Назад
Company hidden
4 дня назад

Lead AppSec Engineer (Application Security)

116 000 - 170 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead AppSec Engineer (Application Security): Supporting application security through vulnerability assessments, threat modeling, risk prioritization, security tooling, and automation with an accent on DevSecOps, cloud security, and secure application design. Focus on triaging vulnerabilities, implementing AWS/Azure/GCP security controls, defining security metrics, and coordinating remediation across business and technology stakeholders.

Location: Hybrid environment near the Irving, Texas or Stamford, Connecticut Centers of Excellence, United States

Salary: $116,000–$170,000 USD annually, plus bonus or sales incentive eligibility

Company

hirify.global provides business and technology insights, digital solutions, and guidance to enterprise leaders worldwide.

What you will do

  • Design secure applications with business stakeholders, assess applications for security weaknesses, and coordinate remediation.
  • Mentor engineers and security champions on practical threat modeling techniques.
  • Triage and prioritize security risks, vulnerabilities, and exceptions according to business impact and risk tolerance.
  • Coordinate the orchestration, automation, and lifecycle management of application security technologies and platforms.
  • Create security posture reports, define KRIs and security scorecards, and use data to influence roadmap decisions.
  • Act as an application security subject-matter expert for risk assessments, critical issues, and CI/CD security triage.

Requirements

  • 6–8 years of experience in security engineering, including DevSecOps, cloud security, and application security.
  • Experience with vulnerability scanning technologies, AST platforms, and cloud security tooling.
  • Formal experience with threat modeling and risk assessment and prioritization.
  • Experience leading projects, initiatives, and resources through direct and indirect leadership.
  • Cloud experience with AWS, Azure, or GCP, plus knowledge of Infrastructure as Code and Policy as Code concepts.
  • Ability to work in a hybrid environment near the Irving or Stamford Centers of Excellence.

Nice to have

  • Knowledge of SOC 2, ISO 27001/27013, or NIST 800-53 frameworks.
  • Ability to automate tasks and develop solutions for repetitive problems.
  • Scripting or programming experience with Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, or Bash.
  • Experience with penetration testing and web application assessment.

Culture & Benefits

  • Hybrid flexibility combining remote work with collaboration in dynamic offices.
  • 20+ PTO days, holidays, and floating holidays during the first year.
  • Medical, dental, and vision insurance, plus wellness allowance programs.
  • 401(k) with corporate match and immediate vesting, including a match of up to $7,200 per year.
  • Learning and development programs, certification opportunities, tuition reimbursement, parental leave, and employee stock purchase options.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →