Summary
What you’ll impact
The Senior Application Security Engineer will partner with enterprise software engineering squads to embed security throughout the development lifecycle, automate security gates in CI/CD pipelines, and lead vulnerability remediation. The role involves hands‑on application security work, including manual testing, code review, and development of metrics dashboards, on a 13‑month full‑time contract.
Responsibilities
What you'll do
- Embed Secure SDLC & DevSecOps: Define and automate security gates, vulnerability standards, and Definition of Done criteria across Agile engineering pipelines.
- Tooling & Repository Security: Manage and optimize repository scanning coverage—including SAST, SCA, dependency review, and secret scanning via GitHub Advanced Security and CodeQL.
- Exploit Validation & Penetration Testing: Conduct manual security testing and triage findings using Burp Suite and API testing suites to distinguish actionable business risks from false positives.
- Code-Level Remediation: Collaborate with developers to review, test, and patch application code in Java and Python across cloud and on-premise workloads.
- Metrics & Modern Capabilities: Develop vulnerability reduction dashboards for leadership and champion the safe adoption of AI-assisted security and development tools.
Requirements
What you’ll bring
- 5–7+ years of hands-on experience in Application Security, DevSecOps, or Software Engineering with a strong security focus.
- Deep technical knowledge of OWASP Top 10, API Security Top 10, authentication/authorization protocols (OAuth, OIDC, SAML), and secure coding standards.
- Proven experience with AppSec tooling: GitHub Advanced Security (GHAS), CodeQL, SAST/DAST, SCA, and Burp Suite.
- Proficiency in reading, debugging, and modifying code in Java and Python.
- Solid grasp of cloud security concepts, modern containerized architectures, and CI/CD automation.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.