
Senior Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Model threats related to authentication and session management, privilege escalation paths, integration boundaries, tenant isolation, cryptographic handling, and secrets management.
• Establish security requirements during the architecture and design phases.
• Provide guidance to product and engineering leadership on risk acceptance and release decisions.
• Submit, evaluate, and implement security fixes in product repositories where commit access is granted.
• Oversee static analysis, dependency scanning, and dynamic testing across all product lines.
• Optimize security tools and direct findings to the appropriate engineering teams.
• Enhance secure coding practices within .NET and Java codebases through patterns, libraries, reference implementations, and code reviews.
• Define review and automated remediation strategies for AI-generated code.
• Manage product vulnerability responses from intake through triage, coordinated disclosure, CVE processing, and customer advisories.
• Translate penetration testing and bug bounty findings into actionable fixes and systemic improvements.
• Oversee software composition analysis and SBOM generation, incorporating license and provenance data.
• Generate product security documentation for customer questionnaires, security assessments, and certification processes.
• Collaborate across all product lines as the security representative integrated within engineering.
• A minimum of six years in software engineering or security, with at least three years focused on application or product security.
• Equivalent experience may be considered.
• Proven application security experience on products that customers deploy and manage independently.
• Proficiency in C# and .NET, with enough versatility to contribute within a Java codebase.
• Capability to read and write production-level code.
• Recent hands-on experience with AI-assisted development or AI-enabled security tools within the last six months.
• A well-formed perspective on the integration of AI in the security review process.
• Background in threat modeling during the design phase.
• Familiarity with static, dynamic, and software composition analysis tools.
• Understanding of identity and authentication protocols, including OAuth, OIDC, SAML, and SCIM.
• Experience with coordinated vulnerability disclosure and CVE management.
• Secure code review experience across web and API surfaces.
• Knowledge of SBOM standards and license compliance is beneficial.
• Experience in cryptographic reviews is advantageous.
• Participation in security champions programs is a plus.
• Experience with PCI DSS or FedRAMP applied to a product is beneficial.
• Prior experience in product engineering is advantageous.
• Health and wellness programs.
• Opportunities for career development and learning.
• Commitment to equal employment opportunities and a non-discriminatory workplace.
INFICON
INFICON
GE Aerospace
Aeroflow Health
Get handpicked remote jobs straight to your inbox weekly.