Application Security Engineer - Job Description (JD)Job Title Application Security Engineer (AppSec Engineer) Job Summary We are seeking an experienced
Application Security Engineer to ensure the security of software applications throughout the Software Development Life Cycle (SDLC). The ideal candidate will identify security vulnerabilities, conduct secure code reviews, perform application security testing, implement DevSecOps practices, and collaborate with development teams to build secure applications.
Key Responsibilities - Integrate security practices into the SDLC (Secure SDLC).
- Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Conduct secure code reviews for web, mobile, and backend applications.
- Identify, assess, and remediate application security vulnerabilities.
- Perform threat modeling and security risk assessments.
- Implement DevSecOps security controls in CI/CD pipelines.
- Conduct penetration testing and vulnerability assessments.
- Validate authentication, authorization, session management, and API security.
- Secure cloud-native and containerized applications.
- Collaborate with developers, DevOps, QA, and infrastructure teams.
- Develop security standards, guidelines, and best practices.
- Support compliance with industry regulations and security frameworks.
Required Skills Application Security - Secure Software Development Life Cycle (SSDLC)
- Secure Coding Practices
- Threat Modeling
- Secure Design Principles
- Risk Assessment
- Vulnerability Management
- Security Architecture
- Security Code Reviews
Security Testing - Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Software Composition Analysis (SCA)
- Runtime Application Self-Protection (RASP)
- Mobile Application Security Testing (MAST)
- API Security Testing
Security Tools - Burp Suite
- OWASP ZAP
- Checkmarx
- Veracode
- Fortify
- SonarQube
- Snyk
- GitHub Advanced Security
- Semgrep
- Trivy
- Nessus
- Nmap
Programming Languages Knowledge of one or more:
- Java
- Python
- C#
- JavaScript
- TypeScript
- Go
- PHP
- Kotlin
- Swift
Understanding of:
- Object-Oriented Programming (OOP)
- Secure Coding Standards
- Input Validation
- Error Handling
Web Security - OWASP Top 10
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Server-Side Request Forgery (SSRF)
- XML External Entity (XXE)
- Insecure Direct Object References (IDOR)
- Remote Code Execution (RCE)
- Command Injection
- Clickjacking
- Content Security Policy (CSP)
API Security - REST API Security
- GraphQL Security
- OAuth 2.0
- OpenID Connect (OIDC)
- JWT
- API Gateway Security
- Rate Limiting
- API Authentication & Authorization