Hampton North · 5 hours ago
Senior Application Security Engineer
Maximize your interview chances
Insider Connection @Hampton North
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Collaborate with software development teams to integrate security best practices throughout the software development lifecycle (SDLC).
Conduct security assessments, including code reviews, threat modeling, and vulnerability scanning of web, mobile, and cloud applications.
Identify, triage, and recommend remediation strategies for application vulnerabilities such as OWASP Top 10 and SANS/CWE Top 25 issues.
Design and implement application security tools and automation frameworks to improve efficiency in detecting and remediating vulnerabilities.
Stay updated on the latest security trends, tools, technologies, and threat intelligence to proactively address potential risks.
Develop and maintain security standards, policies, and guidelines for application development.
Provide security training and guidance to developers and other technical staff to foster a security-first culture.
Assist in incident response activities related to application-level threats, including analyzing root causes and implementing preventive measures.
Participate in compliance and regulatory efforts by ensuring applications meet required standards.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
3+ years of experience in application security or a related field, with at least 1 year in a mid to senior role.
Strong knowledge of secure coding practices and frameworks, such as OWASP, NIST, or ISO 27001.
Proficiency in at least one programming language (e.g., Python, Java, C#, JavaScript).
Hands-on experience with security tools such as SAST, DAST, RASP, and vulnerability management platforms.
Understanding of cloud security principles for platforms like AWS, Azure, or Google Cloud.
Excellent communication and collaboration skills, with the ability to translate complex security concepts to technical and non-technical audiences.
Preferred
Professional certifications such as CISSP, CSSLP, OSWE, or CEH.
Experience with DevSecOps practices and integrating security into CI/CD pipelines.
Familiarity with containerization and orchestration technologies (e.g., Docker, Kubernetes).
Knowledge of identity and access management (IAM) principles and tools.