Apply

Application Security Engineer

Posted 2024-11-23

View full description

πŸ“ Location: United States

πŸͺ„ Skills: Communication SkillsAnalytical SkillsCollaborationProblem SolvingAttention to detailOrganizational skillsPresentation skillsTime ManagementWritten communication

Requirements:
  • U.S. citizenship is required
  • Ability to obtain a Public Trust before starting the position
Responsibilities:
  • Work hand-in-hand with the Federal client
  • Ensure security for highly visible applications
  • Provide technical and operational subject matter expertise
  • Support services to partners and clients
Apply

Related Jobs

Apply

πŸ“ United States

🧭 Full-Time

πŸ” Dating products

  • Technical background in security with experience in writing security-adjacent code.
  • Creative approaches in performing quick and impactful work.

  • Help ensure the highest standard of security for Match Group products.
  • Work spans across applications, infrastructure, devices, vendors, and anything else potentially at risk.

PythonSoftware DevelopmentCybersecurityCommunication SkillsAnalytical SkillsCollaborationProblem SolvingAttention to detailOrganizational skillsTime ManagementWritten communicationDocumentation

Posted 2024-11-13
Apply
Apply

πŸ“ USA

πŸ” Dating products

NOT STATED

  • Lead collaborations across various teams to develop security priorities.
  • Design and execute security measures impacting user-facing platforms.
  • Ensure the highest standard of security for Match Group products and members.

LeadershipCybersecurityCross-functional Team LeadershipCommunication SkillsAnalytical SkillsCollaboration

Posted 2024-11-09
Apply
Apply

πŸ“ US

🧭 Full-Time

πŸ’Έ 188000 - 230000 USD per year

πŸ” Mental healthcare technology

🏒 Company: Headway

  • 5+ years experience in security and/or software engineering roles with a focus on security-related projects.
  • Strong cross-functional collaboration skills.
  • Technical experience in building secure platforms and products.
  • Ability to tackle ambiguous problems in a fast-paced environment.
  • Drive innovation in security and privacy technologies.

  • Partner with Product and Engineering teams to implement secure features and conduct security reviews.
  • Develop and improve automated tooling for application security.
  • Define and build application guardrails for secure development.
  • Assist in ongoing security operations including incident response and vulnerability management.

AWSPythonKafkaTypeScriptFastAPIPostgresProduct designRedisReactSpark

Posted 2024-11-07
Apply
Apply

πŸ“ New York City, California, Colorado, Washington

πŸ’Έ 160000 - 200000 USD per year

πŸ” Visual collaboration software

  • 5+ years experience in a product security focused role.
  • Experience with product security at a multi-tenant SaaS company preferred.
  • Experience with vulnerability management.
  • Deep understanding of web application and mobile application security risks.
  • Deep understanding of Linux, Networking, Cryptography, and Cloud Architecture fundamentals.
  • Software development experience with Node.JS or other frameworks like React, Angular, etc. is preferred.
  • Familiarity with MongoDB, Node.JS, Ruby, and/or Python is preferred.
  • Excellent command of English, both written and verbal.

  • Performing security reviews of Mural product features and architecture.
  • Manage and operate our bug bounty program.
  • Lead penetration testing and manage any risks to remediation.
  • Implementation and operation of SAST and DAST technologies in the CI workflow.
  • Working closely with Engineering teams to track and manage product risks to remediation.
  • Working closely with Engineering to increase coverage of security testing.
  • Communicating and nurturing relationships with security researchers, customers, and other stakeholders.
  • Producing metrics to help track the health of our product vulnerability management strategy.
  • Educating and evangelizing secure coding best practices.

Node.jsSoftware DevelopmentMongoDBRubyStrategyAngularReactLinux

Posted 2024-10-25
Apply
Apply

πŸ“ San Diego, San Mateo, United States

🧭 Internship

πŸ’Έ $41.50 - $50 per hour

πŸ” Entertainment, Gaming

🏒 Company: PlayStation Global

  • Must be enrolled in an accredited university, pursuing an undergraduate degree in Information Security or a related field, with an expected graduation by Spring 2026.
  • Knowledge of penetration testing or related security practices.
  • Basic understanding of software development, with the ability to read code to identify security issues (software engineering experience is not required).
  • Strong communication and collaboration skills, with the ability to work effectively with engineering teams.

  • Collaborate with engineers, consultants, and leadership to identify security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC).
  • Validate security controls to ensure compliance with industry best practices.
  • Perform manual security testing on products and services to proactively identify vulnerabilities and work with developers to resolve them.
  • Manage vulnerabilities identified by SAST, SCA, and DAST tools, guiding the development teams from triage to remediation.
  • Investigate and triage vulnerabilities reported through the Responsible Disclosure program.
  • Work closely with development teams, providing guidance and support for the remediation of security issues across applications, services, and other areas.
  • Recommend and communicate remediation guidelines for vulnerabilities to developers and other technical teams.

CybersecurityCommunication SkillsAnalytical SkillsCollaboration

Posted 2024-10-16
Apply
Apply

πŸ“ United States, Northeast region

🧭 Full-Time

πŸ’Έ $160,000 - $200,000 per year

πŸ” Artificial Intelligence, Cybersecurity

🏒 Company: Blackbird.AI

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
  • Minimum of 10 years of experience in application security engineering.
  • Proven experience in achieving security certifications such as SOC2, FEDRAMP, GDPR.
  • Deep understanding of AWS services and security best practices.
  • Strong knowledge of security principles, practices, and technologies related to AWS and Kubernetes.
  • In-depth understanding of web, API, and microservices security.
  • Expertise in cloud infrastructure security, especially AWS services like IAM, EC2, S3, and Lambda.
  • Solid grasp of common security vulnerabilities and mitigation techniques, especially in containerized environments.
  • Familiarity with DevSecOps practices and CI/CD pipelines.
  • Hands-on experience with security tools such as SAST/DAST, vulnerability scanners, and penetration testing frameworks.
  • Proficient in security assessment tools and methodologies.
  • Strong knowledge of compliance frameworks and standards.
  • Familiarity with programming languages such as Python, Go, or Java.

  • Develop and implement a comprehensive application security strategy aligned with company objectives.
  • Lead initiatives to achieve security certifications, including SOC 2, FEDRAMP, GDPR compliance.
  • Collaborate with cross-functional teams to integrate security best practices into all stages of the Software Development Lifecycle (SDLC).
  • Assess and enhance the security of applications hosted in AWS and Kubernetes environments.
  • Conduct regular security assessments, code reviews, and vulnerability scans.
  • Implement security controls and policies to protect against threats and vulnerabilities.
  • Prepare and lead efforts to achieve SOC 2 certification and maintain compliance.
  • Coordinate with external auditors and ensure all security documentation is up-to-date.
  • Plan and oversee regular penetration testing activities and analyze test results.
  • Provide training and mentorship on secure coding practices.

AWSDockerLeadershipPythonSoftware DevelopmentJavaKubernetesStrategyGoCommunication SkillsCI/CD

Posted 2024-09-20
Apply
Apply

πŸ“ Australia, Austria, Bangladesh, Belgium, Brazil, Canada, Colombia, Costa Rica, Croatia, Czech Republic, Denmark, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, India, Indonesia, Ireland, Israel, Italy, Kenya, Mexico, Netherlands, Nigeria, Peru, Poland, Singapore, South Africa, Spain, Sweden, Switzerland, Uganda, United Arab Emirates, United Kingdom, United States of America, Uruguay

🧭 Full-Time

πŸ’Έ 109047 - 169455 USD per year

πŸ” Nonprofit, Technology, Open Source

  • Two or more years of application security experience, with knowledge of OWASP Top Ten and CWE Top 25
  • Strong understanding of modern, object-oriented PHP development
  • In-depth experience developing or auditing JavaScript
  • Demonstrated ability to exploit and mitigate application-level vulnerabilities
  • Experience conducting software security reviews using source code inspection, manual testing, and automated scanning
  • Ability to explain security issues to non-technical audiences
  • Sensitivity to security challenges in large, international projects
  • Strong understanding of cryptography in web application security
  • Experience using Linux for web application development and deployment tasks
  • Ability to maintain focus while working remotely

  • Triage and remediate reported security issues
  • Review and deploy features developed by the Foundation and community members
  • Work with other development teams to ensure safe architectural and implementation choices
  • Test and evaluate software to find bugs before attackers do
  • Provide application security concept reviews and promote application security best practices
  • Provide support for application security incidents and operations

PHPSoftware DevelopmentBashCybersecurityJavaJavascript*NixOAuthC (Programming language)Linux

Posted 2024-08-30
Apply