Job Description & How to Apply Below
Job Title:
Application Security Engineer
Job Summary:
A Security Engineer will be responsible for ensuring the security and privacy of the company's products and services. This role will be vital in shaping the company's security strategy by working closely with development teams to identify, evaluate, and mitigate potential security risks and ensuring that all products are designed, built, and deployed with security as a critical consideration.
Roles and Responsibilities:
Embed security in all products and services, including architecture, development, deployment, and maintenance, through the SSDLC program.
Perform threat modeling, security reviews, code assessments, penetration testing, and overall application security evaluations.
Develop and implement security policies, standards, and guidelines to secure product development processes.
Identify and mitigate security risks across the product life cycle with practical solutions.
Continuously enhance the organization's security posture through technical improvements and process optimization.
Assist in incident response and support vulnerability remediation efforts with technical expertise.
Stay informed on emerging security threats and technologies, integrating improvements into the security strategy.
Drive the adoption of shift-left security practices, ensuring security is considered early in development.
Collaborate with Dev Ops and IT teams to integrate security into the CI/CD pipeline and drive security automation initiatives such as SAST, DAST, and IAST.
Measure and improve security maturity using different frameworks like the Dev Sec Ops Maturity Model.
Ensure compliance with industry standards and regulations such as ISO 27001, GDPR, and PCI DSS.
Promote security awareness across development teams and establish secure coding practices through continuous education.
Experience &
Skills:
Strong understanding of security principles and methodologies, with experience securing systems ficiency in application security engineering, vulnerability assessments, and incident response.
Expertise in web, mobile, and cloud security and familiarity with tools like OWASP and SANS frameworks.
Mobile Application Testing, API Security Testing, Web Application Testing, Cloud Security (AWS, GCP, Open Stack etc)
Strong problem-solving skills with the ability to address complex security issues.
Excellent communication and collaboration skills, with experience working across development and operations teams.
Expertise in ISO/IEC 27001, ISO 27017, ISO 27018, SOC 2, and PCI DSS is highly desirable.
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×