Senior Application Security Engineer
Core
Secure the software development lifecycle (SDLC) for financial applications by implementing security controls, testing initiatives, and automation.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Secure CI/CD pipelines, automated security testing (DAST/SAST/SCA), and secure container/serverless environments
Domain
Financial services / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
DAST tool deployment and CI/CD integration, SAST/SCA/IAST/RASP tooling, container and serverless security, API security, vulnerability management, secure SDLC strategy, technical mentorship, automation of security processes
Preferred skills
NIST/OWASP/MITRE standards knowledge, cloud security, AI/ML security strategies
Technologies
DAST, SAST, SCA, IAST, RASP, CI/CD pipelines, containers, serverless, cloud platforms
Responsibilities
Guide Application Security strategy and secure the SDLC; Drive API, Container, and Application Security testing initiatives; Develop strategies to secure emerging technologies (containers, serverless, API, AI/ML); Provide hands-on engineering support for security incidents and vulnerability management; Gather and report metrics on security coverage and risk reduction; Create and maintain technical standards and operational procedures; Provide technical mentorship and training to development teams; Implement and optimize Application Security solutions; Drive automation to improve developer experience and security processes
Seniority
Senior, hands-on IC with mentorship responsibilities