Koch Industries

Application Security Engineer

Koch Industries$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in application security and secure coding practices.
  • Strong understanding of web application frameworks like React.js and ASP.NET.
  • Proficient in using SAST, SCA, and DAST tools to identify vulnerabilities.
  • Familiar with cloud security principles, especially within AWS or Azure.
  • Ability to work collaboratively across teams and influence security outcomes without direct authority.

Responsibilities

  • Partner with development teams to integrate security best practices into their workflow.
  • Identify and prioritize web application vulnerabilities and consult on mitigations.
  • Plan, execute, and manage tasks effectively with self-direction.
  • Design training sessions for developers on secure coding and risk assessment.
  • Enhance Application Security Testing platforms, minimizing false positives with developers' collaboration.
  • Conduct proactive code reviews and promote a Secure Development Lifecycle within engineering.
  • Provide expert security advice in stakeholder meetings and on various projects.

Benefits

  • Medical, dental, and vision coverage.
  • Flexible spending and health savings accounts.
  • Life and disability insurance.
  • Retirement plan options.
  • Paid vacation and time off.
  • Educational assistance and support for professional development.
  • Parenting and adoption assistance programs.
Full Job Description
Your Job

As the Application Security Engineer, you will be dedicated to strengthening and expanding our application security posture. You will collaborate closely with development, engineering, product, and other teams during every stage of the software development lifecycle (SDLC), and your insights will influence broader security initiatives throughout the organization. Within the GP Cyber Security Organization, this position is crucial in shaping the future of security at Georgia-Pacific. You will be part of a larger team comprised of Vulnerability Management, Security Operations, Application Security, and GRC capabilities.

This role is based in Atlanta, GA at the GP HQ on Peachtree St. Expectation is three days in office per week.

Our Team

The Application Security team within GP Cyber Security is focused on reducing risk across the software development lifecycle by embedding secure development practices, operating our application security testing platforms, and driving vulnerability remediation. We partner closely with development, engineering, and product teams to deliver risk-based insights that enable secure, profitable business decisions. The team manages and tunes our application security tooling and collaborates with stakeholders onboarding applications into those tools to identify vulnerabilities and drive timely remediation across the enterprise.

What You Will Do
  • Partner with development teams to embed security standards and best practices into their work processes
  • Identify web application vulnerabilities, prioritize and risk-adjust findings, consult on mitigation strategies, and ensure timely resolution
  • Demonstrate self-motivation and direction while applying strong organizational and project management skills to plan, execute, and complete tasks in a timely and efficient manner
  • Design and deliver training sessions for developers and stakeholders on secure coding practices, threat modeling, and risk assessment
  • Mature our Application Security Testing (GHAS/Orca) platforms, collaborating with developers to address findings and minimize false positives
  • Lead proactive code reviews to pinpoint vulnerabilities while refining and incorporating the Secure Development Lifecycle into our engineering processes
  • Offer specialized application security guidance on projects, system issues, and in stakeholder meetings, including guidance on relevant industry standards and practices such as OWASP and CIS
  • Assist in developing and maintaining an ongoing security assurance program, including appropriate scripts and monitoring capabilities to verify security effectiveness, analyze data, develop trend analysis, and ensure compliance with existing standards, policies, and procedures
  • Conduct technical security risk assessments with internal and external resources as needed


Who You Are (Basic Qualifications)
  • Experience testing and identifying vulnerabilities in web applications that utilize industry-standard frameworks such as React.js, Next.js, ASP.NET, and the .NET Framework
  • Experience analyzing code and prioritizing findings using SAST, SCA, and DAST for security vulnerabilities
  • Experience with programming and scripting languages (e.g., Python, PowerShell, C#, Java) and modern development practices such as CI/CD, containers, microservices, and infrastructure-as-code
  • Experience securing cloud environments (AWS and/or Azure), including IAM, security groups, and other native cloud security controls
  • Experience partnering across teams and influencing without direct authority to achieve business outcomes
  • Must have legal authorization to work permanently in the United States for any employer without requiring a visa transfer or visa sponsorship


What Will Put You Ahead
  • Experience with citizen development within ServiceNow
  • Experience troubleshooting network security controls, firewalls, and remote access technologies
  • Experience aggregating data from various sources for security analysis and reporting (e.g., scripting, SQL, PowerShell, Python, .NET, Java, JavaScript, Go)
  • Experience building tools utilizing AI, LLM, machine learning, and code analysis platforms
  • Application security certifications (e.g., EC-Council Certified Application Security Engineer (CASE), Offensive Security Certified Professional (OSCP), etc.)
  • AWS Certified Solutions Architect or comparable certification


Any compensation range provided for a role is an estimate determined by available market data. The actual amount may be higher or lower than the range provided considering each candidate's knowledge, skills, abilities, and geographic location. If you have questions, please speak to your recruiter about the flexibility and detail of our compensation philosophy.

Hiring Philosophy

All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers. Learn more about our hiring philosophy here.

Our Benefits

Our goal is for each employee, and their families, to live fulfilling and healthy lives. We provide essential resources and support to build and maintain physical, financial, and emotional strength focusing on overall wellbeing so you can focus on what matters most. Our benefits plan includes medical, dental, vision, flexible spending and health savings accounts, life insurance, ADD, disability, retirement, paid vacation/time off, educational assistance, and may also include infertility assistance, paid parental leave and adoption assistance. Specific eligibility criteria is set by the applicable Summary Plan Description, policy or guideline and benefits may vary by geographic region. If you have questions on what benefits apply to you, please speak to your recruiter.

#LI-GM1

About Koch Industries

Koch Industries, Inc. is an American privately-held multinational conglomerate corporation based in Wichita, Kansas. Its subsidiaries are involved in the manufacturing, refining, and distribution of petroleum, chemicals, energy, fiber, intermediates and polymers, minerals, fertilizers, pulp and paper, chemical technology equipment, ranching, finance, commodities trading, and investing. Koch owns Infor, Invista, Georgia-Pacific, Molex, Flint Hills Resources, Koch Pipeline, Koch Fertilizer, Koch Minerals, Matador Cattle Company, i360, and Guardian Industries. The firm employs 120,000 people in 60 countries, with about half of its business in the United States. The company is the largest non-Canadian landowner in the Athabasca oil sands. With annual revenues of $110 billion by 2014, the company is the largest privately held company in the United States. In 2007, it was ranked as the largest privately held company. If Koch Industries had been a public company in 2013, it would have ranked 17th in the Fortune 500. The company was founded by its namesake, Fred C. Koch, in 1940 after he developed an innovative crude oil refining process. Fred C. Koch died in 1967 and his majority interest in the company was split amongst his four sons. In June 1983, after a bitter legal and boardroom battle, the stakes of Frederick R. Koch and William "Bill" Koch were bought out for $1.1 billion and Charles Koch and David Koch became majority owners in the company. Charles owns 42% of the company; trusts for the benefit of Elaine Tettemer Marshall and Elaine's children, Preston Marshall and E. Pierce Marshall Jr., own 16% of the company. The heirs of David Koch, who died on August 23, 2019, own the balance, 42%, of the corporation.
Learn more about Koch Industries
Industry
Founded
1940

Similar Jobs

More Jobs at Koch Industries

More Information Technology Jobs

Find similar Application Security Engineer jobs: