Application Security Engineer, Vice President
Core
Conduct comprehensive application security testing and vulnerability management across the software development lifecycle to enhance the security posture of enterprise applications.
Role type
Senior IC application security engineer (vulnerability management & secure coding)
Builds
Secure enterprise applications and CI/CD pipelines
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security testing (DAST/SAST/SCA), Secure coding (Java/Python/.NET), Vulnerability remediation, CI/CD integration, Scripting (Python/Bash/PowerShell), Compliance frameworks (NIST/PCI-DSS/SOX)
Preferred skills
AI/ML security (LLM/prompt injection), Cloud security (AWS/Azure/Oracle), OSCP/OSWE/GWAPT/CEH certifications
Technologies
Invicti, Veracode, Burp Suite, Java, Python, .NET, AWS, Azure, Oracle Cloud
Responsibilities
Conduct DAST scans using Invicti to identify vulnerabilities in applications; Conduct SAST scans using Veracode to identify vulnerabilities in source code; Conduct SCA scans using Veracode to identify vulnerabilities in open-source components; Integrate security testing into CI/CD pipelines and DevOps workflows; Write scripts and code in Java and Python for security engineering and automation; Collaborate with developers to remediate security flaws and reinforce secure coding practices
Seniority
Senior, hands-on IC
