обновлено 3 дня назад
Senior Application Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (Java/Python/Go, Cloud Security): Securing internet-facing financial software and APIs through hands-on code analysis, vulnerability remediation, and Secure SDLC improvements with an accent on secure code review, threat modeling, and developer enablement. Focus on reproducing vulnerabilities, assessing exploitability and reachability, tuning SAST/DAST/SCA tooling, and building preventative controls across AWS and Kubernetes environments.
Location: Remote, United States
Company
develops digital and biometric identity authentication, fraud prevention, and mobile deposit solutions for organizations worldwide.
What you will do
- Perform hands-on security analysis and secure code reviews across applications, services, APIs, and supporting components.
- Work directly in Java, Python, and Go codebases to identify vulnerabilities, trace root causes, assess exploitability, and guide remediation.
- Own vulnerability remediation from discovery and prioritization through retesting, validation, and closure.
- Mature Secure SDLC gates, threat modeling, security requirements, and preventative controls in CI/CD workflows.
- Operate and tune SAST, DAST, and SCA tooling, including dependency and supply-chain security processes.
- Partner with Engineering on cloud-native application security across AWS, Kubernetes/EKS, containers, and Linux environments.
Requirements
- 7+ years of experience in Application Security, Product Security, security-focused software engineering, or a related discipline.
- Senior-level ownership of Application Security initiatives and vulnerability remediation.
- Strong coding and secure code review experience in Java, Python, and Go.
- Experience with SAST, DAST, SCA, software dependency security, OWASP Top 10, and OWASP API Security risks.
- Experience with STRIDE, PASTA, or similar threat-modeling methodologies.
- Experience securing cloud-native applications in AWS and Kubernetes/EKS, with strong communication skills for working with developers and engineering leadership.
Nice to have
- Application or API penetration-testing experience.
- Financial services, fintech, identity, fraud, regulated SaaS, or PCI-DSS experience.
- Experience building a Security Champions program or AppSec automation.
- OSCP, GWEB, CSSLP, or a similar technical security certification.
Culture & Benefits
- Virtual-first work model with remote work from a home office and access to company offices.
- Ownership of the Application Security function with executive visibility and direct collaboration with IT, Security, and Engineering leadership.
- Healthcare options, retirement or pension contributions, stock plan participation, life and disability coverage, and paid time off.
- Learning resources, tuition reimbursement, hackathons, and a home office setup allowance.
- Opportunity to secure internet-facing financial software with complex API integrations and US/EU regulatory considerations.
Hiring process
- The hiring process includes an in-person meeting.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Application Security Engineer (AI)
111 000 - 144 400$
Contentsquare
7 дней назад
Application Security Engineer (AppSec)
ДОМ.РФ
10 дней назад
Эксперт направления Application Security
6 дней назад
Application Security Engineer - Vice President (API Security)
Cohere
8 дней назад
Senior Product Security Engineer (AI)
260 000 - 385 000CAD
10 дней назад