Application Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (AWS): Building and managing application and cloud security capabilities from the ground up with an accent on AWS security services, CSPM via Wiz, and secure code scanning pipelines. Focus on integrating SAST/DAST into CI/CD, automating vulnerability management, and embedding security practices across engineering teams.
Location: Remote (US, EST); must be authorized to work for any employer in the U.S. (no visa sponsorship)
Salary: $110,000 - $120,000 annually
Company
applies AI Digital Twin technology exclusively toward metabolic health to prevent and improve chronic diseases like type 2 diabetes and obesity.
What you will do
- Design, implement, and manage AWS security tooling including Security Hub, GuardDuty, Inspector, and Macie with automation.
- Lead deployment and configuration of Wiz CSPM, enhancing visibility and remediation workflows with infrastructure and DevOps.
- Manage secure code scanning with SAST/DAST via Sonar Cloud, identifying vulnerabilities early in SDLC.
- Develop automated pipelines for vulnerability triage, remediation tracking, and metrics reporting (MTTD, MTTR).
- Embed security into CI/CD pipelines, promote secure coding, and contribute to threat modeling and code reviews.
- Align with SOC 2, HIPAA, SOX controls; support incident response, vendor assessments, and penetration testing.
Requirements
- Bachelor’s in Computer Science, Information Security or equivalent; 1-3+ years in AppSec, DevSecOps, or Cloud Security
- Hands-on with AWS security services (Security Hub, GuardDuty, Inspector, Macie, IAM, KMS)
- Experience integrating SAST/DAST (Sonar Cloud, etc.) into CI/CD; familiarity with Wiz or similar CSPM
- Familiarity with Docker, K8S, microservices, WAF, endpoint security, IAM
- Strong SSDLC knowledge (OWASP Top 10, CWE, CVSS); proficiency in Python/Bash scripting and Java
- Threat modeling, code review, cloud best practices; excellent collaboration skills
Nice to have
- Experience with SOC 2, HIPAA, HiTrust compliance
- High-growth or regulated environment experience
Culture & Benefits
- Remote global team with high flexibility
- Competitive compensation with equity participation
- Unlimited vacation (manager approval); 16 weeks paid parental leave for delivering parents, 8 weeks for non-delivering
- 100% employer-sponsored healthcare, dental, vision; HSA/FSA options; 401k plan
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →