Application Security Engineer - CTEM, 12 Month Fixed Term Contract
Core
Strengthen application security maturity and scale practices across API, Platform, Data, Investment, and Digital Engineering teams.
Role type
Application Security Engineer (CTEM)
Builds
Secure SDLC controls, GitHub source-control security, and vulnerability management workflows.
Domain
Financial services / Application Security
Required skills
SAST/DAST/SCA scanning, API security, container security, infrastructure-as-code security, OWASP Top 10, CWEs, software supply-chain risk, secure SDLC controls, GitHub security governance, vulnerability management, risk-based prioritization
Technologies
GitHub, SAST, DAST, SCA, API security tools, container scanning, IaC scanners (via careerplan.io/jobs/a687e7b0-d1ca-49b6-9786-1cc0c3158219-application-security-engineer-ctem-12-month-fixed-term-contract-at-rest)
Responsibilities
Triage and prioritize application security findings from various tooling; Provide remediation guidance and maintain traceability for security findings; Govern GitHub source-control security and integrations; Monitor remediation backlog health and trends; Coordinate secure SDLC controls across the engineering lifecycle; Validate remediation and manage risk exemptions.
Seniority
Mid-level, hands-on IC
