Application Security Engineer
Core
Design and implement application security architecture and processes to safeguard software applications against novel threats and vulnerabilities throughout the software development lifecycle.
Role type
Senior Application Security Engineer
Builds
Secure software products and CI/CD pipelines for enterprise analytics and mobility software
Domain
Enterprise software security, AI/ML security, cloud security
Deliverable
production ML models | product features | infrastructure
Required skills
Threat modeling, secure code review, SAST/DAST/SCA tooling, API security, container security (Docker/Kubernetes), supply chain security, AI/ML adversarial attack mitigation, IaC security, cloud security (AWS/Azure/GCP)
Preferred skills
Exploit development, red teaming, security automation, mentoring security champions
Technologies
GitHub Advanced Security, Checkmarx, Fortify, Veracode, SonarQube, Burp Suite, ZAP, Terraform, CloudFormation, Python, Java, JavaScript, Docker, Kubernetes, AWS, Azure, GCP
Responsibilities
Design application security architecture; manage risk-balanced SDLC with threat modeling and secure code reviews; identify and remediate vulnerabilities via SAST/DAST/SCA; perform penetration testing and red teaming; lead DevSecOps initiatives; conduct security incident response; develop security training programs
Seniority
Senior, hands-on IC