Application Security Engineer
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
Job Summary:
We are seeking a highly skilled and motivated Application Security Engineer to join our Information Security Team. The candidate will have a deep understanding of application security principle, practices, and technologies. You will be responsible for ensuring the security of our software applications by identifying and mitigating potential security risk, implementing best practices, and collaborating with cross-functional teams to integrate security into the software development lifecycle. They will navigate the complexities of modern technologies, fortify our systems against evolving threats, and uphold the integrity of our data and operations with precision and foresight.
Key Responsibilities:
Security Assessments: Conduct comprehensive security assessments of applications/API/mobile applications, including code reviews, vulnerability assessments, and penetration testing. Perform security testing (SAST, DAST, pen test) and vulnerability assessments to identify security strengths and weaknesses.
Threat Modeling: Develop and implement threat models to identify potential security issues early in the development process
Secure Development: Provide guidance and support to development teams on secure coding practices, security architecture, and the use of security tools
Incident Response: Investigate and respond to security incidents related to application vulnerabilities and provide remediation recommendations
Compliance and Standards: Ensure compliance with industry standards, regulations, and best practices (e.g. OWASP, NIST, ISO/IEC 27001)
Training and Awareness: Develop and deliver security training programs for developers and other stakeholders to promote security awareness and best practices.
Security Tooling: Implement and manage security tools and technologies to automate security testing and monitoring. Support Web Application Firewall Operation and new service onboarding.
Collaboration: Work closely with development, QA, and operations teams to integrate security into the continuous integration/continuous development (CI/CID) pipeline.
Documentation: Maintain detailed documentation of security assessments, incidents, and remediation activities. Prepare KPI and KRI for AppSec services.
Qualifications:
· Minimum 5 years of security engineering experience with a passion for information security; technical certifications such as CEH, CSSLP, or OSCP are required for this role
· Technical Skill:
Proficiency in programming languages such as Java, C#, Python, or JavaScript
Experience with security assessment tools such as OWASP ZAP, Burp Suite, AppSpider, Veracode, Semgrep, Data Theorem, Github advanced security, Snyk, Signal Science, Imperva, Cloud based WAF, etc.
Strong understanding of application security vulnerabilities (e.g., SQL Injection, XSS, CSRF) and mitigation techniques
Familiarity with cloud security (e.g. AWS, Azure) and container security (e.g., Docker, Kubernetes)
· Soft Skills:
Excellent problem-solving and analytical skills
Strong communication and collaboration abilities
Ability to work independently and as part of a team in a fast-paced environment
Preferred Qualifications:
Experience with DevSecOps practices and tools
Knowledge of microservices architecture and security implications
Understanding of identity and access management (IAM) principles
Job Type: Full-time
Pay: $90,000.00 - $110,000.00 per year
Benefits:
Dental insurance
Health insurance
Paid time off
Vision insurance
Schedule:
8 hour shift
Experience:
Linux: 5 years (Preferred)
Cybersecurity: 5 years (Required)
Information security: 5 years (Required)
Ability to Commute:
San Marino, CA (Required)
Ability to Relocate:
San Marino, CA: Relocate before starting work (Required)
Work Location: In person