Senior Application Security Engineer
Core
Senior Application Security Engineer responsible for implementing and maintaining application security testing (AST) and posture management (ASPM) tools, integrating them into CI/CD pipelines, and supporting development teams in remediating vulnerabilities.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Inline code testing and reporting processes, centralized security findings dashboards, and automated security workflows within CI/CD pipelines.
Domain
Pharmaceutical industry + Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security testing (SAST, DAST, IAST, SCA), Application Security Posture Management (ASPM), CI/CD pipeline integration, Secure coding practices (Java, Node.js), OWASP Top 10/CWE knowledge, DevSecOps practices, Infrastructure as Code (Terraform, CloudFormation), Cloud environments (AWS, Azure), Vulnerability triage and risk management, Technical communication and stakeholder management, Mentoring junior engineers
Preferred skills
Consolidating security findings from multiple sources, Snyk and Endor Labs administration, Cloud Security Posture Management (CSPM) integration, Python scripting for automation, Logging into DevSecOps pipelines, Collaboration with risk management partners
Technologies
SAST, DAST, IAST, SCA, ASPM, CI/CD, Terraform, CloudFormation, AWS, Azure, Snyk, Endor Labs, Python
Responsibilities
Implement and maintain AST tools to identify code and dependency vulnerabilities; Integrate security tooling with CI/CD pipelines; Act as first line of support for resolving false positives and evaluating security exceptions; Develop detailed reports on security findings and remediation efforts; Demonstrate proficiency across application security technologies, software design, containerization, and cloud environments; Coach and support the development of junior engineers
Seniority
Senior, hands-on IC with strategic influence