IBM · 3 days ago
Application Security Engineer
Wonder how qualified you are to the job?
Maximize your interview chances
Business DevelopmentBusiness Information Systems
Growth Opportunities
Insider Connection @IBM
Responsibilities
Proven experience in application security, including vulnerability assessments and code reviews.
Perform regular security assessments of application code vulnerability scans.
Analyze and interpret security scan results, identifying vulnerabilities, security risks, and validating reported false positives.
Collaborate with Customers, Customer System Integrators and CRM's to ensure production application deploys are scanned, reviewed and approved.
Monitor and respond to security incidents related to applications
Collaborate with the incident response team to investigate and mitigate security breaches.
Stay up-to-date with the latest security threats, vulnerabilities, and industry best practices.
Design and implement application security standards and guidelines.
Oversee the development and improvement of application security policies and procedures.
Ensure that applications comply with relevant security standards and regulations.
Keep abreast of changes in security regulations and update security measures accordingly.
Collaborate with development teams to implement secure coding practices and provide guidance on addressing security findings.
Identify and provide remediation recommendations for security vulnerabilities in applications, APIs, and web services.
Work closely with DevOps and IT teams to automate security testing processes.
Provide guidance on secure architecture and design principles.
Advise development teams on security best practices, emerging threats, and industry trends.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
Proven experience in application security, including vulnerability assessments and code reviews.
Perform regular security assessments of application code vulnerability scans.
Analyze and interpret security scan results, identifying vulnerabilities, security risks, and validating reported false positives.
Collaborate with Customers, Customer System Integrators and CRM's to ensure production application deploys are scanned, reviewed and approved.
Monitor and respond to security incidents related to applications
Collaborate with the incident response team to investigate and mitigate security breaches.
Stay up-to-date with the latest security threats, vulnerabilities, and industry best practices.
Design and implement application security standards and guidelines.
Oversee the development and improvement of application security policies and procedures.
Ensure that applications comply with relevant security standards and regulations.
Keep abreast of changes in security regulations and update security measures accordingly.
Collaborate with development teams to implement secure coding practices and provide guidance on addressing security findings.
Identify and provide remediation recommendations for security vulnerabilities in applications, APIs, and web services.
Work closely with DevOps and IT teams to automate security testing processes.
Provide guidance on secure architecture and design principles.
Advise development teams on security best practices, emerging threats, and industry trends.
Must be able to obtain/maintain a Secret Security Clearance
Bachelor's degree in Computer Science, Information Security, or related field.
3-5 years of experience in application security or related roles.
Solid understanding of web application security principles.
Experience with SAST (Fortify, Checkmarx, SonarQube…) and DAST (WebInspect, Burp Suite….) tools
Proficiency in programming languages such as Java, Python, C++, C#, or others.
Knowledge of web application security principles and common vulnerabilities.
Familiarity with security frameworks and compliance standards (e.g., OWASP, NIST, ISO 27001).
Understanding of secure coding practices and the OWASP Top 10.
Strong analytical and problem-solving skills.
Excellent communication and interpersonal skills.
Experience with DevOps practices and tools
Preferred
Industry certifications such as CISSP, CSSLP, or CEH.
Experience with cloud security (AWS, Azure, or GCP).
Knowledge of container security (Docker, Kubernetes).
Familiarity with scripting languages (Python, Ruby, etc.)
Benefits
Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs
Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
Company
IBM
IBM is an IT technology and consulting firm providing computer hardware, software, infrastructure, and hosting services.
Funding
Current Stage
Public CompanyTotal Funding
$1MKey Investors
Mehdi Amara
2024-01-12Post Ipo Equity· $1M
2015-01-16IPO· nyse:IBM
Leadership Team
Recent News
2024-06-05
Business, Technology, Startups and Science News and Trends in India | IndianWeb2.com
2024-06-04
Company data provided by crunchbase