Application Security Engineer
Core
Securing application code across the enterprise by identifying vulnerabilities early in the software development lifecycle through modern security scanning and tooling integrated into development workflows.
Role type
Application Security Engineer (IC)
Builds
Secure code practices embedded across the organization via CI/CD pipelines
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SAST, SCA, vulnerability detection at code level, CI/CD pipeline integration (Jenkins), Java-based application security, Docker/containerization, secure SDLC practices
Preferred skills
AI/LLM application security, Linux systems, threat modeling, developer enablement, broader DevOps/CI/CD ecosystem, AppSec platforms (Fortify, Black Duck, FOSSA)
Technologies
Jenkins, ServiceNow, Docker, Java, SAST, SCA, DAST, Fortify, Black Duck, FOSSA
Responsibilities
Configure and maintain application security tools within CI/CD pipelines; Perform application security scanning using SAST and SCA methodologies; Support development and expansion of DAST capabilities; Analyze, triage, and track vulnerabilities; Contribute to AI-focused application security initiatives; Maintain internal Java-based automation tools; Support infrastructure components across cloud, on-prem, and containerized environments
Seniority
Mid-Senior, hands-on IC