Job SummaryThe Application Security Engineer will join the Productivity and Collaboration fleet within Workforce Technology to strengthen the security, quality, and resilience of applications and services used across the firm. This role focuses on reviewing, hardening, and improving code across internal .NET repositories to meet the highest standards of secure engineering while collaborating with development squads throughout the software development lifecycle.
Key Responsibilities- Review and harden code across internal .NET Framework applications and services.
- Automate security improvements using PowerShell to analyze and harden code repositories.
- Embed secure coding practices throughout the software development lifecycle in partnership with development squads.
- Remediate security findings raised through code reviews and security tooling.
- Enhance automated security testing within CI/CD pipelines.
- Perform code reviews and contribute to secure-by-design standards, patterns, and guidance.
- Support agile principles by participating in retrospectives, demos, and team collaboration.
Required Qualifications- 8+ years of software development experience.
- Strong hands-on expertise with .NET Framework (C#, ASP.NET).
- Demonstrable application security experience including secure coding, code review, and remediation.
- Familiarity with OWASP standards and secure development practices.
- Hands-on experience with CI/CD pipelines and Agile development (Scrum, Kanban).
- Understanding of SDLC and secure CI/CD processes.
- Experience with Jira or other issue-tracking systems.
Preferred Qualifications- Experience with .NET Core.
- Proficiency in PowerShell scripting.
- Exposure to SAST/DAST tools for security testing.
- Threat modeling experience.
- Secure software development certification (e.g., CSSLP).
- Knowledge of SQL and database design.
Certifications- Secure software development certifications (CSSLP or equivalent) preferred.