Logo for Jobs Capital Manpower Consultants

Sr. Application Security Engineer

Key Facts

Remote From: 
Full time
English

Other Skills

  • β€’
    Collaboration
  • β€’
    Communication
  • β€’
    Problem Solving

Roles & Responsibilities

  • Bachelor's Degree or 7 years of developer experience with 3 years in application security required.
  • Minimum of 5 years in Software Development.
  • Expert knowledge of Azure security services and familiarity with CI/CD processes.
  • Strong working knowledge of programming languages such as Java, C++, C#, or Python.

Requirements:

  • Design, define, and implement security requirements and processes for cloud-based applications.
  • Implement and enforce Application Security tools and coordinate security initiatives across teams.
  • Perform threat modeling and technical design reviews to enhance product security.
  • Educate developers on application security best practices and assist in developing security checklists.

Job description

About the Job
Featured
We are looking for a technical subject matter expert who can show developers how they can secure their traditional cloud and cloud native applications. This person will design, define, and implement security requirements, controls, and processes to properly secure our cloud-based applications. This person will be responsible for and driving the β€œSEC” in our DevSecOps process and evangelizing it’s benefits and outcomes.
Core Responsibilities
  •  Work independently and collaboratively with various teams.
  •  Implement, onboard, and enforce Application Security tools (SAST, SCA, IaC, DAST and IAST), including cloud-based CI/CD Pipelines.
  •  Coordinate software security initiatives with various teams.
  •  Manual and tool-based vulnerability management of priority issues.
  •  Perform threat modeling and technical design reviews of sensitive features, highlight risk, and help developers improve the overall security of our products.
  •  Define, develop and automate the deployment or our Azure security tools and services.
  •  Partner with application teams to implement application security standards, patterns and guidelines.
  •  Assist in developing Source Code Review and application security checklists.
  •  Advise developers on how to implement security into DevSecOps CI/CD pipelines
  •  Partner with Infrastructure teams to implement technical security standards, patterns, and guidelines for server and serverless based platforms.
  •  Educate developers in application security best practices and least privilege principles.
Required Skills
  •  Must have expert Knowledge of Azure security services (Azure Security Center / Azure Sentinel)
  •  Mid-level knowledge of tools such as Terraform, Kubernetes, Jenkins, Azure DevOps
  •  Current experience in security testing, assessment, and methodologies (including browser-based, API, CI/CD pipeline, and Mobile)
  •  Strong working knowledge of at least two programming or scripting languages, preferably Java. Having C++, C#, or Python, and mastery of object-oriented design and programming helpful.
  •  Current experience in threat modeling, and technical design reviews.
  •  Current experience using in at least 1 AppSec (SAST, DAST, IAST) tool sets.
  •  Strong scripting skills in at least one language, preferably Python.
  •  Strong Knowledge of CI/CD processes
  •  Familiarity with manual and automated vulnerability management and resolution across multiple teams.
  •  Familiarity with securing cloud-based resources, including containers, Apps services v3, and other PaaS services in Azure.
  •  Knowledge of configuration and information management analysis, such ask XML, JSON, etc..
  •  Strong understanding of security principles, policies, and industry best practices.
  •  Familiarity of various compliance frameworks (HIPAA, PCI DSS, NIST, etc.).
  •  Familiarity with Open Web Application Security Project (OWASP), Software Assurance Maturity Model (SAMM), Application Security Verification Standard (ASVS), National Institute of Standards and Technology (NIST) Special Publications.
Qualifications
  •  Bachelor's Degree or 7 years developer experience with 3 years of application security or equivalent required
  •  Minimum of 5 years in Software Development
  •  Minimum of 3 years' experience supporting security in CI/CD pipelines

Security Engineer Related jobs

Other jobs at Jobs Capital Manpower Consultants

We help you get seen. Not ignored.

We help you get seen faster β€” by the right people.

πŸš€

Auto-Apply

We apply for you β€” automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

✨

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.