Summary
What you’ll impact
The role is for an experienced Application Security Engineer who will design, build, and mature application security capabilities across a large-scale engineering organization. The engineer will collaborate with developers, architects, DevOps, cloud engineering, data science, and cybersecurity teams to identify security risks and implement automated controls throughout the software development lifecycle.
Responsibilities
What you'll do
- help design, build, and mature application security capabilities across a large-scale engineering organization.
- work closely with software developers, architects, DevOps, cloud engineering, data science, and cybersecurity teams to identify complex security risks and build scalable, automated controls throughout the software development lifecycle.
Requirements
What you’ll bring
- Strong professional experience in Application Security, AppSec Engineering, Cloud Security, Software Engineering, or a closely related discipline.
- Deep expertise in application security, secure software design, and technology risk management.
- Strong knowledge of: OWASP ASVS, OWASP Top 10, NIST SP 800-53. Secure SDLC / SSDLC, Threat modeling, Risk assessment and vulnerability management
- Extensive experience conducting complex security assessments across large-scale engineering environments.
- Demonstrated ability to design and implement automated security controls and security tooling.
- Proficiency in multiple programming languages, preferably including Python, Java, and JavaScript/TypeScript.
- Hands-on experience with SAST, DAST, SCA, IaC, container, API, and cloud security technologies.