
Lead Application Security Engineer – DevSecOps
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Massachusetts.
• Engage and promote the implementation of essential security best practices throughout the R&D organization.
• Contribute to the enterprise security catalog by developing best practices, techniques, and patterns.
• Enhance the quality and uptake of Security Development Lifecycle practices.
• Oversee the assessment, design, execution, integration, reliability, and ongoing enhancement of application security capabilities.
• Assist with SAST, SCA, DAST, API security testing, and vulnerability management workflows.
• Document, disseminate, and facilitate the automation of coverage for common abuse cases and attack vectors.
• Spearhead the API security testing initiative.
• Manage API discovery, both authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness.
• Identify and articulate feature-level design or architectural vulnerabilities that may lead to security concerns.
• Collaborate with enterprise security leadership to monitor and prioritize outstanding issues and ensure their resolution.
• Work alongside DevOps, Infrastructure, IAM, API Gateway, NOC, Enterprise Security, and application teams to devise and maintain security-enhanced platforms.
• Establish technical strategy, influence stakeholders, and define quantifiable security objectives.
• Bachelor’s degree in Computer Science, Computer Engineering, Cyber Security, or a related field, or equivalent experience.
• A minimum of 3 years of experience as a software developer.
• 3–5 years of experience in a security-oriented development role within an agile framework.
• Proficiency in software and product design and architecture, product security, and the prevention and mitigation of security issues.
• Strong foundation in software engineering principles.
• Capability to develop, review, and troubleshoot code in one or more programming languages.
• Practical experience with Docker and Terraform.
• In-depth knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication.
• Solid understanding of RESTful services, service bus architectures, JSON, and related web services concepts.
• Familiarity with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls.
• Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD processes.
• Knowledge of HIPAA, HITRUST, and PCI-DSS is advantageous.
• Comprehensive health and financial benefits.
• Commuter support.
• Employee assistance programs.
• Tuition assistance.
• Employee resource groups.
• Collaborative workspaces.
• Flexible work arrangements and support for work-life balance.
• Company events such as book clubs, guest speakers, and hackathons.
• A culture focused on learning and development.
• Supportive team environment.
• Inclusive workplace atmosphere.
• Annual discretionary bonus plan, variable compensation plan, and equity plans (subject to role eligibility).
Samsara
EVERSANA
New Charter Technologies
KLA
Get handpicked remote jobs straight to your inbox weekly.