Назад
Company hidden
7 дней назад

Staff Application Security Engineer (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Application Security Engineer (Cybersecurity): Building and maturing enterprise-wide secure SDLC, application-security, and software supply-chain security capabilities with an accent on DevSecOps integration, vulnerability management, and secure release controls. Focus on securing CI/CD pipelines, implementing SAST, DAST, SCA, SBOM, and artifact-integrity practices, and guiding engineering teams through threat modeling and remediation.

Location: Remote

Company

Enterprise Operations Division focused on cybersecurity, secure software development, and software supply-chain security.

What you will do

  • Establish and improve company-wide secure SDLC policies, standards, control objectives, procedures, and evidence requirements.
  • Assess engineering teams, source-control practices, CI/CD pipelines, build environments, and release processes, then lead practical improvement roadmaps.
  • Implement and operationalize SAST, DAST, SCA, secrets detection, infrastructure-as-code, container, API, and cloud-native security controls.
  • Lead threat modeling, security requirements definition, secure design reviews, architecture reviews, vulnerability management, and risk acceptance processes.
  • Mature software supply-chain security through SBOMs, VEX, build provenance, artifact signing, trusted promotion, secure registries, and SLSA-aligned controls.
  • Partner with developers, DevOps, platform engineering, leadership, auditors, and customers on remediation, security champions, reporting, disclosure, and assurance activities.

Requirements

  • Experience designing, implementing, or maturing secure SDLC or application-security programs across multiple engineering teams.
  • Strong knowledge of secure coding, application-security testing, vulnerability management, software delivery, and DevSecOps.
  • Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related tooling.
  • Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
  • Experience with threat modeling, security and architecture reviews, software supply-chain security, SBOMs, artifact signing, provenance, and open-source risk governance.
  • Ability to assess production code and scripts, explain technical risk and trade-offs, and communicate with technical and nontechnical stakeholders.

Nice to have

  • Experience with VEX, CSAF, SPDX, CycloneDX, cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
  • Experience with security, source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms and tools such as Snyk, Checkmarx, Veracode, Semgrep, SonarQube, OWASP ZAP, or Burp Suite.
  • Knowledge of NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or comparable regulated-environment requirements.
  • Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance products.
  • Relevant security certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, or cloud-security certifications.

Culture & Benefits

  • Remote full-time employee position.
  • Work across engineering, security, product, technology leadership, DevOps, and platform engineering.
  • Opportunity to build developer enablement through security champions, training, office hours, and reusable secure-development guidance.
  • Focus on measurable security controls, practical remediation, reduced false positives, and improved delivery workflows.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →