Central Insurance · 10 hours ago
Application Security Engineer
Central Insurance is a company focused on delivering exceptional customer service and innovative IT support. They are seeking a detail-oriented Application Security Engineer to join their cybersecurity team, responsible for embedding security into the software development lifecycle and collaborating with developers to build resilient applications.
Responsibilities
Conduct secure code reviews, threat modeling, and vulnerability assessments
Collaborate with engineers to integrate security controls into CI / CD pipelines
Develops, maintains, and champions secure coding guidelines and training materials
Collaborates with DevOps and Software Engineering to integrate security into the SDLC process
Implements and manages application security tools (SAST, DAST, SCA, WAF, etc..)
Assists with monitoring security events and contributes with the incident response. team
Collaborates on data security to ensure secure data access configurations with Data Engineering and Infrastructure
Collaborates with Software Engineering to integrate security into AI/ML pipelines and governance frameworks
Responsible for scripting automation for integration of security tools and functions
Utilizes scripting for meta-data aggregation to allow for the creation of dashboards or other metrics for security analytics
Stay current with emerging threats, vulnerabilities, and security technologies
Qualification
Required
Bachelor's degree in Computer Science or related field and 2 years related experience
Or 4 years related experience
Creativity and passion for application security
Curious mind and strong desire to constantly learn
Strong understanding of OWASP Top Ten, secure coding practices, and common attack vectors
Proven ability to apply secure design principles within application architecture
Strong analytical, research, and problem-solving skills
Understanding of the software development life cycle
Understanding of security tools such as Burp Suite, Snyk, Rapid7, or similar tools
Familiarity with CI/CD tools such as Azure DevOps, GitLab, Jenkins or similar tools
Ability to work with product, software, data, and infrastructure engineering teams
Strong understanding of data protection principles and technologies (Encryption, DLP, IAM)
Understanding of scripting automation using Python, PowerShell, Bash
Possess a positive, professional, cooperative, and quality-conscious attitude
Possesses verbal and written communication skills, including negotiation, presentation, and influence skills
Ability to understand Central Insurance's policies and processes
Preferred
CISSP, CASE, GWAPT, or CSSLP certifications preferred
Benefits
Health and wellness benefits
Flexibility
Work-life balance
Long-term financial security
Company
Central Insurance
Since our beginning in 1876, Central Insurance has evolved into a successful property and casualty group operating on a strong foundation of core values including Integrity in the way we operate our business; Relationships we develop working as a team and sharing in each others’ successes; and Excellence achieved by never compromising on quality, providing superior performance, and pursuing continual improvements.