
Senior Application Security Engineer
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in India.
• Collaborate with Engineering and Infrastructure teams to identify and address any security vulnerabilities in our SDLC, cloud infrastructure, and related processes.
• Embed security practices into the Software/Infrastructure workflows, from initial threat modeling to the decommissioning phase.
• Conduct manual penetration testing for web and mobile applications as well as APIs.
• Review source code and perform audits for significant application changes.
• Assist teams in recognizing security vulnerabilities and their associated risks, offering guidance in prioritization and remediation efforts.
• Identify critical security threats and spearhead mitigation efforts with engineering teams.
• Oversee collaboration and communication among cross-functional internal and external teams.
• Implement security services and tools through Infrastructure as Code (IaC), while actively fostering a culture of security as code.
• Conduct periodic security assessments and configuration reviews of cloud environments.
• Develop custom security solution tools and automation while leading security initiatives.
• Promote and scale DevSecOps throughout the organization, facilitating the integration of tools and practices as teams transition to DevSecOps.
• A minimum of 10 years of experience in a security engineering role, with a focus on application security and cloud security.
• Strong knowledge of Linux operating systems and cloud environments such as Amazon AWS and GCP, including networking concepts and security services and patterns.
• Understanding of core AWS Cloud Services (e.g., EC2, ECS, Lambda, RDS, etc.) architecture (e.g., Well-Architectured Framework) and microservices.
• Experience in implementing secure Infrastructure as Code (IaC) solutions.
• Familiarity with container-based architecture and deployments (Docker, Kubernetes).
• Practical experience in penetration testing for web applications and APIs.
• Thorough understanding of the OWASP Top 10 and CWE 25.
• Proficient in using SAST, DAST, IAST, and SCA tools.
• Experience in Threat Modeling.
• Effective communication skills, with the ability to present security threats and risks to engineering teams.
• Self-motivated with the capability to work independently on new initiatives.
• Jumio is a diverse collaboration of individuals with varied ideas, strengths, interests, and cultures. We welcome applications from candidates of all backgrounds and statuses.
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.