Application Security Engineer
Core
Ensuring the security of software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams to integrate security into the SDLC.
Role type
Application Security Engineer
Builds
ASPM tools and rules, secure coding guidelines, and security automation
Domain
Cloud infrastructure for AI, software development lifecycle
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability assessment, penetration testing, secure coding, threat modeling, risk assessment, authentication protocols (SAML/OIDC), security testing tools (Burp Suite, ZAP, Semgrep), OWASP Top 10 mitigation
Preferred skills
Security automation design, compliance translation, web application exploitation, Linux kernel/container/network exploitation
Technologies
Python, Go, Java, JavaScript, Burp Suite, ZAP, Semgrep, SAML, OIDC
Responsibilities
Build and maintain ASPM tools and their rules; Identify, analyze, and remediate application security vulnerabilities; Collaborate with development teams to integrate security best practices into the SDLC; Conduct manual and automated penetration testing of applications; Develop and maintain secure coding guidelines for development teams; Facilitate threat modeling and risk assessments on new and existing applications
Seniority
Mid-Senior, hands-on IC