Application Security Engineer
Core
Design and execute application security strategy to protect the software development lifecycle, focusing on API, container, and application security testing.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Secure software delivery pipelines and enterprise application security posture
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
DAST tool deployment and configuration, SAST/SCA/IAST/RASP tooling, CI/CD integration, container security, serverless security, API security, vulnerability management, secure development practices, technical standards creation, team mentorship
Preferred skills
NIST/OWASP/MITRE framework knowledge, DevSecOps certifications, cloud security certifications, AI/ML security knowledge
Technologies
AI, API, CI/CD, Cloud, DevSecOps, OWASP, Serverless
Responsibilities
Lead API, container, and application security testing initiatives; develop approaches to secure emerging technologies; provide hands-on engineering support for security incidents and vulnerability management; collect and report metrics on security coverage and risk reduction; create and maintain technical standards and operational procedures; mentor development and cloud engineering teams on secure practices; implement and operationalize Application Security solutions; drive automation to enhance developer experience; stay current on emerging security trends and attack techniques.
Seniority
Senior, hands-on IC with strategic influence