About the job
Join our dynamic Information Security Team as an Application Security Engineer. In this role, you will collaborate with software development teams, product owners, and key stakeholders to establish, implement, and uphold robust security measures throughout the software development lifecycle (SDLC).
Your primary responsibility will be to identify and mitigate security vulnerabilities within applications, systems, and APIs, ensuring adherence to secure coding practices and compliance with industry security standards such as OWASP Top 10, NIST, and ISO/IEC 27001.
This position is vital in enhancing the organization’s security framework, advocating for security best practices, and safeguarding the integrity of our software applications.
Key Responsibilities:
- Conduct thorough security assessments of applications, including code reviews, static/dynamic analysis, and penetration testing.
- Work alongside development teams to design and implement security controls, integrating security into the SDLC.
- Lead efforts to identify and remediate security vulnerabilities in applications, APIs, and third-party services.
- Provide expert security guidance on secure coding practices, threat modeling, and vulnerability management to development teams.
- Implement and enforce best practices for secure coding, API security, and encryption across application architectures.
- Stay informed about the latest security threats, vulnerabilities, and trends, applying this knowledge to minimize risks.
- Develop and maintain automated security testing tools, frameworks, and processes for continuous integration within CI/CD pipelines.
- Assist in risk assessments and threat modeling for new and existing applications, prioritizing security remediation efforts.
- Participate in incident response activities related to application security, offering expertise to investigate and address security breaches.
- Create and deliver security training and awareness programs for developers to foster a security-first culture.
- Support vulnerability management and remediation efforts, ensuring resolution of identified issues.
- Ensure compliance with internal security standards and external regulatory requirements (e.g., GDPR, PCI-DSS, HIPAA).
- Collaborate with cross-functional teams, including DevOps, infrastructure, and security operations, to ensure a unified approach to application security.
