Insight Global logo

Application Security Tech Lead

Insight Global

Alpharetta, GAJob$60–70/hrSeen 2 days agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$60–70/hr
Location
Alpharetta, GA
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Application Security Tech Lead defines and delivers application security standards for the BC2 remediation program within Data Engineering. The role translates InfoSec controls into engineering specifications, creates hardened reference implementations, and validates remediation before production. It partners with remediation engineers and teams across security, platform engineering, application development, and operations, while application owners retain sign-off and risk acceptance for their systems.

Skills & qualifications

RequiredNice to have

Skills

Software EngineeringCI/CDBuild SystemsDeveloper PlatformsLinuxWindowsEngineering Standards AdoptionContainer Build SystemsVulnerability ManagementJava.NETPythonTest StrategyAWS or AzurePipeline AutomationJenkinsGitHub ActionsGitLabInfrastructure as CodeTerraformAnsibleInventory Data ExtractionDependency Data ExtractionConfiguration Data ExtractionPolicy as CodeSBOM GenerationBuild ProvenanceArtifact SigningSecure Base Image PlatformsCloud Security Posture ManagementVerbal CommunicationWritten Communication

Qualifications

10+ Years Software EngineeringTech Lead ExperienceRegulated Environment ExperienceShared-Services Delivery Experience

Full job description

Job Description

We are seeking a Tech Lead to define and deliver the application security standards used across the BC2 remediation program within Data Engineering. This is a centralized role that translates InfoSec control requirements into executable engineering specifications, establishes hardened reference implementations for each application type in the estate, and validates remediation prior to production implementation.

The role works alongside remediation engineers who execute against those standards, and partners with Information Security, Platform Engineering, application development teams, and operational support. Application owners retain sign-off and risk acceptance for their own systems.

Duties

  • Translate InfoSec control requirements into scoped, assignable engineering work with defined acceptance criteria and audit evidence.
  • Create and maintain well-defined development tickets with clear requirements and measurable outcomes, enabling effective tracking of developer progress, delivery, and performance.
  • Classify the application estate into a small number of types, based on build and runtime characteristics, and maintain that classification as the estate changes.
  • Establish, or specify for others to build, the tooling, environments, and pipeline capability required to deliver and validate standards at scale.
  • Design, build, and maintain a hardened reference implementation for each type, covering approved base images, required security controls, verification, and evidence generation.
  • Define migration paths for end-of-life runtimes and frameworks and identify workloads where retirement or replacement is lower cost than remediation.
  • Analyze scan findings and exception requests to determine exploitability, identify false positives, and specify compensating controls where remediation is not viable, including applications where source changes are not possible.
  • Define acceptance criteria and rollback procedures with the accountable application owner prior to production implementation, escalating where ownership is unresolved.
  • Ensure remediation evidence is generated by the build rather than assembled manually.
  • Provide technical direction to remediation engineers executing against published standards.
  • Produce standards documentation, migration procedures, developer guidance, and remediation evidence.

The pay rate for this ranges between $60-70/hour based on years of experience and expertise.

Skills and Requirements

  • 10+ years of software engineering experience across the full development lifecycle, including Tech Lead roles.
  • Experience designing and operating CI/CD, build, or developer platform capability adopted at scale across multiple development teams.
  • Experience in Linux environments; Windows exposure preferred.
  • Experience delivering in regulated environments with audit and evidence obligations.
  • Experience in a shared-services or centralized delivery model supporting multiple application teams with competing priorities.

Required Technical Experience

  • Track record driving adoption of engineering standards across teams outside direct reporting lines.

  • Container build systems, including base images, multi-stage builds, minimal and hardened images, and the runtime impacts of adoption.

  • Vulnerability management, including interpreting scanner findings, exploitability and reachability assessment, prioritization, compensating controls, and exception documentation.

  • Working proficiency in Java, .NET, and Python sufficient to specify and review code changes.

  • Test strategy for request-serving services and for batch and pipeline workloads, including output-correctness verification.

  • Cloud platform depth in AWS or Azure.

  • CI/CD tooling and pipeline automation, such as Jenkins, GitHub Actions, GitLab, or equivalent.

  • Infrastructure as code, such as Terraform, Ansible, or equivalent. Desired Knowledge and Experience

  • Programmatic extraction of inventory, dependency, and configuration data from codebases at scale.

  • Policy as code.

  • Software supply chain controls, including SBOM generation, build provenance, and artifact signing.

  • Secure base image providers, cloud security posture management, or equivalent platforms.

  • Excellent verbal and written communication, with the ability to convey technical detail to audiences at varying technical levels.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.