Application Security Engineer

Ova Technologies

$120K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of application security expertise
  • Proficient in Secure Software Development Life Cycle (SSDLC)
  • Strong knowledge of secure coding practices and principles
  • Experience with application security testing tools (SAST, DAST, SCA)
  • Familiarity with security compliance regulations and frameworks
  • Solid understanding of common web and API security vulnerabilities
  • Programming proficiency in languages such as Java, Python, or JavaScript.

Responsibilities

  • Integrate security into the software development process (SDLC)
  • Perform comprehensive application security testing (SAST, DAST, SCA)
  • Conduct secure code reviews for various application types
  • Identify and remediate application vulnerabilities and security risks
  • Execute threat modeling and risk assessments proactively
  • Implement DevSecOps practices within continuous integration and delivery pipelines
  • Collaborate cross-functionally with development, QA, and operations teams to enhance security.

Benefits

  • Flexible working hours
  • Health and wellness programs
  • Professional development and training opportunities
  • Opportunity to work with cutting-edge security tools
  • Collaborative and inclusive company culture
Full Job Description
Application Security Engineer - Job Description (JD)

Job Title

Application Security Engineer (AppSec Engineer)

Job Summary

We are seeking an experienced Application Security Engineer to ensure the security of software applications throughout the Software Development Life Cycle (SDLC). The ideal candidate will identify security vulnerabilities, conduct secure code reviews, perform application security testing, implement DevSecOps practices, and collaborate with development teams to build secure applications.

Key Responsibilities
  • Integrate security practices into the SDLC (Secure SDLC).
  • Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Conduct secure code reviews for web, mobile, and backend applications.
  • Identify, assess, and remediate application security vulnerabilities.
  • Perform threat modeling and security risk assessments.
  • Implement DevSecOps security controls in CI/CD pipelines.
  • Conduct penetration testing and vulnerability assessments.
  • Validate authentication, authorization, session management, and API security.
  • Secure cloud-native and containerized applications.
  • Collaborate with developers, DevOps, QA, and infrastructure teams.
  • Develop security standards, guidelines, and best practices.
  • Support compliance with industry regulations and security frameworks.

Required Skills

Application Security
  • Secure Software Development Life Cycle (SSDLC)
  • Secure Coding Practices
  • Threat Modeling
  • Secure Design Principles
  • Risk Assessment
  • Vulnerability Management
  • Security Architecture
  • Security Code Reviews

Security Testing
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Interactive Application Security Testing (IAST)
  • Software Composition Analysis (SCA)
  • Runtime Application Self-Protection (RASP)
  • Mobile Application Security Testing (MAST)
  • API Security Testing

Security Tools
  • Burp Suite
  • OWASP ZAP
  • Checkmarx
  • Veracode
  • Fortify
  • SonarQube
  • Snyk
  • GitHub Advanced Security
  • Semgrep
  • Trivy
  • Nessus
  • Nmap

Programming Languages

Knowledge of one or more:
  • Java
  • Python
  • C#
  • JavaScript
  • TypeScript
  • Go
  • PHP
  • Kotlin
  • Swift

Understanding of:
  • Object-Oriented Programming (OOP)
  • Secure Coding Standards
  • Input Validation
  • Error Handling

Web Security
  • OWASP Top 10
  • SQL Injection (SQLi)
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Server-Side Request Forgery (SSRF)
  • XML External Entity (XXE)
  • Insecure Direct Object References (IDOR)
  • Remote Code Execution (RCE)
  • Command Injection
  • Clickjacking
  • Content Security Policy (CSP)

API Security
  • REST API Security
  • GraphQL Security
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • JWT
  • API Gateway Security
  • Rate Limiting
  • API Authentication & Authorization

Similar Jobs

More Jobs at Ova Technologies

  • Mobile Test Engineer
    $100K — $120K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • DevTest Engineer
    $110K — $130K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Tableau Developer
    $110K — $130K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Edge AI Engineer
    $130K — $155K *
    New York, NY 10025 (New York County)
    Consumer Technology
    Hybrid
  • SAP Developer
    $95K — $115K *
    Alpharetta, GA 30022 (Fulton County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Application Security Engineer jobs: