Senior Application Security Engineer
J
Job&TalentSoftware Engineering
This is a fully remote position with flexibility within ±1 hour of CET., ±1 hour of CETFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 3-4 years of experience in Information Security, including at least 2 years in Application Security
- Required Skills
- PythonKubernetesCI/CD
Requirements
- 3-4 years of experience in Information Security, including at least 2 years in Application Security.
- Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews.
- Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines.
- Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices.
- Experience implementing and managing WAF solutions.
- Experience conducting internal penetration testing (including APIs using Burp Suite).
- Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP).
- Basic scripting or development experience, preferably in Python.
- Excellent communication skills, with the ability to influence engineering teams.
Responsibilities
- Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC.
- Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks.
- Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling.
- Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation.
- Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management.
- Mentor Security Champions and junior engineers, promoting a strong security culture across development teams.
- Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness.
View Full Description & ApplyYou'll be redirected to the employer's site