Application Security Engineer - Associate
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-01-27
-
IT/Tech
Cybersecurity
Application Security Engineer - Associate
Join to apply for the Application Security Engineer - Associate role at SMBC Group.
SMBC Group is a top‑tier global financial group headquartered in Tokyo with a 400‑year history. It offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group and one of the three largest banking groups in Japan.
SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges. In the Americas, SMBC Group operates in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru, providing commercial and investment banking services to corporate, institutional, and municipal clients.
This role is part of a team responsible for administering security projects designed to safeguard Capital Market’s information systems. The Application Security Engineer works closely with the development community to ensure that any code being developed follows the prescribed SDLC process and enterprise policies. The engineer serves as a subject‑matter expert, using their expertise to resolve complex problems in consideration of established policies, guidelines, and processes.
Key responsibilities include ensuring all code scanning vulnerabilities follow organizational policies, working closely with developers to fix issues before releasing code to production, and maintaining a strong development background to read and explain code deficiencies to stakeholders across various programming and scripting languages.
- Strong ability to work with stakeholders and explain code issues and fixes to the development community.
- Work closely with developers on a day‑to‑day basis to ensure all projects follow the SDLC process and all code in the environment is scanned and reported, focusing on SAST, SCA, and container security issues.
- Manage respective code scanning tools in the stack and handle day‑to‑day operational management of the tools.
- Interface with development and security architecture teams on topics related to application security such as vulnerability remediation, best practices, and threat modeling.
- Interface with the vulnerability management team to ensure vulnerabilities identified are reported and validated according to SLAs.
- Develop KPIs and metrics related to application security risk in close collaboration with the Americas Division Application Security and Testing teams.
- Publish and present high‑level management reports on the State of App Sec Program within Capital Markets and Nikko entities.
- Perform manual testing activities to validate vulnerability or penetration testing findings.
- Weekend and night work may be required at times based on project, support, and business needs.
- 3+ years of experience as a developer with a strong focus on Application Security.
- Development background with one or more of the following languages: C#, C++, Java, Python, .NET.
- Ability to read and understand code deficiencies – required.
- Ability to write code fixes for stakeholders and create automation scripts to support internal cybersecurity projects.
- Experience developing and maturing CI/CD pipelines with a focus on code quality and vulnerability detection.
- 2+ years of experience with Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST).
- 2+ years of experience with container security issues and container technologies.
- Through understanding of the components of the Secure Software Development Lifecycle.
- Strong knowledge of OWASP Top 10 or CWE.
- Understanding of common software threats and mitigations.
- Must be process‑ and detail‑oriented, with the ability to create detailed process documentation.
- Experience with Jira and Confluence.
- Bug bounty and/or penetration testing experience is a bonus.
SMBC’s employees participate in a hybrid workforce model that provides the opportunity to work from home as well as from an SMBC office. Employees are required to live within a reasonable commuting distance of their office location. Prospective candidates will learn more about the specific hybrid work schedule during the interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA‑registered roles that require in‑office attendance for the entire workweek.
SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at
- Associate
- Full‑time
- Information Technology
- Banking, Financial Services, IT Services and IT Consulting
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).