Senior Security Engineer, Application
Core
Designing secure applications, assessing weaknesses, and supporting remediation efforts across the application security lifecycle.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Secure software development lifecycle programs and secure application environments
Domain
Financial services / Application security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
vulnerability scanning, threat modeling, risk assessment, cloud security (AWS/Azure/GCP), infrastructure as code, policy as code, compliance frameworks (SOC 2, ISO 27001, NIST 800-53), HIPAA/PHI/PCI knowledge, automation/scripting, secure SDLC implementation
Preferred skills
penetration testing, web application assessment, project leadership
Technologies
AWS, Azure, GCP, Bash, CI/CD, Java, JavaScript, PowerShell, Python, ASP.NET, C#, PHP, Perl, Ruby
Responsibilities
Manage and support application vulnerability scanning tools and cloud security technologies; collaborate with business partners to design secure applications; coordinate orchestration and automation of security platforms; prepare actionable security reports and track metrics via KRIs and scorecards; serve as subject matter expert for risk reviews and CI/CD triage; evaluate needs to implement security tools and processes; improve compliance processes.
Seniority
Senior, hands-on IC