Application Security Engineer
Core
Expert Application Security Engineer providing advice, conducting assessments, and guiding government teams on integrating security into the software development lifecycle.
Role type
Senior IC Application Security Engineer
Builds
Secure software development practices and secure CI/CD pipelines for government clients
Domain
Government sector, Application Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk assessment, Threat modelling, Code review, Secure SDLC principles, CI/CD pipeline security review, Vulnerability assessment, Secure coding guidelines development, Mentoring development teams
Preferred skills
Experience with JavaScript, Node.js, Java, C#, Python
Technologies
SAST, DAST, VAPT
Responsibilities
Perform comprehensive risk assessments of development environments, DevOps workflows, and CI/CD processes. Perform security assessments, threat modelling, and code reviews to identify vulnerabilities. Review and recommend improvements in identity and access management, network security, and data protection. Guide application teams on adopting secure development practices and integrating security tools. Review existing CI/CD pipelines from a security perspective. Mentor and advise internal teams on secure coding practices.
Seniority
Senior, hands-on IC