Senior Application Security Engineer
The Senior Application Security Engineer acts as a technical authority. This role ensures secure design, development, deployment, and integrity across both on-prem and SaaS environments. You should be comfortable wearing multiple hats and thrive in a fast-paced, collaborative environment.
WHAT YOU'LL BE DOING
- Define and mature secure SDLC and AppSec program frameworks.
- Embed secure coding practices into development and backend platform engineering.
- Lead threat modeling and high-risk security reviews for major releases.
- Implement application security testing tools (e.g. SCA, ASPM), container scanning, and secrets detection in CI/CD pipelines.
- Perform Penetration Testing and manage external penetration testing efforts
- Manage application vulnerabilities from identification to remediation.
- Provide guidance for development teams.
- Design, maintain, and enforce organization-wide paved roads and guardrails
- 5+ years in application security, secure architecture, or related functions.
- Demonstrated ability to influence senior engineering and product leadership.
- Proven implementation of CI/CD security automation and secure coding practices.
- Strong understanding of web, API, and microservice security.
- Experience with Java, Javascript.
- Experience in Penetration Testing
