Application Security Engineer
Core
Design, implement, and operate security controls to protect enterprise applications and services at scale, partnering with application owners and cloud teams to prevent, detect, and remediate risks across web apps, APIs, and SaaS solutions.
Role type
Senior Application Security Engineer
Builds
Security controls for internet-facing services, CI/CD guardrails, and operational dashboards
Domain
Semiconductor manufacturing / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
WAF configuration and operation, API security (OWASP Top 10), bot/DDoS mitigation, Identity and access management (MFA, IGA/PAM), SaaS security posture management (SSPM), vulnerability triage and remediation, CI/CD integration, scripting (Python/PowerShell), data egress monitoring
Preferred skills
CISSP/CCSP/GIAC certifications, enterprise platform experience (Akamai/F5 WAF, CyberArk, ServiceNow), CASB tools, AI/ML security (MLSecOps, LLMs)
Technologies
WAF, API gateways, IdPs, PAM, CMDB, Power BI, CASB, Python, PowerShell
Responsibilities
Deploy and operate WAF, API security, bot/DDoS mitigation, identity/MFA, egress/DLP/SSL inspection, and SSPM controls; Triage and remediate application and SaaS vulnerabilities; Build and maintain security standards and baseline policies; Integrate security checks into CI/CD processes; Develop and publish operational dashboards and metrics; Collaborate with engineering to troubleshoot complex issues; Monitor and respond to security incidents; Secure data egress and promote secure data handling practices; Support internal/external audits and close findings
Seniority
Senior, hands-on IC with moderate leadership