Senior (5+ years of experience)
Summary of the Role
We are looking for a seasoned Application Security Engineer to join our team. As a Senior Application Security Engineer, you will be responsible for the security of our software applications, conducting security assessments, and implementing security best practices throughout the development lifecycle. Your expertise will help in defining and maintaining our cybersecurity standards, and ensuring the protection of our data and systems from cyber threats.
Required Skills
Proficient in various programming languages like Java, Python, or C++.
Knowledge of web application security, including OWASP top 10 vulnerabilities.
Experience with security tools such as static and dynamic analysis tools, and penetration testing tools.
Strong understanding of cryptography, authentication, authorization, security protocols, and security vulnerabilities.
Excellent communication skills, both written and verbal.
Ability to work collaboratively across different teams.
Problem-solving skills and the ability to work under pressure.
Ability to think like an attacker and anticipate potential security threats.
Qualifications
Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
Minimum of 5 years of experience in application security or related field.
Certifications such as CISSP, CEH, OSCP, or GIAC are highly desirable.
Proven experience with security frameworks and standards like OWASP, NIST, and ISO/IEC 27001.
Responsibilities
Lead security assessments and penetration tests on our applications and systems.
Develop and maintain security policies, procedures, and standards.
Work closely with the development team to integrate security practices in the SDLC.
Manage vulnerabilities and track resolution within software portfolios.
Advocate for secure coding practices and promote security awareness.
Coordinate with stakeholders to define and implement security requirements.
Stay up to date with emerging security threats and technologies.
Conduct security training and education programs for staff.