Application Security Engineer @ IBM | Jobright.ai
JOBSarrow
RecommendedLiked
0
Applied
0
Application Security Engineer jobs in Newport News, VA
41 applicants
company-logo

IBM · 3 days ago

Application Security Engineer

Wonder how qualified you are to the job?

ftfMaximize your interview chances
Business DevelopmentBusiness Information Systems
check
Growth Opportunities

Insider Connection @IBM

Discover valuable connections within the company who might provide insights and potential referrals, giving your job application an inside edge.

Responsibilities

Proven experience in application security, including vulnerability assessments and code reviews.
Perform regular security assessments of application code vulnerability scans.
Analyze and interpret security scan results, identifying vulnerabilities, security risks, and validating reported false positives.
Collaborate with Customers, Customer System Integrators and CRM's to ensure production application deploys are scanned, reviewed and approved.
Monitor and respond to security incidents related to applications
Collaborate with the incident response team to investigate and mitigate security breaches.
Stay up-to-date with the latest security threats, vulnerabilities, and industry best practices.
Design and implement application security standards and guidelines.
Oversee the development and improvement of application security policies and procedures.
Ensure that applications comply with relevant security standards and regulations.
Keep abreast of changes in security regulations and update security measures accordingly.
Collaborate with development teams to implement secure coding practices and provide guidance on addressing security findings.
Identify and provide remediation recommendations for security vulnerabilities in applications, APIs, and web services.
Work closely with DevOps and IT teams to automate security testing processes.
Provide guidance on secure architecture and design principles.
Advise development teams on security best practices, emerging threats, and industry trends.

Qualification

Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.

Application SecurityVulnerability AssessmentsCode ReviewsSecurity AssessmentsSecurity Scan Results AnalysisIncident ResponseSecurity Regulations ComplianceSecure Coding PracticesSecurity Testing AutomationSecure Architecture DesignSecurity ClearanceWeb Application SecuritySAST Tools FortifySAST Tools CheckmarxSAST Tools SonarQubeDAST Tools WebInspectDAST Tools Burp SuiteProgramming Languages JavaProgramming Languages PythonProgramming Languages C++Programming Languages C#OWASPNISTISO 27001OWASP Top 10DevOps PracticesProblem-SolvingCommunicationInterpersonalCISSP

Required

Proven experience in application security, including vulnerability assessments and code reviews.
Perform regular security assessments of application code vulnerability scans.
Analyze and interpret security scan results, identifying vulnerabilities, security risks, and validating reported false positives.
Collaborate with Customers, Customer System Integrators and CRM's to ensure production application deploys are scanned, reviewed and approved.
Monitor and respond to security incidents related to applications
Collaborate with the incident response team to investigate and mitigate security breaches.
Stay up-to-date with the latest security threats, vulnerabilities, and industry best practices.
Design and implement application security standards and guidelines.
Oversee the development and improvement of application security policies and procedures.
Ensure that applications comply with relevant security standards and regulations.
Keep abreast of changes in security regulations and update security measures accordingly.
Collaborate with development teams to implement secure coding practices and provide guidance on addressing security findings.
Identify and provide remediation recommendations for security vulnerabilities in applications, APIs, and web services.
Work closely with DevOps and IT teams to automate security testing processes.
Provide guidance on secure architecture and design principles.
Advise development teams on security best practices, emerging threats, and industry trends.
Must be able to obtain/maintain a Secret Security Clearance
Bachelor's degree in Computer Science, Information Security, or related field.
3-5 years of experience in application security or related roles.
Solid understanding of web application security principles.
Experience with SAST (Fortify, Checkmarx, SonarQube…) and DAST (WebInspect, Burp Suite….) tools
Proficiency in programming languages such as Java, Python, C++, C#, or others.
Knowledge of web application security principles and common vulnerabilities.
Familiarity with security frameworks and compliance standards (e.g., OWASP, NIST, ISO 27001).
Understanding of secure coding practices and the OWASP Top 10.
Strong analytical and problem-solving skills.
Excellent communication and interpersonal skills.
Experience with DevOps practices and tools

Preferred

Industry certifications such as CISSP, CSSLP, or CEH.
Experience with cloud security (AWS, Azure, or GCP).
Knowledge of container security (Docker, Kubernetes).
Familiarity with scripting languages (Python, Ruby, etc.)

Benefits

Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs
Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences

Company

IBM is an IT technology and consulting firm providing computer hardware, software, infrastructure, and hosting services.

Funding

Current Stage
Public Company
Total Funding
$1M
Key Investors
Mehdi Amara
2024-01-12Post Ipo Equity· $1M
2015-01-16IPO· nyse:IBM

Leadership Team

leader-logo
Alain Bénichou
Chief Executive Officer, IBM Greater China Group
linkedin
leader-logo
Martin J. Schroeter
CEO - IBM Kyndryl
linkedin
Company data provided by crunchbase
logo

Orion

Your AI Copilot