Application Security Engineer
Core
Expert Application Security Engineer providing advice, conducting assessments, and guiding teams to build security into the software development lifecycle for a government project.
Role type
Senior IC Application Security Engineer
Builds
Secure software development lifecycle (SSDLC) practices, secure CI/CD pipelines, and secure coding guidelines for government applications.
Domain
Government sector, Application Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security, DevSecOps, Secure SDLC, Threat modeling, Code review, Vulnerability assessment, Risk assessment, CI/CD security, Identity and access management, Cryptographic key handling
Preferred skills
Secure coding guidelines development, Mentoring development teams, SAST/DAST/VAPT integration
Technologies
JavaScript, Node.js, Java, C#, Python, SAST, DAST, VAPT
Responsibilities
Perform comprehensive risk assessments of development environments and CI/CD processes; Conduct security assessments, threat modeling, and code reviews; Review and recommend improvements in IAM, network security, and data protection; Guide teams on adopting secure development practices and integrating security tools; Review CI/CD pipelines for security alignment; Mentor teams on secure coding practices across various platforms.
Seniority
Senior, hands-on IC with advisory focus