Application Security Engineer (Secure SDLC)
Core
Partner with software engineering teams to embed security throughout the Secure Software Development Lifecycle (SSDLC) by integrating security into CI/CD pipelines, supporting cloud-native security, and enabling secure code practices.
Role type
Application Security Engineer II (DevSecOps)
Builds
Secure software delivery pipelines, automated security controls, and secure cloud-native applications
Domain
Application Security, DevSecOps, Cloud Security (AWS/Azure)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Secure SDLC integration, SAST/DAST/SCA tooling, CI/CD pipeline security, cloud-native security (AWS/Azure), secure code review, threat modeling (OWASP ASVS/STRIDE), vulnerability remediation, programming languages (Java/C#/Python/JavaScript/TypeScript/Go)
Preferred skills
Infrastructure as Code (Terraform/CloudFormation/Bicep), container security (Docker/Kubernetes), AI/LLM security, security champion programs, compliance standards (LGPD/GDPR/PCI DSS/ISO 27001), authentication/API security (OAuth 2.0/OpenID Connect/JWT)
Technologies
GitHub Actions, Azure DevOps, GitLab CI, Jenkins, AWS, Azure, Docker, Kubernetes, Terraform, CloudFormation, Bicep
Responsibilities
Partner with engineering teams to identify and remediate application security risks; Implement and maintain application security tooling in CI/CD pipelines; Support secure code reviews and provide secure coding guidance; Review penetration testing findings and validate remediation; Contribute to security automation and reusable security controls; Collaborate with DevOps on IaC workflows; Assist with application security reviews for cloud-native services and APIs; Evaluate emerging technologies like AI-enabled applications for security risks; Contribute to security governance and documentation; Maintain security monitoring and vulnerability reporting processes; Collaborate with Privacy, Compliance, Legal, and IT teams on data protection initiatives.
Seniority
Mid-level, hands-on IC