Application Security Engineer, Information Security

Posted 12 hours ago

This is a fully remote position, open to applicants in Florida, +2 more states.

📋 Description

• Act as the main resource for Ascensus’s application security program

• Safeguard, secure, and appropriately manage confidential Ascensus data

• Create a thorough, agile, and innovative DevSecOps strategy throughout the software development lifecycle

• Offer security advice to scrum teams, application owners, and technology teams on security controls and secure SDLC processes

• Engage in sprint planning and decision-making sessions to incorporate security requirements into development practices

• Execute application security assessments, including architecture reviews, data-flow analysis, penetration-testing support, and threat modeling

• Establish and oversee compliance with application security policies, coding standards, and security controls

• Implement and integrate services that support SAST, DAST, and SCA functions

• Support development teams with static and dynamic testing, triage findings, and provide guidance for remediation

• Serve as a reliable application security advisor and subject matter expert in secure development practices

• Undertake other assigned tasks and projects


⛳️ Requirements

• At least 4 years of experience in Secure Software Development and/or DevSecOps (preferred)

• Capability to define software security and privacy requirements

• Strong understanding of threat modeling, risk, and mitigation from both internal and external threats

• Experience in developing system security architecture diagrams and security architecture specifications according to established standards

• Proficient in performing software security design reviews

• Experience in integrating security testing tools into CI/CD pipelines, including SAST, DAST, and SCA

• Familiarity with application testing tools such as Burp Suite, Fiddler, ZAP, Wireshark, and Metasploit

• Experience in configuring WAF, API Gateway, and API security tools

• Strong knowledge of OWASP Top 10 and SANS/CWE Top 25

• Comprehensive understanding of application, database, and network vulnerability testing principles

• Working knowledge of Microsoft SDL, OWASP SAMM, or BSIMM

• Experience in assessing the secure adoption of third-party components, including open-source or commercial software

• Familiarity with information security frameworks such as ISO 27001, NIST, and CSA

• Experience operating in environments regulated under FFIEC, SEC, and/or HIPAA requirements

• Strong understanding of authentication and authorization systems

• Solid grasp of cryptographic standards, including encryption, hashing, key management, and digital signatures

• Ability to provide guidance and mentoring for vulnerability remediation to software engineers in product development

• Skill in translating security risks into business impact

• Experience running or managing vulnerability assessments using automated tools such as Nessus and Qualys

• Experience managing penetration testing engagements

• Understanding of privacy regulations related to information handling and protection

• Experience with fraud detection and analysis for custom-developed applications

• Experience implementing cloud security controls in line with CSA or CSP best practices, including Azure and AWS

• Experience implementing and supporting security automation tools, covering Kubernetes and CSP platform configuration, hardening, and monitoring

• .NET/Java experience is advantageous


🏝️ Benefits

• Equal Opportunity Employer

• The employer will never request payment from applicants or require them to purchase equipment

People also viewed

Oregon Health & Science University Foundation7 hours ago

Application Engineer

US flagUnited States OnlyFull-timeApplication Engineer$107.4k – $162.6k/year
ApplyView job
Intel Corporation9 hours ago

Application Engineer

CN flagChina OnlyFull-timeApplication Engineer
ApplyView job
Anovia16 hours ago

Application Support Engineer, ROL Testing

IN flagIndia OnlyFreelanceApplication Engineer₹2M – ₹2.5M/year
ApplyView job
InductiveHealth Informatics17 hours ago

Application Support Engineer

US flagUnited States OnlyFull-timeApplication Engineer$95k – $105k/year
ApplyView job
Smile Digital Health18 hours ago

Senior Application Support Engineer

CA flagCanada OnlyFull-timeApplication EngineerC$110k – C$120k/year
ApplyView job
MBL Technologies Inc.19 hours ago

Senior Application Security Engineer

US flagDistrict of Columbia, +1 more stateFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers