model. Our work focuses on helping customers reduce operational friction, improve resilience, and make better, faster decisions as their environments evolve. Arctiq builds on decades of industry expertise and a customer-centric ethos to deliver exceptional value to clients across diverse industries.

This is a remote, supporting a project Arctiq is delivering for a client.

This is a 3 months contract.

Position Overview: Arctiq is seeking an Application Security Remediation Engineer to support the customer’s vulnerability remediation initiative across multiple application platforms and technology stacks. This role focuses on resolving code-level vulnerabilities, upgrading dependencies, securing container images, and implementing sustainable remediation patterns within enterprise software environments. The consultant will work directly alongside the customer’s software engineering teams to remediate vulnerabilities identified through Wiz across .NET, Java, Go, PHP, Node.js, SQL Server, and MySQL workloads while ensuring compatibility, stability, and operational continuity. 

Responsibilities:

  • Analyze and remediate application-level vulnerabilities identified by Wiz. 
  • Resolve code vulnerabilities within .NET, Java, PHP, Go, and Node.js applications. 
  • Upgrade vulnerable libraries, frameworks, packages, and third-party dependencies. 
  • Perform compatibility and regression testing for upgraded software components. 
  • Remediate container image vulnerabilities and insecure build configurations. 
  • Modernize and rebuild affected images to comply with organizational security standards. 
  • Work with development teams to incorporate secure coding practices. 
  • Address insecure configurations within application runtimes and frameworks. 
  • Validate completed remediations and ensure findings are accurately resolved within Wiz. 
  • Design and document reusable remediation patterns for recurring vulnerability classes. 
  • Support secure software delivery through DevSecOps and CI/CD integration. 
  • Collaborate with SRE, cloud, platform, and security teams throughout remediation activities. 

Qualifications:

  • Strong software engineering experience in one or more of .NET/C#, Java, Go, PHP, or Node.js. 
  • Experience working with enterprise-scale application environments. 
  • Experience remediating application vulnerabilities and applying secure coding practices. 
  • Strong understanding of OWASP Top 10 vulnerabilities and software supply-chain security. 
  • Experience upgrading third-party libraries, frameworks, packages, and application dependencies. 
  • Docker and container image remediation experience. 
  • Kubernetes application deployment and container security experience. 
  • Experience with SQL Server and/or MySQL, including application-to-database security fundamentals. 
  • CI/CD pipeline integration, Git-based workflows, and Secure Software Development Lifecycle practices. 
  • Experience with automated security testing, SAST, SCA, and dependency-management tooling. 
  • Experience with vulnerability management programs and prioritization of Critical and High findings. 
  • Experience using Wiz, Snyk, Veracode, Checkmarx, SonarQube, or similar tools. 
  • Strong debugging, analytical, root-cause investigation, documentation, and communication skills. 

Preferred Qualifications:

  • Hands-on Wiz experience. 
  • Experience securing containerized microservices architectures. 
  • Cloud-native application development experience. 
  • Experience with Amazon EKS and Kubernetes. 
  • Secure coding or application-security certifications. 
  • Experience in healthcare, payments, or other regulated industries. 

Tools and Technologies:

  • Wiz 
  • .NET / C# 
  • Java 
  • PHP 
  • Go 
  • Node.js 
  • SQL Server 
  • MySQL 
  • Docker 
  • Kubernetes 
  • Amazon EKS 
  • Git 
  • GitHub / GitLab 
  • CI/CD platforms 
  • Dependency scanning tools 
  • SAST / SCA platforms 
  • OWASP tooling 
  • DevSecOps toolchains 

Arctiq is an equal opportunity employer. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know. We celebrate our inclusive work environment and welcome members of all backgrounds and perspectives to apply.

We thank you for your interest in joining the Arctiq team! While we welcome all applicants, only those who are selected for an interview will be contacted.

Similar roles