Назад
3 дня назад

Application Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

Application Security Engineer.

Location:
#London.
Salary: Competitive.
Employer: Visa.

Responsibilities:
• Review and triage findings from application security tooling, including SAST, DAST, SCA, and container scanning solutions.
• Provide technical guidance to development teams to support remediation of vulnerabilities and improve security posture.
• Conduct or support penetration testing and targeted security assessments where appropriate.
• Review and escalate critical application security risks to the appropriate technical and business stakeholders.
• Support engineering teams in understanding and meeting Visa security standards and requirements.
• Provide coaching, best practices, and security knowledge sharing to promote secure development across the organization.
• Deliver training sessions for technical and non-technical groups on application security topics and processes.
• Contribute to continuous improvement of application security processes, tooling, and standards.
• Support exception management, including reviewing risk acceptance submissions and documenting decisions.
• Assist with compliance and evidencing requirements related to application security activities.
• Because this role involves close collaboration with other teams and hands-on work within the Application Security team, you will be expected to demonstrate practical coding skills.
• Partner closely with development, DevOps, infrastructure, and product stakeholders to drive secure design and remediation outcomes.
• Share expertise and mentor other members of the Application Security team.
• Participate in relevant cross-functional forums (e.g., BCWG) where application security topics arise.

Requirements:
• Bachelor's degree in Computer Science, Information Security, or related field-or equivalent hands-on experience.
• Demonstrable experience in application security engineering, secure development, vulnerability management, or related security domain.
• Familiarity with common AppSec tooling: SAST, DAST, SCA, container scanning, and cloud security tools.
• Experience supporting compliance or regulatory requirements (e.g., PCI DSS).
• Relevant certifications (e.g., OSCP, OSWE, GWAPT, CISSP) are desirable.



#Гибрид #AppSec

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -