Home

Application Security Engineer at Remote, Remote, USA
Email: [email protected]
Application Security Engineer

Auburn Hills, MI or Frisco, TX - Preferred

Required Skills/Experience

SAST/SCA Container Scanning
Container workload protection experience
Threat Modeling
Hands on experience with App Security scanning tools like Snyk/Checkmarx preferred.
AWS Cloud experience
Understanding of programming language/development experience with programming languages like Java added plus.

The Application Security Engineer provides a higher level of security in web application environments. Generally working with dynamic and static code analyzers, communicates vulnerabilities to development teams and coaches as necessary
to remediate these vulnerabilities. Integrates tool output into development pipelines. Creates and shares proof of concept code to demonstrate application attacks. Onboards applications and vulnerability tracking into management system and reports on progress.
Hosts threat modeling exercises based on STRIDE or other industry standard methodology to draw out vulnerabilities during design phase. Guides aspiring application security individuals, leads implementation of new tools and methods. Significant overlap and
interplay with Penetration Testing team.

Position Responsibilities:

Static and Dynamic Code Analysis

Performs integration of static and dynamic code scan output into CI/CD pipeline.
Reviews of code analysis output and translation into findings.
Utilizes the finding management software and tracking remediations with the development teams.
Performs development and application team education resolution training.
Performs emerging threat and threat landscape research.
Provides forensic cyber event analysis.
Identifies means to reduce cyber-attack effectiveness.
Looks for continuous improvement of detections for operationalization.

Threat Modeling and Emerging Vulnerability Detection

Leads threat modeling workshops to draw out vulnerabilities.
Champions industry standard Threat Modeling framework (such as STRIDE).
Updates detection tools as new vulnerabilities emerge.
Stays aware of new vulnerabilities to articulate their inner workings against Comerica's environment.

Company Expert Application Security Consulting

Works closely with partners in Cyber and Technology to solve security problems.
Serves as the escalation point for cyber incidents, events, and application vulnerability research.
Identifies and provides guidance to mitigate threat vectors unique to the shared cyber attack surface.
Proactively communicates with application development teams to illustrate vulnerabilities and solutions.

Planning and Organizing

Identifies & evaluates projects, products, and solutions to enhance threat detection and other capabilities.
Provides expert guidance on highly complex, large projects to incorporate cyber and fraud detection capabilities and considerations.
Participates in industry working and information sharing groups.

Administration

Keeps management informed of status of threats, the threat landscape, and current incidents and events through appropriate reporting.
Actively participates on committees representing Cybersecurity.
Keeps abreast of leading-edge technologies in the application security space.

Other duties as assigned.

Qualifications

Bachelor's Degree from an accredited university in Computer Science, Mathematics, Information Technology, Big Data, Cyber Security or equivalent through a combination of education and/or technology experience
or 12 years of technology experience
8 years progressive cyber security technology experience
5 years of experience in application security engineering
2 years Dynamic/Static application security review
2 years web application development/object-oriented programming
2 years working with attack vectors in OWASP top 10
1 year of experience in threat modeling

Thanks and Regards

Abhisek Limma

Technical Recruiter at

Triano Technologies.

Phone
: +1 9109361935 

Email
:[email protected]

325 Illinois St,

Glen Ellyn, IL 60137

Keywords: continuous integration continuous deployment Illinois Michigan Texas
Application Security Engineer
[email protected]
[email protected]
View All
09:39 PM 29-Jan-25


To remove this job post send "job_kill 2125009" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.


Your reply to [email protected] -
To       

Subject   
Message -

Your email id:

Captcha Image:
Captcha Code:


Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]


Time Taken: 0

Location: ,