Application Security Engineer

Kestra Holdings

$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, IT, or related field.
  • 2+ years of experience in application security or a similar role.
  • Strong understanding of OWASP Top 10 vulnerabilities.
  • Proficiency in Python and familiarity with Javascript, Bash, Powershell, and C#.
  • Hands-on experience with CI/CD tools and securing DevOps processes.

Responsibilities

  • Secure software development by embedding security measures in every phase.
  • Manage and oversee security tools and technology solutions.
  • Conduct regular security assessments, code reviews, and penetration testing.
  • Integrate security tools and standards into the CI/CD pipeline.
  • Collaborate with IT and development teams on secure architectural design.
  • Promote a culture of security and provide coding training for developers.
  • Maintain up-to-date documentation on DevSecOps practices and secure development.
  • Stay informed on the latest security trends and vulnerabilities.

Benefits

  • Competitive pay and comprehensive benefits from a large employer (over 1600 employees).
  • 401(k) plan and health insurance options.
  • Supportive and collaborative work environment focused on professional excellence.
  • Impactful work helping clients make informed financial decisions.
  • Growth opportunities through training and development programs.
  • Tuition reimbursement for eligible educational expenses.
Full Job Description
The Application Security Engineer will be pivotal in integrating security into our development and operations processes. As an expert in development and security, the ideal candidate will foster a culture of shared security responsibility across the entire organization. This position requires a balance of application security know-how and some DevOps experience. What you'll Do: - Secure Software Development: Ensure security measures are embedded throughout the development lifecycle. - Tool Management: Manage security tools and solutions. - Security Assessments: Perform regular security assessments, code reviews, and penetration tests. - Automation: Integrate security tools, standards, and processes into the CI/CD pipeline and KPI reporting. - Collaboration: Partner closely with IT and development teams to ensure secure architectural designs and to address application security concerns. - Training & Culture: Advocate for a strong security culture and provide development teams with secure coding training and resources to help them build secure applications from the start. - Documentation: Maintain DevSecOps and secure software development documentation to ensure accuracy. - Continuous Learning: Stay up-to-updated with security trends, vulnerabilities, and best practices. What You Bring: - Bachelor's degree in computer science, IT, or related field. - 2+ years of proven experience in a similar role. - A strong understanding of the OWASP Top 10 vulnerabilities. - Proficiency in Python and basic Javascript, Bash, Powershell, and C# knowledge. - Hands-on experience with CI/CD tools and integrating security into DevOps processes. Internal Application Policy: Internal applicants must be in good standing and have a minimum of 1 year of service with Kestra. Internal applicants must also have a minimum of 1 year service in current role unless approved by EVP. Benefits to support you: - Competitive pay and benefits with a large employer (over 1600 employees nationwide) - 401(k), health insurance, and a competitive benefits package - Work in a supportive, collaborative environment committed to professional excellence - Help clients navigate meaningful financial decisions with confidence - Opportunities for training, development, and long-term growth within the firm - Tuition reimbursement for qualified expenses

Similar Jobs

More Jobs at Kestra Holdings

More Information Technology Jobs

Find similar Application Security Engineer jobs: