Назад
Company hidden
1 день назад

Senior Application Security Engineer (Pharmaceutical)

109 500 - 208 500$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (SAST/DAST/DevSecOps): Implementing and administering application security testing and posture management tooling, integrating security controls into CI/CD pipelines, and supporting development teams with vulnerability remediation with an accent on secure coding, cloud environments, and scalable DevSecOps practices. Focus on consolidating and triaging security findings, building infrastructure as code, and solving complex application security challenges across large development environments.

Location: North Chicago, Illinois, United States

Salary: $109,500–$208,500 USD annually

Company

hirify.global develops medicines and healthcare solutions across areas including immunology, oncology, neuroscience, and aesthetics.

What you will do

  • Implement and maintain application security testing tools, including SAST, DAST, IAST, and SCA.
  • Implement and administer ASPM tools to consolidate and deduplicate findings from multiple security solutions.
  • Integrate security tooling into CI/CD pipelines and development workflows.
  • Support developers by investigating false positives, guiding remediation, and evaluating security exceptions.
  • Develop reports on security findings and remediation efforts, and triage risks across application environments and business units.
  • Communicate security risks, promote secure development practices, and coach junior engineers.

Requirements

  • Bachelor’s degree with 7 years of experience, master’s degree with 6 years, or PhD with 2 years; pharmaceutical industry experience is preferred.
  • Experience in application security, software development, and administration of SAST, DAST, IAST, or SCA tooling.
  • Knowledge of secure coding across multiple programming languages, especially Java and Node, plus OWASP Top 10, CWE, and vulnerability mitigation.
  • Experience scaling DevSecOps practices, integrating security testing into CI/CD pipelines, and working with AWS or Azure cloud environments.
  • Experience developing infrastructure as code with Terraform or CloudFormation and supporting developers with security findings.
  • Excellent written and oral English communication skills required. Ability to communicate with technical and non-technical stakeholders and operate as a principal engineer.

Nice to have

  • Experience with ASPM or other tooling that consolidates application security findings and integrates with development tracking systems.
  • Experience administering Snyk and Endor Labs.
  • Experience integrating CSPM tooling with application security pipelines.
  • Python or other scripting experience, including automation and DevSecOps pipeline logging.
  • Experience collaborating with vulnerability and risk management teams.

Culture & Benefits

  • Paid vacation, holidays, and sick leave.
  • Medical, dental, and vision insurance for eligible employees.
  • 401(k) benefits for eligible employees.
  • Eligibility to participate in long-term incentive programs.
  • Focus on integrity, innovation, and improving patient lives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →