Fullsteam · 3 hours ago
Senior Application Security Engineer
Maximize your interview chances
PaymentsSoftware
Growth Opportunities
Insider Connection @Fullsteam
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Lead the implementation and operationalization of SAST, SCA, and DAST tools across multiple business units with varying tech stacks.
Collaborate with development teams to provide guidance on secure coding practices and consult on remediation efforts for vulnerabilities.
Develop and maintain an application security vulnerability management program, ensuring critical and high vulnerabilities are remediated according to SLAs.
Conduct threat modeling exercises to identify potential threats and propose mitigations throughout the software development lifecycle.
Work closely with engineering teams to integrate security tools seamlessly into CI/CD pipelines and development workflows.
Create comprehensive documentation and training materials for secure development practices.
Perform security assessments, code reviews, and penetration testing as needed.
Track, report, and communicate the progress of application security initiatives to senior management.
Stay up to date with the latest security trends, vulnerabilities, and attack vectors to ensure continuous improvement of the security posture.
Support incident response activities by providing expertise in application security-related incidents.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
5+ years of experience in application security, with hands-on experience in secure coding, SAST, SCA, and DAST.
Proficiency in one or more programming languages such as Python, Java, JavaScript, or C#.
Experience building and managing vulnerability management programs specific to application security findings.
Demonstrated expertise in threat modeling and risk assessment processes.
Solid understanding of modern development frameworks and CI/CD practices.
Strong problem-solving, analytical, and communication skills.
Preferred
Industry certifications such as OSCP, CEH, CISSP, or GWAPT are a plus.
Company
Fullsteam
Backed by Aquiline Capital Partners and ADIA, Fullsteam is a dynamic and growing team of 1,700 employees committed to driving innovation and delivering best-in-class software and payment solutions that empower small and medium-sized businesses across numerous industries.
Funding
Current Stage
Late StageTotal Funding
unknownKey Investors
Aquiline Capital PartnersSixth Street
2023-05-25Private Equity
2021-12-02Private Equity
Leadership Team
Recent News
Company data provided by crunchbase