2 дня назад
Senior Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (Cybersecurity): Designing and maintaining application and API security controls for mission-critical SaaS and hybrid cloud applications with an accent on secure SDLC practices, vulnerability management, and CI/CD security automation. Focus on integrating SAST, SCA, IAST, DAST, and secrets detection, conducting penetration testing, leading incident response, and improving security across complex multi-cloud environments.
Location: Remote within the United States; role is associated with Farmington Hills, Michigan
Company
Amerisure is a property and casualty insurance company serving mid-sized commercial enterprises in construction, manufacturing, and healthcare.
What you will do
- Design, implement, and maintain security controls for IT infrastructure, applications, and data.
- Establish secure development requirements, patterns, guardrails, and application and API security practices across engineering teams.
- Integrate and optimize SAST, SCA, IAST, DAST, and secrets detection tools within CI/CD pipelines, while tracking security metrics.
- Perform application and API security reviews, vulnerability assessments, penetration testing, and security tool tuning.
- Lead incident response and digital forensics investigations and coordinate remediation actions.
- Mentor security professionals and advise leadership on security strategy, emerging technologies, and regulatory alignment.
Requirements
- Bachelor’s degree or equivalent education and experience, with 7+ years of application and API security experience in a DevSecOps environment.
- At least one required certification such as CISSP, CSSLP, CCSP, GSEC, CEH, CISM, or CRISC, plus relevant platform or domain certifications.
- Expertise in secure SDLC, application and API security, container security, secure coding, OWASP Top 10, OWASP API Security Top 10, and CWE.
- Experience with TeamCity, Azure Pipelines, GitHub Actions, Bitbucket Pipelines, and automated security scanning in CI/CD.
- Experience with SonarQube, Black Duck, Synopsys Seeker, Snyk, and Wiz Code, as well as OAuth2, OIDC, JWT, mTLS, SSL/TLS, SSH, and PKI.
- Strong knowledge of vulnerability management, penetration testing, cloud security, cryptography, NIST CSF, MITRE ATT&CK, and applicable regulatory requirements.
Nice to have
- Experience in property and casualty insurance or another regulated industry.
- Familiarity with Guidewire, Salesforce, Databricks, and SnapLogic.
- Platform-specific certifications such as AWS, Microsoft, or Cisco, and domain certifications such as OSWE, OSCP, GWAPT, or GWEB.
- Experience leading initiatives with project management and Agile methodologies.
Culture & Benefits
- Remote work and flexible work arrangements supporting work-life balance.
- Competitive base pay and performance-based incentive pay.
- Health and welfare benefits, a 401(k) savings plan with profit sharing, and paid time off.
- Collaborative environment focused on professional growth and learning.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
AVP, Information Security (Cybersecurity)
4 дня назад
Senior Security Architect Vulnerability Management (AWS)
6 дней назад
Application Security Engineer (Cybersecurity)
86 900 - 198 000$
Apollo.io
3 часа назад
Senior Application Security Engineer (AI)
190 000 - 273 000$
5 часов назад
Senior Security Engineer, Application (Application Security)
96 700 - 145 000$
5 часов назад