4 дня назад
Lead AppSec Engineer (Application Security)
116 000 - 170 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead AppSec Engineer (Application Security): Supporting application security through vulnerability assessments, threat modeling, risk prioritization, security tooling, and automation with an accent on DevSecOps, cloud security, and secure application design. Focus on triaging vulnerabilities, implementing AWS/Azure/GCP security controls, defining security metrics, and coordinating remediation across business and technology stakeholders.
Location: Hybrid environment near the Irving, Texas or Stamford, Connecticut Centers of Excellence, United States
Salary: $116,000–$170,000 USD annually, plus bonus or sales incentive eligibility
Company
provides business and technology insights, digital solutions, and guidance to enterprise leaders worldwide.
What you will do
- Design secure applications with business stakeholders, assess applications for security weaknesses, and coordinate remediation.
- Mentor engineers and security champions on practical threat modeling techniques.
- Triage and prioritize security risks, vulnerabilities, and exceptions according to business impact and risk tolerance.
- Coordinate the orchestration, automation, and lifecycle management of application security technologies and platforms.
- Create security posture reports, define KRIs and security scorecards, and use data to influence roadmap decisions.
- Act as an application security subject-matter expert for risk assessments, critical issues, and CI/CD security triage.
Requirements
- 6–8 years of experience in security engineering, including DevSecOps, cloud security, and application security.
- Experience with vulnerability scanning technologies, AST platforms, and cloud security tooling.
- Formal experience with threat modeling and risk assessment and prioritization.
- Experience leading projects, initiatives, and resources through direct and indirect leadership.
- Cloud experience with AWS, Azure, or GCP, plus knowledge of Infrastructure as Code and Policy as Code concepts.
- Ability to work in a hybrid environment near the Irving or Stamford Centers of Excellence.
Nice to have
- Knowledge of SOC 2, ISO 27001/27013, or NIST 800-53 frameworks.
- Ability to automate tasks and develop solutions for repetitive problems.
- Scripting or programming experience with Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, or Bash.
- Experience with penetration testing and web application assessment.
Culture & Benefits
- Hybrid flexibility combining remote work with collaboration in dynamic offices.
- 20+ PTO days, holidays, and floating holidays during the first year.
- Medical, dental, and vision insurance, plus wellness allowance programs.
- 401(k) with corporate match and immediate vesting, including a match of up to $7,200 per year.
- Learning and development programs, certification opportunities, tuition reimbursement, parental leave, and employee stock purchase options.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Security Engineer (Application Security)
120 000 - 140 000$
4 дня назад
Infrastructure Cyber Defense Leader (Azure/AWS)
187 000 - 270 000$
10 дней назад
Product Security Engineer (AI)
175 000 - 200 000$
WRITER
4 дня назад
Staff Security Engineer Application Security (AI)
183 000 - 240 000$
9 дней назад
Senior Application Security Engineer (AI)
160 300 - 240 500$
10 дней назад
Principal Application Security Engineer (Cybersecurity)
163 625 - 211 750$