ActiveSoft, Inc · 1 day ago
Lead Application Security Engineer
Qualification
Required
4 years in Application / Product security or software engineering with a strong security focus
Hands on depth with modern SDLC/DevSecOps in cloud-native environments: microservices, APIs, containers/Kubernetes, serverless, IaC (Terraform/CloudFormation/ARM/Bicep), and CI/CD integration
Practical expertise operating and tuning SAST, DAST, SCA, API testing, IaC/container scanners, plus CNAPP for multi cloud
Scripting/automation proficiency (Python preferred) and REST API integration skills; able to create quick utilities and pipeline jobs to reduce manual effort
Strong knowledge of OWASP Top 10, ASVS, SAMM, NIST SSDF, CSA CCM, secure design patterns, cryptography fundamentals, authN/Z (OAuth2/OIDC/JWT), and common web/API vulns and mitigations
Preferred
PowerShell/Bash nice
Company
ActiveSoft, Inc
Since 2007, Active Soft, Inc.
Funding
Current Stage
Growth StageCompany data provided by crunchbase