duvari group · Saint Louis, MO

Salary
$150,000
Posted
Jun 29, 2026
Location
Saint Louis, MO
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hands-on engineering role focused on embedding security into cloud-native applications and AI systems. Day-to-day work spans configuring and automating security testing tools (SAST, DAST, SCA, API, and AI-specific), integrating controls into CI/CD pipelines, reviewing AI platforms and models for risk, and guiding development teams on secure coding practices. Best suited to someone with a software development background who wants to build security capabilities rather than just audit for gaps.

Senior level · National · Full-time

Must have (6)
application securityC# or Pythonthreat modelingvulnerability managementAWS, Azure or GCPCI/CD
Nice to have (5)
SASTDASTGitHubAzure DevOpsLLMs

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
vulnerability management55%C#51%CI/CD45%application security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

No work location or metro area is specified in the posting; CBSA is left blank. The role is described as direct hire (full-time) but no remote/hybrid policy is stated — remote is defaulted to false.

SOC classification is a genuine judgment call: the role sits at the intersection of security engineering (15-1212) and software/DevSecOps engineering (15-1252). The emphasis on building/automating security tooling and a required software development background pulls toward 15-1252, but the primary framing — AppSec, vulnerability management, AI security reviews, and security posture — tips it to 15-1212.

AWS is listed under Required as 'preferably AWS', making it a hard gate on cloud experience with AWS as the named preference; Azure and GCP are noted as alternatives a hiring manager would likely accept.

C# and Python appear together under Required as 'ideally with languages such as C# or Python or similar object-oriented languages' — treated as a hard gate on OO development experience with C# as primary and Python as the named alternative.

SAST, DAST, SCA, GitHub, Azure DevOps, LLMs, and Azure appear only in the 'technologies that may include' stack narrative section, not in the Required block, so they are treated as preferred context rather than hard gates.

No total years of experience, degree requirement, compensation, or security clearance is stated in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗