Назад
Company hidden
1 день назад

Info Protection Advisor – Application Security Engineer (AppSec)

155 958 - 171 900$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Info Protection Advisor – Application Security Engineer (AppSec) (Cloud Security/DevSecOps): Securing cloud-hosted and open-source applications by integrating application security throughout the software development lifecycle with an accent on secure code reviews, vulnerability assessment, and CI/CD security controls. Focus on embedding SAST, SCA, and DAST remediation, strengthening identity and access controls, and securing containerized applications against application-level threats.

Location: Bloomfield, Connecticut, United States; hybrid work with telecommuting permitted.

Salary: $155,958–$171,900 per year. A separate compensation statement lists an anticipated range of $103,100–$171,900 per year, depending on experience and geographic location.

Company

hirify.global provides healthcare and health services through Cigna Healthcare and Evernorth Health Services.

What you will do

  • Collaborate with software development teams to integrate application security into product design and the software development lifecycle.
  • Inspect application code and repositories for security issues and conduct secure code reviews and application security assessments.
  • Build and manage automated security controls in CI/CD pipelines using DevSecOps practices.
  • Assess application risks, security architecture, design gaps, and compliance with NIST and ISO 27001 standards.
  • Support vulnerability remediation from SAST, SCA, and DAST tools and educate development teams on secure coding.
  • Help secure cloud-hosted and containerized applications and respond to application-level security incidents.

Requirements

  • Bachelor’s degree in Computer Science or a related field and 5 years of relevant experience.
  • Experience integrating security across every phase of the software development lifecycle and identifying threats early in design.
  • Experience with SAST, DAST, secure coding standards including OWASP Top 10 and SEI CERT, and vulnerability remediation.
  • Knowledge of secure identity management, including OAuth, SAML, JWT, authentication, authorization, and role-based controls.
  • Experience with GitHub Actions and Jenkins for DevSecOps integration, as well as cloud and container security.
  • For home working, a cable broadband or fiber optic connection with at least 10 Mbps download and 5 Mbps upload is required.

Culture & Benefits

  • Full-time employment with telecommuting permitted in a hybrid arrangement.
  • Medical, vision, dental, well-being, and behavioral health programs starting on the first day of employment.
  • 401(k), company-paid life insurance, tuition reimbursement, paid holidays, and leaves of absence.
  • At least 18 days of paid time off per year.
  • Eligibility for participation in an annual bonus plan.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →