Application Security Engineer

AssetMark, Inc.

$130K — $140K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7 to 12 years of experience in application security, product security, SaaS security or related fields.
  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, or equivalent experience.
  • Hands-on experience with vulnerability management and application security testing tools like Rapid7 and Arnica.
  • Knowledge of cloud platforms and CI/CD environments, including Azure and GitHub.
  • Experience with securing Salesforce environments and related technologies.
  • Scripting and automation skills using PowerShell, Python, or IaC tools.
  • Certifications such as CSSLP, CISSP, GIAC, or cloud security credentials.

Responsibilities

  • Design, enhance, and implement application and SaaS security controls across platforms.
  • Collaborate with development and product teams to incorporate security into software lifecycles.
  • Conduct threat modeling and security architecture reviews for various application elements.
  • Perform vulnerability assessments and lead remediation efforts.
  • Review SaaS security configurations, especially in critical platforms like Salesforce.
  • Support various application security testing methodologies.
  • Investigate security incidents and recommend corrective measures.

Benefits

  • Hybrid work schedule, combining remote and in-office work.
  • Opportunity to engage with a collaborative team across multiple disciplines.
  • Involvement in enhancing security for both internal applications and SaaS solutions.
  • Development of security standards and reusable control patterns in a dynamic environment.
Full Job Description
We can only consider candidates for this position who are able to accommodate a hybrid work schedule and are close to our Atlanta, GA office.

Responsibilities:

The Application / SaaS Security Engineer is responsible for strengthening the security of internally developed applications and enterprise SaaS platforms across the organization and its product and service lines. This role partners with development, product, platform, and business application teams to assess risk, define security requirements, improve configurations, and support remediation.

An ideal candidate combines hands on application security knowledge with practical SaaS security experience and a collaborative, problem solving approach.
  • Design, enhance, test, and implement application and SaaS security controls across enterprise platforms and internally developed solutions.
  • Partner with development, product, platform, and SaaS administration teams to integrate security requirements into the software development and application change lifecycles.
  • Perform threat modeling and security architecture reviews for applications, APIs, integrations, authentication flows, and sensitive data paths.
  • Conduct scheduled and on demand vulnerability assessments using tools such as Rapid7 and Arnica, and coordinate risk based remediation with technical owners.
  • Review SaaS security configurations, roles, permissions, integrations, logging, and data protection controls, with emphasis on Salesforce and other critical platforms.
  • Support application security testing, including static analysis, dynamic analysis, software composition analysis, secrets detection, and penetration testing.
  • Investigate application and SaaS security incidents and recommend corrective actions to reduce the likelihood of recurrence.
  • Develop security standards, reusable control patterns, and automated evidence collection for application and SaaS environments.
  • Perform special projects as assigned, while effectively managing time with competing priorities.


Knowledge, Skills & Abilities:
  • Working knowledge of secure software development practices, the OWASP Top 10, threat modeling, API security, and common authentication and authorization patterns
  • Hands on experience with vulnerability management or application security testing tools, including Rapid7, Arnica, or comparable platforms
  • Experience assessing and securing enterprise SaaS platforms, including identity, permissions, integrations, logging, and sensitive data protection
  • Working knowledge of cloud service platforms and CI/CD or DevOps environments, including Azure, GitHub, or comparable technologies
  • Strong communication and collaborative skills, with demonstrated ability to work directly with development and application owner teams


Education & Experience:
  • 7 to 12 years of experience in application security, product security, SaaS security, cybersecurity, or information technology
  • BS degree in Cybersecurity, Computer Science, Software Engineering, or equivalent education and experience
  • Experience securing Salesforce, including profiles, permission sets, connected applications, APIs, integrations, and event monitoring
  • Hands on experience with static analysis, dynamic analysis, software composition analysis, secrets scanning, and penetration testing tools
  • Experience with SaaS security posture management, cloud access security broker technologies, or CrowdStrike Falcon Shield
  • Experience with scripting and automation using PowerShell, Python, APIs, or Infrastructure as Code, and integrating security requirements into JIRA or engineering workflows
  • Supporting certifications such as CSSLP, CISSP, GIAC, Salesforce, or cloud security certifications


Compensation: The Base Salary range for this position is between $130,000-$140,000.

This information reflects a base salary range that AssetMark reasonably expects to pay for the position based on a number of factors which may include job-related knowledge, skills, education, experience, and actual work location. This position will also be eligible for additional variable incentive compensation and competitive benefits.

Candidates must be legally authorized to work in the US to be considered. We are unable to provide visa sponsorship for this position.

#LI-hybrid





Similar Jobs

More Jobs at AssetMark, Inc.

More Information Technology Jobs

Find similar Application Security Engineer jobs: