Назад
Company hidden
15 часов назад

Senior Application Security Engineer (Cybersecurity)

109 500 - 208 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Cybersecurity): Implementing and administering application security testing and posture management tools, integrating them into CI/CD pipelines, and supporting development teams with vulnerability remediation with an accent on SAST, DAST, IAST, SCA, ASPM, and DevSecOps. Focus on scaling secure development workflows across cloud environments, triaging risks at scale, and solving complex application security challenges in large organizations.

Location: North Chicago, Illinois, United States

Salary: $109,500–$208,500 annually

Company

AbbVie discovers and delivers medicines and solutions for serious health issues across immunology, oncology, neuroscience, and aesthetics.

What you will do

  • Implement and maintain application security testing tools, including SAST, DAST, IAST, and SCA, to identify code and dependency vulnerabilities.
  • Implement and administer ASPM tools that centralize and deduplicate findings from multiple security solutions.
  • Integrate application security tooling into CI/CD pipelines and development workflows.
  • Support developers by resolving false positives, guiding remediation, and evaluating security exception requests.
  • Develop reports on security findings and remediation progress, and triage risks across application environments and business units.
  • Communicate security risks, promote secure development practices, and support development teams and management.

Requirements

  • Bachelor’s degree with 7 years of experience, master’s degree with 6 years, or PhD with 2 years; pharmaceutical industry experience is preferred.
  • Demonstrated experience in application security, software development, and implementing, administering, and supporting SAST, DAST, IAST, or SCA tooling.
  • Strong secure coding knowledge across multiple programming languages, especially Java and Node, and knowledge of OWASP Top 10, CWE, and vulnerability mitigation.
  • Experience integrating security testing into CI/CD pipelines and scaling DevSecOps practices in large organizations and cloud environments such as AWS and Azure.
  • Experience with Infrastructure as Code using Terraform or CloudFormation and supporting developers with application security findings.
  • Excellent written and oral English communication skills, including the ability to present technical findings to technical and non-technical stakeholders.

Nice to have

  • Experience with ASPM consolidation, Snyk, Endor Labs, or CSPM integration.
  • Python or other scripting experience for workflow automation.
  • Experience building pipeline logging and collaborating with vulnerability and risk management partners.

Culture & Benefits

  • Paid time off, including vacation, holidays, and sick leave.
  • Medical, dental, and vision insurance for eligible employees.
  • 401(k) benefits for eligible employees.
  • Eligibility for long-term incentive programs.
  • Opportunity to coach and support junior engineers while championing secure development practices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →