Canton, OHremote

Salary
$166,400–$187,200
Posted
Jun 29, 2026
Location
Canton, OH
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

This role sits within an application security team, handling triage of vulnerabilities surfaced by SCA, SAST, and DAST tooling, as well as responding to threat intelligence escalations and critical patch events. The engineer also tests and helps implement AI-assisted security tools, and works to harden the software supply chain — covering open-source dependencies, developer IDEs, plugins, and CI/CD pipelines against malicious code and compromise. It suits someone with hands-on scanning and vulnerability management experience who also has practical exposure to AI-enabled security tooling.

Senior level · 3+ years · Remote · Contract

Pay in the description: $90/hr

Must have (5)
SCA · 3+ yrsDAST · 3+ yrscode scanning · 3+ yrsopen-source scanning · 3+ yrsCI/CD
Nice to have (2)
SBOMLLMs

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 5,400 people nationally plausibly meet what this posting asks for (information security analysts). range 1,600–8,100

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

The three explicit must-haves are stated verbatim in the posting header: '3 plus years Code scanning experience, 3 plus years open-source scanning, and 3 plus years dynamic and static scanning.' These map to code scanning, open-source scanning, SCA/SAST/DAST, and dynamic/static scanning — all treated as hard gates with a 3-year minimum.

The overall years minimum is set to 3 to reflect the stated per-skill minimums; no separate overall experience floor is given.

The role is a 1-year W2 contract-to-hire, classified as Contract.

SOC is Medium confidence: the role is primarily AppSec triage and vulnerability management (15-1212), but a meaningful portion of the duties involve hands-on engineering, scripting, automation, and tooling implementation, which could support 15-1252. 15-1212 wins because security analysis and triage are the primary day-to-day deliverables.

AI/LLM tooling (frontier models, coding assistants, prompt orchestration) appears under Qualifications as 'practical familiarity' — softer language than the hard gates — so it is marked preferred.

SBOM and malicious package detection appear in the duties narrative and qualifications but are not called out as explicit must-haves; marked preferred.

'scripting/automation' is a named capability class required under Qualifications ('Engineering experience with scripting, automation, APIs…'); no single canonical tool is specified, so it is captured at that level rather than inventing a specific language.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): scripting/automation, software supply chain security, AI-enabled security tools.

Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗