
Application Security Engineer, Information Security
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in Florida, +2 more states.
• Act as the main resource for Ascensus’s application security program
• Safeguard, secure, and appropriately manage confidential Ascensus data
• Create a thorough, agile, and innovative DevSecOps strategy throughout the software development lifecycle
• Offer security advice to scrum teams, application owners, and technology teams on security controls and secure SDLC processes
• Engage in sprint planning and decision-making sessions to incorporate security requirements into development practices
• Execute application security assessments, including architecture reviews, data-flow analysis, penetration-testing support, and threat modeling
• Establish and oversee compliance with application security policies, coding standards, and security controls
• Implement and integrate services that support SAST, DAST, and SCA functions
• Support development teams with static and dynamic testing, triage findings, and provide guidance for remediation
• Serve as a reliable application security advisor and subject matter expert in secure development practices
• Undertake other assigned tasks and projects
• At least 4 years of experience in Secure Software Development and/or DevSecOps (preferred)
• Capability to define software security and privacy requirements
• Strong understanding of threat modeling, risk, and mitigation from both internal and external threats
• Experience in developing system security architecture diagrams and security architecture specifications according to established standards
• Proficient in performing software security design reviews
• Experience in integrating security testing tools into CI/CD pipelines, including SAST, DAST, and SCA
• Familiarity with application testing tools such as Burp Suite, Fiddler, ZAP, Wireshark, and Metasploit
• Experience in configuring WAF, API Gateway, and API security tools
• Strong knowledge of OWASP Top 10 and SANS/CWE Top 25
• Comprehensive understanding of application, database, and network vulnerability testing principles
• Working knowledge of Microsoft SDL, OWASP SAMM, or BSIMM
• Experience in assessing the secure adoption of third-party components, including open-source or commercial software
• Familiarity with information security frameworks such as ISO 27001, NIST, and CSA
• Experience operating in environments regulated under FFIEC, SEC, and/or HIPAA requirements
• Strong understanding of authentication and authorization systems
• Solid grasp of cryptographic standards, including encryption, hashing, key management, and digital signatures
• Ability to provide guidance and mentoring for vulnerability remediation to software engineers in product development
• Skill in translating security risks into business impact
• Experience running or managing vulnerability assessments using automated tools such as Nessus and Qualys
• Experience managing penetration testing engagements
• Understanding of privacy regulations related to information handling and protection
• Experience with fraud detection and analysis for custom-developed applications
• Experience implementing cloud security controls in line with CSA or CSP best practices, including Azure and AWS
• Experience implementing and supporting security automation tools, covering Kubernetes and CSP platform configuration, hardening, and monitoring
• .NET/Java experience is advantageous
• Equal Opportunity Employer
• The employer will never request payment from applicants or require them to purchase equipment
Oregon Health & Science University Foundation
Intel Corporation
Anovia
InductiveHealth Informatics
Get handpicked remote jobs straight to your inbox weekly.