Senior Application Security Engineer

Senior Application Security Engineer

26 Feb 2024
New Jersey, Newark, 07101 Newark USA

Senior Application Security Engineer

The Senior Application Security Engineer position is a hands-on role that involves evaluating and enforcing application security in all phases of the Software Development Life Cycle (SDLC). This position will work closely with our engineering teams to define and implement application best practice security controls, perform software architecture and design reviews, threat modeling, conduct white box security testing, and support the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms with a focus on supporting our GovCloud environment.We are looking for someone with a strong background in information security and a proven ability to deliver under pressure. Position is remote and candidates must be willing to collaborate with team on PST timezone.In this role you will…

Participate in architecture and design reviews with Engineering leads to incorporate effective security standards into product design

Design, build. and maintain security tools/processes to effectively secure our cloud-based environments (AWS, GovCloud, GCP)

Guide team on best practices related to Infrastructure as Code (Cloud Formation), Lambda functions, IAM, and related Cloud services.

Implement a program to integrate security into the build/release pipelines to ensure our code is secure before it goes to production

Conduct white box security testing to assess and validate application security

Define, maintain, and enforce application security best practices and evaluate application security tools to improve our detection and prevention capabilities

Monitor and track progress of found vulnerabilities and maintain the history

Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation

Perform secure code development training to developers, quality assurance personnel, and relevant staff

Implement a program to integrate security into the build/release pipelines to ensure our code is secure before it goes to production

You’ve got what it takes if you have…

Ability to obtain a security clearance which requires US citizenship

Bachelor’s degree in an Information Technology related field of study or equivalent post high school education and/or work-related experience

6+ years of experience in web and/or mobile application security

Experience working in AWS GovCloud or FedRAMP/DoD environment

Experience with STIG and/or CIS

Knowledge of information security principles, web applications, and a level of familiarity with malicious code and common techniques used by hackers

Experience with common SDLC tools: static and dynamic code analysis, API security, open source management, container security, threat modeling, etc.

Experience with HTML and JavaScript along with a solid understanding of HTTP protocol

Experience coordinating penetration testing activities and performing penetration testing

Extensive experience with CI/CD practices and tools (Git, Jenkins) and integrating security solutions into CI/CD pipelines

Extensive experience creating solutions in Python, or other such as C#, Node.JS, or Go, and Infrastructure as Code (AWS CloudFormation)

Excellent problem solving and analytical skills; outstanding oral and written communication skills

Self-motivation and the ability to work under minimal supervision are a must

Excellent at multitasking, and open to constant learning

Energetic and positive attitude

Demonstrated commitment to valuing diversity and contributing to an inclusive working and learning environment

Consideration for privacy and security obligations

An extra dose of awesome if you have…

Knowledge of microservices architectures

Experience working on security responsibilities for a SaaS or PaaS solutions, preferably in AWS

Basic knowledge of SQL and prior experience with programming in one or more server-side technologies such as ASP.NET Core or scripting (Python, Shell)

Thorough understanding of SDLC and software security maturity models such as Building Security In Maturity Model (BSIMM) or OWASP Software Assurance Maturity Model (SAMM) is a plus

Experience conducting secure code development training

Knowledge of cryptographic tools and/or security APIs

Experience interacting with security vendors and customers

Knowledge of FIPS 140-2 and cryptographic tools

#LI-ET1Equal Employment Opportunity has been, and will continue to be, a fundamental commitment at Cornerstone OnDemand. All qualified applicants are given consideration regardless of race, color, gender, age, sexual orientation, national origin, marital status, citizenship status, disability, veteran status, or any other protected class as provided in applicable Federal, State, or Local fair employment laws. If you have a disability or special need that requires accommodation, please contact us at careers@csod.com

Related jobs

  • Job Classification:Technology - Agile, Delivery, & ProductA GLOBAL FIRM WITH A DIVERSE & INCLUSIVE CULTUREAs the Global Asset Management business of Prudential, were always looking for ways to improve financial services. Were passionate about making a meaningful impact - touching the lives of millions and solving financial challenges in an ever-changing world.We also believe talent is key to achieving our vision and are intentional about building a culture on respect and collaboration. When you join PGIM, youll unlock a motivating and impactful career all while growing your skills and advancing your profession at one of the worlds leading global asset managers!If youre not afraid to think differently and challenge the status quo, come and be a part of a dedicated team thats investing in your future by shaping tomorrow today.At PGIM, You Can!What you will doIn PGIM Fixed Income, our technology group is a dynamic, fast-paced environment, with exciting changes on the horizon under new senior leadership. We are looking for a well-rounded, senior application support analyst to liaise between our external vendors, end users and technology team to provide oversight and stability within our production environment. Our ideal candidate will have proven experience in supporting complex investment management platforms and applications. This will include front-office investment systems, business support applications and complex back-office data management and automation platforms. The right candidate for this role will identify this challenge as a unique and valuable opportunity to help drive our global technology transformation, so if this sounds interesting, then PGIM could be the place for you.What you can expectProvide application support for systems used by front and back office functions and client distribution teams across end-users, vendors, and technology teams, troubleshoot business issues, solving problems to diverse investment teams and product aligned business areasOwnership and accountability for the operation, monitoring and integrity of the technology platform, including complex nightly data import processes from multiple external vendorsTriage and escalation support for members of the broader technology team including evenings and weekends on a rotation basisOwnership and participation in the incident and problem management processes, being accountable for resolution, root cause analysis and technology/business reporting as well as communicationProviding oversight for the stability of the production environment within the change management process and ensuring policies are enforcedOwn minor development tasks/projects that help address existing bugs or introduce operational enhancements to the broader business community or our technology organizationNavigate the broader technology organization, build relationships to manage the teams agenda with our critical technology partnersInterface with external vendors and their technical support/development organizations ensuring focus to resolution of issues and strategic enhancementsProactively identify improvements and address them through independent thinking within a consensus driven teamWork in close partnership with the development teams to identify, escalate and help persistent patterns of issuesPartner closely with testing and release control teams to move tested code into productionWhat you will bring10+ years of experience in financial services technology, ideally with a focus in investment management. Strong understanding of the SDLC process, with a focus on application support and release managementA hunger for continuous improvement, constantly looking for opportunities to improve upon the status quo and a desire to improve the support experience for our business and technology teams.A tenacious sense of ownership and a desire to bring incidents to resolution quicklyA disciplined approach to problem management, working with development and service management teams to ensure technical incidents do not reoccurDemonstrated experience with service management functions including tight adherence to change, incident and problem management practicesPartner closely with Agile development teams to ensure best-practice checks are followed before new releases and systems are moved into a production supportable stateExperience supporting applications hosted on the cloud (AWS experience preferred)Implement monitoring and alerting for both on-prem and AWS applications using Splunk, Dynatrace, CloudWatch alarms, etc.Technical fluency to use your software coding skills to automate manual processes in the production environment (python hands-on experience preferred)Experience with Business intelligence tools (Tableau preferred)Experience with the use of Enterprise Scheduling/workflow software (autosys preferred)Fluency in configuring/using modern monitoring tools desired (e.g. DynaTrace, Splunk etc.)Direct experience with the Atlassian product suite, including JIRA and Confluence.Experience using service management tools (ServiceNow preferred)Ability to make changes to existing code for minor bug fixes/enhancements (Experience with Java preferred)Experience with Sybase and MS SQL Server. SQL database query and reporting experience.What will set you apart?Very strong research, analytical, investigation, troubleshooting and evaluation skills.Experience working in a DevOps environment combined with a demonstrated experience in an Agile development environmentExperience with assisting development, testing and release teams with CI/CD pipelines.Knowledge of the trading lifecycle, portfolio management and trading systemsEqual Opportunity Employer - minorities/females/veterans/individuals with disabilities/sexual orientation/gender identity

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

  • W2 ONLY Candidates

  • Requisition : 78240

  • Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world—from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better.

  • Company Overview

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

Job Details

Jocancy Online Job Portal by jobSearchi.