AI-Driven Application Security Triage Engineer at Buckeye Global
Canton, OH
$166,400–$187,200
Jul 13, 2026
Canton, OH
Jul 20, 2026
What this job asks for AI summary
A contract application security role centered on triaging findings from SCA, SAST, and DAST tools, coordinating responses to critical patch events and threat intelligence escalations, and producing remediation guidance for development teams. The work also involves hands-on engineering and evaluation of AI-assisted security tooling using frontier models, alongside hardening the software supply chain — covering open-source dependencies, SBOMs, developer IDEs, plugins, and CI/CD integrations. Suits someone with at least three years of code, open-source, and dynamic/static scanning experience who is comfortable bridging security engineering and AI tooling.
Mid level · 3+ years · Remote · Contract
Pay in the description: $90/hr
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 9,400 people nationally plausibly meet what this posting asks for (information security analysts). range 2,750–14,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (11)
The role sits at the intersection of application security analysis (15-1212) and security-focused testing/scanning (15-1253); it was classified as 15-1212 because the primary day-to-day work is vulnerability triage, threat-intel response, and security tooling engineering rather than pure QA test execution.
The three 'Must-Have Experience' items (code scanning, open-source scanning, dynamic and static scanning) each carry a 3-year minimum; these map to SCA, SAST, and DAST respectively.
The 'Qualifications' section describes an engineering background in scripting, automation, APIs, CI/CD, and developer tooling as a required track record — these are treated as hard gates consistent with the requirements framing.
AI-enabled security tools, frontier models, and coding assistants appear under 'Qualifications' with 'hands-on familiarity' language; treated as required given the section placement, though the softer phrasing was noted.
No degree requirement is stated anywhere in the posting.
The role is a 1-year W2 contract with potential extension, classified accordingly as Contract.
No CBSA/location is specified beyond 'Remote'; the role is US-based (W2 engagement implies US employment).
Seniority is assessed as Mid (3+ years minimum, independent triage and escalation ownership) rather than Senior — the scope is well-defined and bounded to a single functional area without evidence of broad org-wide technical leadership.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): AI-enabled security tools.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.