Logo for North

Associate Application Security Engineer

Role overview

Qualifications

  • Bachelor of Science in Cybersecurity, Computer Science, or an allied technical discipline
  • Experience with web vulnerabilities, web attack paths, and web vulnerability remediation
  • Experience with cloud platforms (AWS, Azure, GCP) and their native security tools
  • Basic scripting knowledge using Python, Bash, and PowerShell

Responsibilities

  • Application protection and defense, recommend configuration changes for web application protection
  • Coordinate with application and infrastructure teams to ensure effective protections
  • Conduct application assessments and security tests with the testing team
  • Document, triage and track vulnerabilities and exposures and assist in remediation

About the company

North logo

North

Digital Payments & Money Transfer

North American Bancard Holdings, LLC (NAB) and its subsidiaries are committed to making it as easy as possible for you to grow your business through innovations in credit card processing, ecommerce, mobile payments, back-end business solutions, and more. Throughout our growth, we've stayed agile in order to remain at the forefront of the ever-changing payments landscape. While we are large enough to offer customized solutions to enterprise-level clients we're still nimble enough to take an award-winning, hands-on approach to personal service you just won't find anyplace else. At North American Bancard, we pride ourselves on being a diverse family of thinkers and innovators that are reimagining how business is done. Our most important resource is our people. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. To learn about current openings with NAB and our family of companies, visit us at https://www.northamericanbancard.com/company/careers!

Company details

Company typeLarge
IndustryDigital Payments & Money Transfer
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Associate Application Security Engineer

North - Remote

Please Note:

Only candidates located in the Eastern or Central Time zone will be considered.

North is a US based company and this role is not eligible for current or future sponsorship.

Join our security team as an Associate Application Security Engineer and play a hands-on role in defending cloud infrastructure, networks, and modern web applications using enterprise-level tools. In this role, you will develop your expertise in vulnerability assessment and threat research while collaborating closely with engineering teams to drive timely and effective remediation. You’ll leverage automation, scripting, and data analysis to scale security testing, reduce risk, and continuously monitor critical assets.

This is an excellent opportunity for an early-career security professional looking to grow their skills in a fast-paced, collaborative environment.



 

What you'll do:

  • Application protection and defense, recommend configuration changes, adjustments and enhancements for web application protection controls and monitor for and report on abnormal events.

  • Coordinate with application and infrastructure teams to ensure effective protections and responses.

  • Conduct application assessments and security tests together with the testing team. Maintain, add, enhance, and expand the scope of application assessments and penetration tests. 

  • Use  augmented instruments and tools for application assessments and evaluations.

  • Document, triage and track vulnerabilities and exposures as well as assisting and advising on remediation.

  • Identify and track risks and exposures, create leads for assessments

  • Document and maintain operational processes and procedures.



 

What we need from you:

  • Bachelor of Science in Cybersecurity, Computer Science, or an allied technical discipline, complemented by equivalent professional expertise.

  • Experience with web vulnerabilities, web attack paths, and web vulnerability remediation in modern web frameworks

  • Experience with cloud platforms (AWS, Azure, GCP) and their native security tools

  • Experience with security testing tools such as BurpSuite, nmap, Metasploit, and security testing distributions such as Kali Linux

  • Experience with data analysis and SIEM tools (e.g., Grafana, Opensearch, CS NextGen SIEM) for log analysis and monitoring

  • Strong networking fundamentals and familiarity with network protocols (HTTP/HTTPS, TCP/IP, DNS) and web technologies (HTML, JavaScript, APIs)

  • Basic scripting knowledge using Python, Bash, and PowerShell

  • Comfortable using terminals, scripting, and automation for WAF automation use-cases

  • Ability to translate complex technical vulnerabilities, threat impact, and remediation urgency into actionable, risk-prioritized reports for both technical and non-technical stakeholders

How to stand out (preferred):

  • Relevant industry certifications and qualifications (e.g., CompTIA Security+, CEH, OSCP, or equivalent) are a plus

  • Experience executing penetration testing aligned with OWASP Top 10 standards and modern browser security baselines

  • Experience partnering with engineering teams on vulnerability remediation, including CSP rules, secure CORS origins, and HSTS enforcement

  • Experience developing novel testing methodologies to bypass or harden application-layer defenses

  • Familiarity with DevOps tools (e.g., Docker, Kubernetes, Terraform, git) and CI/CD pipelines

  • Ability to refine automated security tools to reduce false positives and ensure continuous monitoring of critical web assets

  • Experience conducting security research and threat intelligence to advance organizational defenses

  • Knowledge of hardened security configurations including CSP rules, secure CORS origins, and strict HSTS enforcement 

Salary range: $90,000-$125,000

Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process.

Please note: North is a US based company and no sponsorship is available for this position at this time.

Who we are: 

North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else.

Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. 

At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer.

To learn more about North, and our family of companies, visit our website: north.com

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at North

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.