Application Security Engineer
Core
Safeguarding the city's digital infrastructure by identifying, analyzing, and mitigating security risks across software applications.
Role type
Application Security Engineer (IC) (via careerplan.io/jobs/3743990015911176-application-security-engineer-at-city-of-new-york)
Builds
Secure web applications, APIs, and mobile systems for over 100 NYC agencies
Domain
Public sector cybersecurity / Software Security Assurance
Required skills
SAST, DAST, SCA, threat modeling, secure coding guidance, CI/CD pipeline integration, API security review
Preferred skills
DevSecOps practices, vendor solution security review, secure coding guidelines development
Technologies
GitHub Actions, Azure DevOps, GitLab, OAuth, REST
Responsibilities
Execute application security assessments to verify security standards prior to deployment; Perform SAST, DAST, and manual security reviews to validate vulnerabilities; Operate SCA tools to monitor and remediate open-source component vulnerabilities; Conduct threat modeling and logic reviews during the design phase; Serve as technical point of contact for agency development teams; Assist in integrating automated security scanning tools into CI/CD pipelines; Conduct security reviews of third-party vendor solutions and web APIs.
Seniority
Mid-level, hands-on IC
