Senior Application Security Engineer
Core
Lead the implementation and onboarding of Secure Code Scanning platforms across the software development lifecycle.
Role type
Senior IC application security engineer (secure code scanning)
Builds
Automated security scanning and policy enforcement integrated into CI/CD pipelines
Domain
Software development lifecycle + DevSecOps
Deliverable
production ML models | product features | infrastructure
Required skills
Secure Code Scanning platforms (Snyk, Fortify, Checkmarx, Veracode), CI/CD pipeline integration, SAST, vulnerability management, SDLC, DevSecOps
Preferred skills
GitHub, GitLab, risk prioritization, exception handling, SLA definition, secure coding practices
Technologies
Snyk, Fortify, Checkmarx, Veracode, GitHub, GitLab
Responsibilities
Design and implement integrations with GitHub, GitLab and CI/CD pipelines; Establish vulnerability management processes including triage and remediation tracking; Develop technical standards, deployment procedures, and operational runbooks; Provide hands-on support during implementation, testing, rollout, and post-go-live stabilization; Mentor development teams on secure coding practices.
Seniority
Senior, hands-on IC