Senior Application Security Engineer โ Information Security
Responsibilities:
- Implement and maintain Application Security Testing (AST) tools (SAST, DAST, IAST, SCA) to identify code and dependency vulnerabilities during the SDLC.
- Implement and maintain Application Security Posture Management (ASPM) tools to centralize and deduplicate findings and integrate into development processes.
- Provide first-line support: resolve false positives, guide remediation, and evaluate security exception requests.
- Integrate security tooling with CI/CD pipelines.
- Develop detailed reports on security findings and remediation efforts.
- Demonstrate high proficiency across application security, software design/development, containerization, and cloud environments.
- Communicate security risks and evangelize secure development practices.
- Understand vulnerabilities and triage security risks at scale across application environments and business units.
Qualifications:
Required:
- Bachelorโs with 7 yearsโ experience; Masterโs with 6; PhD with 2 (pharmaceutical industry preferred).
- Experience in application security and software development.
- Experience implementing/supporting application security tooling (SAST/DAST/IAST/SCA).
- Secure coding knowledge across multiple languages (esp. Java, Node.js).
- Experience integrating security testing into CI/CD.
- Knowledge of application security principles and vulnerabilities (OWASP Top 10, CWE) and mitigations.
- Experience scaling DevSecOps in large organizations; implementing DevSecOps workflows in AWS and Azure.
- Infrastructure as Code experience (Terraform and/or CloudFormation).
- Ability to assess/mitigate findings; communicate to technical and non-technical stakeholders.
- Principal-engineer capability, creative problem solving, and championing new technologies.
- Excellent English communication; experience presenting at technical conferences; coaching junior engineers.
Preferred:
- Consolidation tooling across multiple finding sources; Snyk/Endor Labs; CSPM integration.
- Automation via Python; DevSecOps pipeline logging.
- Collaboration with vulnerability/risk management partners.
- 5+ years application security/software development; 3+ years with SAST/DAST/IAST/SCA tooling.