Security Engineer, Application Security
Identifies and mitigates application security vulnerabilities through code reviews, penetration testing, and security assessments. Collaborates with development teams to integrate secure coding practices and provides guidance on threats and remediation.
About the job
Responsibilities
- Perform security assessments: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.
- Develop and implement security tools: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.
- Collaborate with development teams: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.
- Threat modeling and risk assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.
- Vulnerability management: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.
- Incident response support: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.
- Stay current on security trends: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.
Requirements
- Extensive experience in information security, cybersecurity, or a related field.
- Deep understanding of security technologies, tools, and best practices, including secure coding practices, threat modeling, risk assessments, and incident response.
- Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.
- Proficiency in programming languages (such as Python, Java, C++).
- Knowledge of security tools (e.g., Burp Suite, OWASP ZAP).
- Familiarity with security protocols and encryption methods.
- Strong written and verbal communication skills.
Skills
Burp Suite, Owasp Zap, Python, Java, C++, Threat Modeling, Penetration Testing, Secure Coding, Vulnerability Management, Incident Response
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.