Role Summary
The Application Security Engineer is a hands-on technical role responsible for embedding security engineering practices throughout the Software Development Life Cycle (SDLC). The role focuses on DevSecOps, security automation, code scanning, security testing, and cloud security, translating security assessments and architectural recommendations into practical engineering controls. The role partners with security, architecture, and engineering teams to shift security left through repeatable, scalable, and self-service practices aligned with DORA, NIST, OWASP, and InfoSec standards.
Key Responsibilities
DevSecOps & Security Automation
- Design, build, and maintain secure CI/CD pipelines integrating SAST, DAST, SCA, secrets detection, container scanning, and SBOM generation.
- Implement and optimize security tools such as GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, or equivalent.
- Develop security standards, guardrails, and reusable pipeline templates for engineering teams.
Security Testing & Vulnerability Management
- Lead security testing for applications, including SAST, DAST, API security testing, and penetration testing support.
- Triage, prioritize, and track vulnerabilities while providing clear remediation guidance to engineering teams.
- Monitor recurring vulnerabilities and security risks and recommend systemic improvements.
Secure Coding & Developer Enablement
- Partner with developers on secure code reviews, remediation, and security best practices.
- Maintain secure coding standards covering OWASP, authentication, authorization, secrets management, and cryptography.
- Conduct security awareness sessions, code review workshops, and threat modeling walkthroughs.
Software Supply Chain Security
- Implement software integrity, dependency, artifact, and license controls within CI/CD pipelines.
- Manage SCA and SBOM processes and monitor emerging CVEs and vulnerabilities affecting technology stacks.
- Coordinate remediation and response with engineering and platform teams.
AI & Digital Security Automation
- Apply GenAI, GitHub Copilot, and agentic/AI frameworks to security tasks such as vulnerability triage, remediation recommendations, and security automation.
- Identify opportunities to automate manual security processes and improve engineering efficiency.
Cloud Security
- Implement and validate Azure security controls, including IAM, Key Vault, network security, containers/Kubernetes, and encryption.
- Conduct Infrastructure-as-Code (IaC) security reviews using Terraform, Bicep, or equivalent.
- Support Cloud Security Posture Management (CSPM) and security alert triage.
Collaboration & Continuous Improvement
- Work with security, architecture, and engineering teams to translate risk assessments and security recommendations into practical controls.
- Partner with engineering leaders and security champions to embed security practices into development workflows.
- Monitor security tooling coverage and effectiveness and continuously improve security processes, controls, and developer guidance.
- Support security governance, audit, and compliance activities with appropriate documentation and evidence.
Requirements
Minimum Qualifications
- 8–12 years of overall technology experience, with 5+ years in Application Security, DevSecOps, or Security Engineering.
- Hands-on experience designing and operating DevSecOps pipelines with SAST, DAST, SCA, secrets detection, container scanning, and SBOM.
- Experience with enterprise security tools such as GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, or equivalent.
- Strong knowledge of Azure cloud security, including IAM, Key Vault, network security, containers/Kubernetes, and IaC.
- Strong understanding of OWASP Top 10, NIST, secure coding, and vulnerability management.
Preferred Qualifications
- Experience in financial services, insurance, or other highly regulated industries.
- Security certifications such as CSSLP, CEH, OSCP, GWEB, and/or Azure security certifications such as AZ-500 or SC-100.
- Experience applying AI, GenAI, automation, GitHub Copilot, or agentic technologies to security engineering.
- Experience supporting distributed engineering teams and security champions at scale.
- Familiarity with threat modeling and security architecture review.