{"schemaVersion":"jobsearcher.job.v1","id":"aade979ee3e636ad3d5e7479","url":"https://jobsearcher.com/jobs/aade979ee3e636ad3d5e7479","canonicalUrl":"https://jobsearcher.com/jobs/aade979ee3e636ad3d5e7479","title":"Application Security Engineer, Information Security","description":"Ascensus is the leading independent technology and service platform powering savings plans across America, providing products and expertise that help nearly 16 million people save for a better today and tomorrow.Section 1: Position SummaryReporting to the BISO, the Application Security Engineer is responsible for the application security program. This position requires a passion for data protection, possesses a combination of either application development and/or security experience, strong communication and organizational skills, collaborative abilities, self-motivation, innovation, efficiency and attention to detail. This position will perform a variety of application security responsibilities across Ascensus and be the primary resource for our application security program. This role serves as a trusted application security advisor to Ascensus scrum teams to drive best practices for application security, to help ensure the confidentiality, integrity and availability of our web and application program interfaces (API). The Application Security Engineer is deeply involved with our application scrum teams and is instrumental in helping define the strategy to meet the information security organizations high level goals, while still being embedded within the scrum team processes and serve as a subject matter expert in secure development practices. This is a critical role at Ascensus requiring strategic thinking, taking initiative, and proactive interaction at many levels. This role will receive strong support of the Head of Technology and the Information Security Leadership, to effectively execute on defined organizational goals and strategic plans.Section 2: Job Functions, Essential Duties and ResponsibilitiesResponsible for protecting, securing, and proper handling of all confidential data held by Ascensus to ensure against unauthorized access, improper transmission, and/or unapproved disclosure of information that could result in harm to Ascensus or our clients. Our I-Client service philosophy and our Core Values of People Matter, Quality First and Integrity Always® should be visible in your actions on a day to day basis showing your support of our organizationIn conjunction with security and development leadership develops a comprehensive, agile, and innovative DevSecOps approach that supports all phases of the software development lifecycle (SDLC), identifies and effectively manage risk. Provide security consultation to scrum teams, application owners, and technology teams on relevant security controls and secure SDLC processParticipate in sprint planning meetings and various decision-making sessions to ensure that security requirements and considerations are built into the development practicesConduct application security analysis, including architecture review, analysis of data flows, penetration testing support, and threat modelingBuild and monitor compliance with application security policies, coding standards, and security controls in support of mitigating threatsResponsible for the deployment and integration of services to support SAST, DAST and SCA functions. Assist development teams in performance of static and dynamic testing, triage findings and provide remediation guidance where necessaryAssist with other tasks and projects as assignedSupervision N/ASection 3: Experience, Skills, Knowledge Requirements Secure Software DevelopmentA minimum of 4 years’ experience in Secure Software Development and/or DevSecOps (preferred)Ability to define software security and privacy requirementsSolid understanding of threat modeling, risk, and mitigation from internal and external threatsExperience with development of system security architecture diagrams and security architecture specification per security architecture standardsExperience performing software security design reviewsExperience running security testing tools into a CI/CD pipeline including tools such as Static and Dynamic Application SecurityTesting (SAST/DAST) and Software Composition Analysis (SCA)Experience with application testing tools (e.g., Burp Suite, Fiddler, Zap, Wireshark, Metasploit)Experience with configuration WAF, API Gateway, API Security ToolsSolid understanding of the most common application and API security risks (OWASP Top 10, SANS/CWE Top 25)Solid understanding of application, database and network vulnerability testing principlesWorking knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM)Experience with assessing secure adoption of third-party components such as open source or commercial software .NET/Java Experience a plusInformation SecurityUnderstanding of information security frameworks such as ISO27001, NIST, CSA and operating in a environment regulated against FFIEC, SEC and/or HIPAA requirementsSolid understanding f authentication and authorization systemsSolid understanding of cryptographic standards(e.g., encryption, hashing, key management, digital signatures, etc.) Ability to provide vulnerability remediation guidance and mentoring to product development software engineersAbility to translate security risks to business impactExperience running or managing vulnerability assessments using automated tools (e.g., Nessus, Qualys, etc) as well as managing penetration testing engagements. Understanding of privacy regulations as it relates to the handling and protection of information. Experience with fraud detection and analysis as it relates to custom developed applicationsDevSecOpsExperience integrating automated testing tools into a CI/CD pipelineExperience in implementing Cloud security controls following owing Cloud Security Alliance (CSA) or Cloud Service Provider (CSP) best practices (Azure, AWS, etc.)Experience implementing and supporting security automation tools (e.g., K8 and CSP platform configuration, hardening, and monitoring). We are proud to be an Equal Opportunity EmployerBe aware of employment fraud. All email communications from Ascensus or its hiring managers originate from @ascensus.com or @futureplan.com email addresses. We will never ask you for payment or require you to purchase any equipment. If you are suspicious or unsure about validity of a job posting, we strongly encourage you to apply directly through our website.","company":"Ascensus","rawCompany":"ascensus","city":"Dresher","state":"PA","isRemote":false,"isActive":true,"createdAt":"2026-09-19T08:52:50.476Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer, Information Security","description":"Ascensus is the leading independent technology and service platform powering savings plans across America, providing products and expertise that help nearly 16 million people save for a better today and tomorrow.Section 1: Position SummaryReporting to the BISO, the Application Security Engineer is responsible for the application security program. This position requires a passion for data protection, possesses a combination of either application development and/or security experience, strong communication and organizational skills, collaborative abilities, self-motivation, innovation, efficiency and attention to detail. This position will perform a variety of application security responsibilities across Ascensus and be the primary resource for our application security program. This role serves as a trusted application security advisor to Ascensus scrum teams to drive best practices for application security, to help ensure the confidentiality, integrity and availability of our web and application program interfaces (API). The Application Security Engineer is deeply involved with our application scrum teams and is instrumental in helping define the strategy to meet the information security organizations high level goals, while still being embedded within the scrum team processes and serve as a subject matter expert in secure development practices. This is a critical role at Ascensus requiring strategic thinking, taking initiative, and proactive interaction at many levels. This role will receive strong support of the Head of Technology and the Information Security Leadership, to effectively execute on defined organizational goals and strategic plans.Section 2: Job Functions, Essential Duties and ResponsibilitiesResponsible for protecting, securing, and proper handling of all confidential data held by Ascensus to ensure against unauthorized access, improper transmission, and/or unapproved disclosure of information that could result in harm to Ascensus or our clients. Our I-Client service philosophy and our Core Values of People Matter, Quality First and Integrity Always® should be visible in your actions on a day to day basis showing your support of our organizationIn conjunction with security and development leadership develops a comprehensive, agile, and innovative DevSecOps approach that supports all phases of the software development lifecycle (SDLC), identifies and effectively manage risk. Provide security consultation to scrum teams, application owners, and technology teams on relevant security controls and secure SDLC processParticipate in sprint planning meetings and various decision-making sessions to ensure that security requirements and considerations are built into the development practicesConduct application security analysis, including architecture review, analysis of data flows, penetration testing support, and threat modelingBuild and monitor compliance with application security policies, coding standards, and security controls in support of mitigating threatsResponsible for the deployment and integration of services to support SAST, DAST and SCA functions. Assist development teams in performance of static and dynamic testing, triage findings and provide remediation guidance where necessaryAssist with other tasks and projects as assignedSupervision N/ASection 3: Experience, Skills, Knowledge Requirements Secure Software DevelopmentA minimum of 4 years’ experience in Secure Software Development and/or DevSecOps (preferred)Ability to define software security and privacy requirementsSolid understanding of threat modeling, risk, and mitigation from internal and external threatsExperience with development of system security architecture diagrams and security architecture specification per security architecture standardsExperience performing software security design reviewsExperience running security testing tools into a CI/CD pipeline including tools such as Static and Dynamic Application SecurityTesting (SAST/DAST) and Software Composition Analysis (SCA)Experience with application testing tools (e.g., Burp Suite, Fiddler, Zap, Wireshark, Metasploit)Experience with configuration WAF, API Gateway, API Security ToolsSolid understanding of the most common application and API security risks (OWASP Top 10, SANS/CWE Top 25)Solid understanding of application, database and network vulnerability testing principlesWorking knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM)Experience with assessing secure adoption of third-party components such as open source or commercial software .NET/Java Experience a plusInformation SecurityUnderstanding of information security frameworks such as ISO27001, NIST, CSA and operating in a environment regulated against FFIEC, SEC and/or HIPAA requirementsSolid understanding f authentication and authorization systemsSolid understanding of cryptographic standards(e.g., encryption, hashing, key management, digital signatures, etc.) Ability to provide vulnerability remediation guidance and mentoring to product development software engineersAbility to translate security risks to business impactExperience running or managing vulnerability assessments using automated tools (e.g., Nessus, Qualys, etc) as well as managing penetration testing engagements. Understanding of privacy regulations as it relates to the handling and protection of information. Experience with fraud detection and analysis as it relates to custom developed applicationsDevSecOpsExperience integrating automated testing tools into a CI/CD pipelineExperience in implementing Cloud security controls following owing Cloud Security Alliance (CSA) or Cloud Service Provider (CSP) best practices (Azure, AWS, etc.)Experience implementing and supporting security automation tools (e.g., K8 and CSP platform configuration, hardening, and monitoring). We are proud to be an Equal Opportunity EmployerBe aware of employment fraud. All email communications from Ascensus or its hiring managers originate from @ascensus.com or @futureplan.com email addresses. We will never ask you for payment or require you to purchase any equipment. If you are suspicious or unsure about validity of a job posting, we strongly encourage you to apply directly through our website.","datePosted":"2026-09-19T08:52:50.476Z","dateModified":"2026-09-19T08:52:50.476Z","hiringOrganization":{"@type":"Organization","name":"Ascensus","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dresher","addressRegion":"PA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"aade979ee3e636ad3d5e7479"},"url":"https://jobsearcher.com/jobs/aade979ee3e636ad3d5e7479"}}