Application Security Engineer
Core
Ensure secure software deployment by partnering with product teams to identify, analyze, and mitigate security vulnerabilities throughout the SDLC.
Role type
Application Security Engineer
Builds
Trustworthy and robust software products
Domain
Cybersecurity / Web Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
threat modeling, manual code review, secure code review, vulnerability triage, security automation scripting, secure architecture design, OWASP Top 10 mitigation, secure coding guidelines development
Preferred skills
DevSecOps, SAST/DAST tool customization, bug bounty program participation, CTF participation, network and OS security knowledge
Technologies
HTTP/HTTPS, cookies, session management, SOP, CORS, CSP
Responsibilities
Partner with product teams for threat modeling and risk assessment; Perform manual code reviews for logical vulnerabilities; Tune automated security scanning rulesets; Develop security automation scripts; Assist developers in understanding security risks; Triage bug bounty vulnerabilities; Collaborate with Dev/QA for security consulting and knowledge sharing; Maintain internal security knowledge base and secure coding guidelines
Seniority
Mid-level, hands-on IC
