Snr Assoc, Application Security Engineer, Information Security Services, Group Technology
Core
Embedding security early in the SDLC, driving automation of security processes, and leveraging technologies like Python and Generative AI to enhance application security posture.
Role type
Senior Application Security Engineer
Builds
Secure software development lifecycle (SDLC) frameworks, automated security tools, and secure application deployments
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Secure coding principles, SAST/DAST/IAST tool interpretation, DevSecOps (CI/CD), Python development, OWASP Top 10 mitigation, Generative AI for security, Unix/Linux as code, vulnerability analysis, threat modeling
Preferred skills
Financial services experience, regulatory landscape familiarity, Generative AI concepts in cybersecurity
Technologies
Python, Go, Java, JavaScript/TypeScript, SAST, DAST, IAST, SCA, CI/CD, Unix/Linux
Responsibilities
Provide advisory on application security tools and processes, Drive integration of security activities into SDLC, Execute vulnerability analysis and root cause investigations, Develop automation scripts and tools using Python/Go, Explore and pilot Generative AI tools for security testing, Contribute to continuous improvement of secure SDLC framework, Train developers on secure coding practices
Seniority
Senior, hands-on IC
