Application Security Engineer
Core
Improving security of internally developed applications and cloud services by integrating security throughout the software development lifecycle.
Role type
Application Security Engineer
Builds
Secure software development practices, secure CI/CD pipelines, and secure cloud-native services
Domain
Music industry, cloud-native technologies, application security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
application security assessments, threat modeling, secure design reviews, SAST, DAST, SCA, API security testing, secure coding guidance, CI/CD integration, authentication/authorization technologies (OAuth, OIDC, SAML), security architecture guidance, automation/scripting
Preferred skills
SSDLC in Agile, container security, Kubernetes, Infrastructure as Code security, Python/PowerShell scripting, cloud-native security assessments
Technologies
AWS, Azure, Google Cloud Platform, GitHub Advanced Security, Microsoft Defender for Cloud, Checkmarx, Veracode, Burp Suite, Semgrep, REST APIs, microservices, OAuth, OpenID Connect, SAML, JWT
Responsibilities
Perform application security assessments, threat modeling, and secure design reviews; Conduct application security testing using SAST, DAST, SCA, and API security testing; Review source code and provide secure coding guidance; Partner with engineering teams to identify risks and recommend remediation; Collaborate with DevOps to integrate security into CI/CD pipelines; Provide security architecture guidance for new applications and APIs; Support investigation and remediation of application-layer security incidents; Create reusable security guidance and technical documentation; Deliver secure coding guidance and developer education.
Seniority
Mid-Senior level, hands-on IC