
Senior Security Engineer II – Application Security
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in Maryland.
• Create, develop, and manage solutions that consistently enhance and automate security functionalities.
• Collaborate across various teams and stakeholders.
• Utilize data to analyze security trends, metrics, and opportunities for strengthening security posture.
• Lead and improve incident and issue response initiatives, including analysis, containment, and mitigation strategies.
• Develop and refine security documentation, encompassing policies, standards, baselines, and standard operating procedures.
• Provide mentorship and guidance to junior engineers or analysts.
• Design, implement, and maintain security services that support the business.
• Drive significant outcomes and enhance the security of the digital environment.
• Bachelor’s degree (BS/BTech) or higher in Computer Science, Information Technology, Cybersecurity, or a related field, or 10 years of experience in the security domain without a degree.
• Over 6 years of experience in securing and deploying applications in Cloud Native environments.
• More than 3 years of experience in a dedicated application security role focused on establishing secure SDLC and DevSecOps processes.
• Familiarity with health-tech systems, including Electronic Health Records, clinical data, and PHI; direct experience is preferred.
• Experience in architecting, developing, and deploying large-scale distributed systems.
• Extensive experience in identifying, evaluating, and triaging vulnerabilities using SAST/DAST methodologies and tools.
• Proven track record in conducting code reviews and threat modeling.
• Significant experience in developing automated security testing and validation systems using Terraform, CloudFormation, Python, etc.
• Proficient in programming languages such as Python, R, C++, and JavaScript.
• Extensive experience in AWS/Azure/GCP software development environments.
• Proven ability to implement security controls for web-based SaaS applications, including API Security and WAF.
• Deep understanding of AI/LLM and machine learning architectures, along with best practices for securing them.
• Comprehensive knowledge of OWASP Top 10 vulnerabilities and best practices for containment and remediation.
• Strong familiarity with server-side web technologies, such as Java, Python, Scala, C#, C++, and Go.
• At least 4 years of experience serving as a trusted technical decision-maker in a team environment.
• Must be capable of sitting for extended periods.
• Flexible work schedules with remote work options available for many positions.
• Health, dental, and vision insurance covered up to 80% for employees, dependents, and domestic partners.
• Comprehensive time-off plan providing 21 days of PTO in the first year.
• Two paid volunteer days and 11 paid holidays.
• 12 weeks of paid parental leave for all new parents.
• Six weeks of paid sabbatical after six years of service.
• Educational Assistance Program and Clinical Employee Reimbursement Program.
• 401(k) plan with up to 4% matching.
• Stock options available.
• Additional comprehensive benefits package and time off to promote work-life balance.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.