Application Security Engineer
Core
Application Security Engineer focusing on secure SDLC, application security reviews, and security monitoring for a global travel experiences platform.
Role type
Senior IC Application Security Engineer
Builds
Secure web/API applications, CI/CD security controls, and security monitoring/detection capabilities
Domain
Travel technology, Cloud Security, Application Security
Required skills
Application security, Secure SDLC, Web/API security, OWASP Top 10 mitigation, Threat modeling, CI/CD security controls (SAST/DAST/SCA), Python/Go/Java programming, AWS security (IAM/WAF/Kubernetes), Security monitoring/SIEM, Incident response, API security, Microservices security
Preferred skills
Penetration testing, Risk assessment, Security frameworks (NIST/PCI DSS/GDPR/SOC 2), AI-assisted security automation
Technologies
GitLab CI/CD, Elastic SIEM, AWS, Kubernetes, Python, Go, Java
Responsibilities
Perform application security reviews, code reviews, and threat modeling; Implement and maintain CI/CD security controls; Write automation for security workflows and tooling; Support incident response and alert triage; Provide guidance on secure coding and architecture; Participate in security on-call rotation
Seniority
Senior, hands-on IC
