Назад
Company hidden
2 дня назад

Senior Application Security Engineer (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Cybersecurity): Designing and maintaining application and API security controls for mission-critical SaaS and hybrid cloud applications with an accent on secure SDLC practices, vulnerability management, and CI/CD security automation. Focus on integrating SAST, SCA, IAST, DAST, and secrets detection, conducting penetration testing, leading incident response, and improving security across complex multi-cloud environments.

Location: Remote within the United States; role is associated with Farmington Hills, Michigan

Company

Amerisure is a property and casualty insurance company serving mid-sized commercial enterprises in construction, manufacturing, and healthcare.

What you will do

  • Design, implement, and maintain security controls for IT infrastructure, applications, and data.
  • Establish secure development requirements, patterns, guardrails, and application and API security practices across engineering teams.
  • Integrate and optimize SAST, SCA, IAST, DAST, and secrets detection tools within CI/CD pipelines, while tracking security metrics.
  • Perform application and API security reviews, vulnerability assessments, penetration testing, and security tool tuning.
  • Lead incident response and digital forensics investigations and coordinate remediation actions.
  • Mentor security professionals and advise leadership on security strategy, emerging technologies, and regulatory alignment.

Requirements

  • Bachelor’s degree or equivalent education and experience, with 7+ years of application and API security experience in a DevSecOps environment.
  • At least one required certification such as CISSP, CSSLP, CCSP, GSEC, CEH, CISM, or CRISC, plus relevant platform or domain certifications.
  • Expertise in secure SDLC, application and API security, container security, secure coding, OWASP Top 10, OWASP API Security Top 10, and CWE.
  • Experience with TeamCity, Azure Pipelines, GitHub Actions, Bitbucket Pipelines, and automated security scanning in CI/CD.
  • Experience with SonarQube, Black Duck, Synopsys Seeker, Snyk, and Wiz Code, as well as OAuth2, OIDC, JWT, mTLS, SSL/TLS, SSH, and PKI.
  • Strong knowledge of vulnerability management, penetration testing, cloud security, cryptography, NIST CSF, MITRE ATT&CK, and applicable regulatory requirements.

Nice to have

  • Experience in property and casualty insurance or another regulated industry.
  • Familiarity with Guidewire, Salesforce, Databricks, and SnapLogic.
  • Platform-specific certifications such as AWS, Microsoft, or Cisco, and domain certifications such as OSWE, OSCP, GWAPT, or GWEB.
  • Experience leading initiatives with project management and Agile methodologies.

Culture & Benefits

  • Remote work and flexible work arrangements supporting work-life balance.
  • Competitive base pay and performance-based incentive pay.
  • Health and welfare benefits, a 401(k) savings plan with profit sharing, and paid time off.
  • Collaborative environment focused on professional growth and learning.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →