Security Engineering Analyst — AppSec | Senior
Core
Strengthen application security across the software development lifecycle by defining secure practices, integrating automated controls into CI/CD pipelines, and supporting secure AWS architectures.
Role type
Senior AppSec Engineer (DevSecOps)
Builds
Secure software development lifecycle, automated security gates in CI/CD, and secure cloud architectures
Domain
Application Security, Cloud Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SSDLC, Secure Software Development, Security by Design, Threat Modeling, OWASP Top 10, OWASP ASVS, Secure Coding, API Security, Microservices Architecture, DevOps, CI/CD, DevSecOps, Application Vulnerability Management
Preferred skills
AWS API Gateway, AWS Security Hub
Technologies
SAST, DAST, SCA, Secret Scanning, IaC Scanning, Container Security, SBOM, AWS
Responsibilities
Define and improve corporate SSDLC; Establish and implement Security Gates in CI/CD pipelines; Conduct security assessments and threat modeling during architecture stages; Integrate security tools (SAST, DAST, SCA, etc.) into pipelines; Support secure architecture initiatives in AWS environments; Conduct security-focused code reviews and assess APIs/microservices.
Seniority
Senior, hands-on IC
