This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
In your role as a Senior Application Security Engineer, you are responsible for enabling developers to build secure applications. Under limited direction of your management, you will operate with an agile mentality – delivering solutions quickly and improving upon design and implementation of existing solutions. You will collaborate with cloud security, security operations, and other teams to ensure secure application development across the enterprise. This role will be a global role and is part of the Enterprise Security group, which is globally deployed.
Job Responsibility:
Enable development teams to develop secure applications
Operation and support of code scanning tools, e.g., Wiz and Checkmarx
Supporting development teams to triage findings and enable self-service
Ensuring code scanning tools integrate seamlessly into the current software development lifecycle with minimal friction e.g. Github actions as a part of existing shared CICD workflows
Oversee the design, implementation, and management of the infrastructure and tooling necessary to support all security aspects of continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines
Collaborate with key stakeholders to identify opportunities for automation, process improvement, and tool optimization
Research and implement new technologies to improve and grow secure development (e.g. applications, systems, outsources services)
Maintain operational guidelines, diagrams, and documentation for secure development
Work closely with the developer experience team to integrate security automation into the development process
Requirements:
Bachelor’s degree in computer science or related field
Minimum of 5 years of experience in application security, software development, or related field
Expertise in Securing Software Development Lifecycles
Expertise in one or more high-level programming languages, e.g., Java, C#, Python, etc.
Expertise in application-level attacks and defenses, e.g., OWASP Top 10, SANS Top 25, etc.
Experience with AI application security concepts e.g. OWASP Top 10 for LLM applications, etc.
Experience with AppSec tooling such as SAST, DAST, IAST, RASP, etc.
Experience working with DevOps, Agile, Scrum, Kanban methodologies
Experience with AWS cloud services such as WAF, EC2, S3, Lambda, VPC, CloudWatch, CloudTrail, EKS, ECS, KMS, IAM, RDS
Nice to have:
Master's degree in computer science or related field
Experience with using AI-powered coding assistants (e.g. Github Copilot, Augment) and the security concerns related to it
Security related certification(s) such as CSSLP
Experience with Infrastructure as Code and the use of Application Release Automation tools
Experience as an AWS Dev/Sec/Ops Engineer developing continuous Integration and Continuous Delivery pipelines (CI/CD)
Experience working in a regulated secured environment and understanding the security requirements (NIST, ISO, etc.)
Experience working with production incident management tools and processes to resolve Enterprise level issues
Experience in leading or mentoring other engineers