Senior Security Engineer (Application Security)
Core
Lead application security initiatives across Tekion's automotive retail platform ecosystem, integrating security into the SDLC and empowering developers.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Secure-by-design principles, scalable application security controls, and security automation within CI/CD pipelines for web, mobile, APIs, and cloud-connected systems.
Domain
Automotive retail technology / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security fundamentals, DevSecOps integration, threat modeling, secure coding, security automation, CI/CD pipeline security, IaC scanning, API security, vulnerability management, secure architecture review, secure coding guidance development, developer enablement, programming/scripting (Python, Bash, Java, JavaScript, or Go)
Preferred skills
OWASP Top 10 and ASVS expertise, modern software assurance practices, code review experience, penetration testing interpretation
Technologies
SAST, DAST, SCA, secrets scanning, API security tools, CI/CD pipelines, IaC scanners
Responsibilities
Drive integration of security across all phases of the software development lifecycle; Lead threat modeling exercises and security design reviews for high-impact systems; Build and improve security automation within CI/CD pipelines; Review and prioritize application security findings from internal testing and third-party assessments; Develop secure coding guidance, patterns, and developer-facing best practices.
Seniority
Senior, hands-on IC
