{"schemaVersion":"jobsearcher.job.v1","id":"b7f5fae6da4a583c03faad84","url":"https://jobsearcher.com/jobs/b7f5fae6da4a583c03faad84","canonicalUrl":"https://jobsearcher.com/jobs/b7f5fae6da4a583c03faad84","title":"Application Security Engineer","description":"Security AnalystKey Responsibilities (with Technologies): Conduct in-depth security testing on front-end web and mobile apps to uncover vulnerabilities and enforce strong security controls. Technologies: OWASP ZAP, Burp Suite, MobSF, Appium, Selenium, Postman, Charles Proxy Partner with the GraphQL (GQL) team to integrate security protocols and ensure secure data flow. Technologies: GraphQL, Postman, Insomnia, JWT, OAuth 2.0, API Gateway, Kong Apply knowledge of eSIM, SIM/device swaps to identify and mitigate telecom-specific threats. Technologies: eUICC, GSMA standards, SIMalliance tools, Wireshark, QXDM, QCAT Analyze business logic and coding practices to uncover fraud risks; validate scenarios through end-to-end testing. Technologies: Splunk, Kibana, ELK Stack, Python, SQL, Fraud Management Systems (e.g., Actimize, SAS) Adopt a hacker's mindset to identify abuse cases and differentiate between legitimate and malicious user journeys. Technologies: Kali Linux, Metasploit, Burp Suite, OWASP Juice Shop, Threat Modeling Tools (e.g., Microsoft Threat Modeling Tool) Use real-world breach tactics to refine testing strategies. Technologies: SET (Social-Engineer Toolkit), Gophish, OSINT tools (e.g., Maltego, Recon-ng) Utilize tools to track secure data flow and support fraud/security initiatives. Technologies: Wireshark, Fiddler, tcpdump, Splunk, ELK Stack Develop and maintain security policies, procedures, and training. Technologies: NIST, ISO/IEC 27001, CIS Benchmarks, Confluence, SharePoint Apply industry best practices and technologies to secure software and business processes. Technologies: OWASP ASVS, DevSecOps pipelines (e.g., Jenkins, GitHub Actions), Snyk, SonarQube Evaluate compliance with industry standards and recommend improvements. Technologies: Nessus, OpenVAS, Qualys, Compliance Management Tools (e.g., RSA Archer) Regularly assess and adapt security measures to evolving threats. Technologies: Threat intelligence platforms (e.g., Recorded Future, MISP), CVE databases, SIEM tools Build automated security checks using BDD frameworks like Karate or similar tools. Technologies: Karate, Cucumber, Selenium, Cypress, Jenkins, GitLab CI/CD","company":"My3Tech","rawCompany":"my3tech","city":"Englewood","state":"CO","isRemote":false,"isActive":true,"createdAt":"2026-06-14T11:00:33.540Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer","description":"Security AnalystKey Responsibilities (with Technologies): Conduct in-depth security testing on front-end web and mobile apps to uncover vulnerabilities and enforce strong security controls. Technologies: OWASP ZAP, Burp Suite, MobSF, Appium, Selenium, Postman, Charles Proxy Partner with the GraphQL (GQL) team to integrate security protocols and ensure secure data flow. Technologies: GraphQL, Postman, Insomnia, JWT, OAuth 2.0, API Gateway, Kong Apply knowledge of eSIM, SIM/device swaps to identify and mitigate telecom-specific threats. Technologies: eUICC, GSMA standards, SIMalliance tools, Wireshark, QXDM, QCAT Analyze business logic and coding practices to uncover fraud risks; validate scenarios through end-to-end testing. Technologies: Splunk, Kibana, ELK Stack, Python, SQL, Fraud Management Systems (e.g., Actimize, SAS) Adopt a hacker's mindset to identify abuse cases and differentiate between legitimate and malicious user journeys. Technologies: Kali Linux, Metasploit, Burp Suite, OWASP Juice Shop, Threat Modeling Tools (e.g., Microsoft Threat Modeling Tool) Use real-world breach tactics to refine testing strategies. Technologies: SET (Social-Engineer Toolkit), Gophish, OSINT tools (e.g., Maltego, Recon-ng) Utilize tools to track secure data flow and support fraud/security initiatives. Technologies: Wireshark, Fiddler, tcpdump, Splunk, ELK Stack Develop and maintain security policies, procedures, and training. Technologies: NIST, ISO/IEC 27001, CIS Benchmarks, Confluence, SharePoint Apply industry best practices and technologies to secure software and business processes. Technologies: OWASP ASVS, DevSecOps pipelines (e.g., Jenkins, GitHub Actions), Snyk, SonarQube Evaluate compliance with industry standards and recommend improvements. Technologies: Nessus, OpenVAS, Qualys, Compliance Management Tools (e.g., RSA Archer) Regularly assess and adapt security measures to evolving threats. Technologies: Threat intelligence platforms (e.g., Recorded Future, MISP), CVE databases, SIEM tools Build automated security checks using BDD frameworks like Karate or similar tools. Technologies: Karate, Cucumber, Selenium, Cypress, Jenkins, GitLab CI/CD","datePosted":"2026-06-14T11:00:33.540Z","dateModified":"2026-06-14T11:00:33.540Z","hiringOrganization":{"@type":"Organization","name":"My3Tech","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Englewood","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"b7f5fae6da4a583c03faad84"},"url":"https://jobsearcher.com/jobs/b7f5fae6da4a583c03faad84"}}