Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The Application Security Engineer will be executing automated application security tools for security weaknesses, performing vulnerability scans, managing security tools, and providing security guidance to software development teams.
Responsibilities:
Execute automated SAST and SCA scans to identify security vulnerabilities in web, API, and mobile applications.
Perform manual secure code reviews to validate findings and detect security issues not identified by automated tools.
Analyze vulnerability scan results, prioritize risks, and provide remediation recommendations to development teams.
Collaborate with developers to resolve security issues and promote secure coding best practices.
Integrate application security testing into the Software Development Life Cycle (SDLC) to ensure security is embedded throughout development.
Manage application security tools, perform re-validation of fixes, and support continuous improvement of the organization's application security posture.
Requirements:
Expertise in automating secure coding tools and processes (SAST, SCA, DAST, mobile, and API security).
Review security test results from vulnerability scans and penetration testing for true positives and propose appropriate remediation measures or mitigation controls.
Experience with programming languages such as Java, Python, or Go, and at least one scripting language.
Knowledge of WAF.
Knowledge of web, mobile, API, microservices, and network penetration testing.
Knowledge of security best practices, principles, and common security frameworks, such as NIST and OWASP, etc.
Knowledge of current and emerging security technologies, threats, and techniques for exploiting security vulnerabilities.
Knowledge of AWS, Azure, Google Cloud, or Oracle is preferable.
Knowledge of securing container platforms such as Docker and Kubernetes.
Ability to interact with a broad cross-section of personnel to explain and enforce security measures.
Good written and verbal communication skills.
Bachelor's degree in computer science, information technology, cyber security, or a related discipline or equivalent experience.
4 to 6 years of application security experience with knowledge of security tools and vulnerabilities.
Certifications: CSSLP, GWAPT, CEH, CISSP, CCSP.
Skills
Application Security, SAST, APIs, AWS, Python, Penetration Testing, Information Security, Java, Shell Scripting
Experience
3-5 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.