Senior Application Security Engineer

Posted 3 months agoViewed
United States, CanadaFull-TimeHospitality Software
Location:United States, Canada
Languages:English
Seniority level:Senior, 6+ years
Experience:6+ years
Skills:
AWSPythonSoftware DevelopmentCloud ComputingJavascriptKubernetesGoCI/CDLinuxDevOpsTerraformMicroservices
Requirements:
6+ years in security engineering, DevSecOps, or related roles. Excellent communication and teamwork abilities. Strong experience integrating security into modern SDLC pipelines. Hands-on with AppSec tooling (Snyk, OWASP ZAP, Burp Suite, SonarQube, Checkmarx). Solid understanding of web app security (OWASP Top 10, API security, auth flows, input validation). Familiarity with AWS/Kubernetes security. Strong programming skills (Python, Go, or JavaScript). Proven track record in partnering with product and engineering teams to drive security adoption. Strong AWS security skills (IAM, KMS, Security Hub, GuardDuty, WAF). Experience with Kubernetes security (RBAC, OPA/Gatekeeper, network policies). Hands-on with Terraform, Helm, and GitOps practices. Familiarity with security tooling (Trivy, Falco, Snyk, Aqua). Knowledge of networking, encryption, and cloud-native security best practices.
Responsibilities:
Define and enforce secure coding, dependency management, and design review best practices. Integrate and manage SAST, DAST, and SCA tools in CI/CD pipelines. Partner with developers to identify risks early in the lifecycle. Implement best practices for secrets handling, API authentication/authorization, and data protection. Build security guidelines, training, and reusable libraries. Triage and prioritize findings from bug bounties, penetration tests, and scans. Act as a bridge between application developers and platform engineers. Implement monitoring, alerting, and remediation for security incidents. Scan and remediate vulnerabilities in container images, OS packages, dependencies, and IaC templates. Design and maintain least-privilege IAM roles, secrets management, and authentication flows. Automate evidence gathering and control enforcement for compliance.
Similar Jobs:
Posted 1 day ago
United States, United Kingdom, Canada, Australia, New ZealandContractAI Development
Mercor - Exceptional SWE Annotator, application via RippleMatch
Posted 1 day ago
United States, United Kingdom, Canada, Australia, New ZealandContractAI Development
Mercor - Exceptional SWE Annotator, application via RippleMatch
Posted 1 day ago
United States, United Kingdom, Canada, Australia, New ZealandContractAI Research
Mercor - Exceptional SWE Annotator, application via RippleMatch