Senior Application Security Engineer
Core
Establish and mature the secure software development lifecycle (SSDLC) and DevSecOps program for a national law firm, embedding security into cloud-native applications and CI/CD pipelines.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Secure CI/CD pipelines, automated security testing workflows, and secure development patterns for Azure-hosted services.
Domain
Legal services / Application Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security review, threat modeling, secure architecture assessment, SAST/DAST/SCA/IaC scanning, vulnerability triage, secure coding principles, OWASP Top 10, scripting/automation, CI/CD pipeline integration
Preferred skills
Secure SDLC practices, developer enablement, Security Champions program management, low-code/no-code platform security
Technologies
Azure DevOps, Snyk, SonarQube, PowerShell, Python, .NET, JavaScript, React, PHP, Azure cloud services, Containers/Kubernetes, Databricks, MongoDB, Power Platform
Responsibilities
Lead the organization's SSDLC program; integrate security tooling into CI/CD workflows; administer security scanning tools; collaborate with cloud teams to secure Azure-hosted applications; deliver developer-focused training and mentorship.
Seniority
Senior, hands-on IC

