PACCAR

Application Security Engineer

PACCAR$90K — $141K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.
  • 5+ years of application or software security experience, including secure code review and vulnerability assessment.
  • Hands-on experience with DAST (e.g., Burp Suite) and SAST/SCA tools (e.g., Fortify).
  • Proficient in programming languages such as C#, JavaScript, or Python.
  • Strong knowledge of web technologies like HTTP, HTML, CSS, JavaScript.
  • Expert understanding of the OWASP Top 10 and common vulnerabilities.
  • Familiar with SDLC and development methodologies like Agile.

Responsibilities

  • Conduct source code reviews and perform security assessments using SAST tools.
  • Execute assessments on web applications and APIs using DAST tools.
  • Review automated test results and identify false positives.
  • Develop and review threat models to assess security risks proactively.
  • Engage with developers for vulnerability remediation and secure coding support.
  • Collaborate with teams to integrate security practices into CI/CD pipelines.
  • Participate in security culture-building activities and training.

Benefits

  • 401k with up to a 5% company match
  • Employee Stock Purchase Program (ESPP)
  • Fully funded pension plan
  • Comprehensive paid time off including 10 paid vacation days
  • Tuition reimbursement for continued education
  • Medical, dental, and vision plans
  • Flexible spending accounts (FSA) and health savings account (HSA)
Full Job Description
Requisition Summary

As an Application Security Engineer, you will be a key member of the Global Security group within the IT Division at PACCAR and will be reporting directly to the Principal Engineer. You will provide security guidance to development teams, including secure code review and scanning, vulnerability assessments, and security testing to help application teams build and deploy secure applications and APIs.

In this role, you will support security governance and help ensure adherence to application security controls and risk analysis across the organization's application portfolio throughout the SDLC. This includes internally developed applications, third-party developed applications, commercial off-the-shelf (COTS) solutions, and open-source software.

You will utilize a risk-based methodology and "shift-left" approach to engage early in the software development lifecycle, working alongside engineering teams to help prevent security defects before they are introduced. You will contribute to a team culture that values openness, teamwork, continuous improvement, learning, commitment, and empathy.

Job Functions / Responsibilities

Security Assessments & Testing

  • Perform source code reviews using manual analysis and Static Application Security Testing (SAST) tools to identify vulnerabilities.
  • Execute web security assessments on websites, web applications, web services, and APIs using Dynamic Application Security Testing (DAST) tools.
  • Review test results from automated security tools, ensure automated tests complete successfully, and identify and remove false positives from tool reports.
  • Participate in developing and reviewing threat models to proactively identify security risks.


Developer Engagement & Remediation
  • Engage with development teams to provide vulnerability remediation support through consultation or hands-on assistance.
  • Assist developers with understanding security defects, associated risk, and defining acceptable solutions to fix defects.
  • Collaborate with teams to integrate secure coding practices and security tooling into CI/CD pipelines.
  • Contribute to code reviews and design discussions with a security lens.


Security Governance & Standards

  • Support adherence to application security controls and contribute to risk analysis of applications across the SDLC.
  • Participate in the creation, maintenance, and communication of PACCAR secure coding standards, guidelines, and examples.
  • Support the implementation of secure design principles according to organizational policies, standards, and application security patterns.
  • Assist in creating technical security documents including assessment reports and remediation guidance.


Training & Culture

  • Share application security knowledge with the engineering team through brown bags, secure coding tournaments, and developer outreach activities.
  • Actively participate in improving security culture and awareness throughout the organization.
  • Participate in security incident response when needed.


Tooling & Automation

  • Help maintain and tune Secure SDLC tools including SAST, DAST, and Software Composition Analysis (SCA) platforms.
  • Support the integration of security tooling and automated security checks within CI/CD pipelines.
  • Stay current with security technologies, products, and emerging trends relevant to application security.


Qualifications

  • Basic Qualifications
    • Bachelors degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.
    • 5+ years of professional experience in application or software security, including hands-on work in areas such as secure code review, vulnerability assessment, threat analysis, or secure development practices.
    • Hands-on experience with application security testing tools, including DAST platforms (e.g., Burp Suite, WebInspect, OWASP ZAP) and SAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube).
    • Proficiency in one or more programming languages: C#, JavaScript, and/or Python.
    • Strong working knowledge of web application technologies including HTTP, HTML, CSS, JavaScript.
    • Expert-level understanding of the OWASP Top 10 and common web application vulnerabilities and website security concepts such as headers, cookies, CORS, XSS, CSRF.
    • Familiarity with web authentication technologies such as OAuth and/or SAML.
    • Experience with Software Development Life Cycle (SDLC) and development methodologies such as Waterfall and Agile.
    • Experience with control systems: Git, GitHub, Azure DevOps

    Preferred Experience
    • Experience working in a large enterprise environment.
    • Experience with penetration testing or security tools (e.g., Kali Linux, Nmap).
    • Familiarity with cloud environments such as Azure, AWS, or GCP.
    • Certified Secure Software Lifecycle Professional (CSSLP)
    • Certified Information Systems Security Professional (CISSP)
    • CompTIA Security+


Additional Job Board Information

PACCAR Benefits

As a U.S. PACCAR employee, you have a full range of benefit options including:
  • 401k with up to a 5% company match
  • Employee Stock Purchase Program (ESPP)
  • Fully funded pension plan that provides monthly benefits after retirement
  • Comprehensive paid time off - minimum of 10 paid vacation days (additional days are provided with additional seniority/years of service), 12 paid holidays, and sick time
  • Tuition reimbursement for continued education
  • Medical, dental, and vision plans for you and your family
  • Flexible spending accounts (FSA) and health savings account (HSA)
  • Paid short-and long-term disability programs
  • Life and accidental death and dismemberment insurance
  • EAP services that include wellness plans, estate planning, financial counseling and more


The salary range for this position is $90,000 - $141,000 annually. Additionally, this role is eligible for the full range of benefit options listed above.

About PACCAR

PACCAR Careers

Join the PACCAR team today and be part of a global leader known for its commitment to excellence and innovation in the automotive industry. At PACCAR, we offer a range of job opportunities that allow you to put your skills to work in a dynamic environment that fosters growth, leadership, and professional development.

Work You’ll Do

At PACCAR, we believe in empowering our employees to drive their career paths with robust support and resources. Engage in challenging projects that not only enhance your skills but also contribute to groundbreaking innovation and sustainable practices in the truck manufacturing industry.

Explore PACCAR’s Diverse Opportunities

Whether you're looking for a full-time position, an internship, or a leadership role, PACCAR has a place for you. Our team is composed of dedicated professionals who bring their unique perspectives and skills to the table every day. We are committed to diversity and provide comprehensive diversity training to ensure an inclusive culture where everyone feels valued.

Innovate and Lead

Join a company that is at the forefront of the transportation sector, where innovation leads to real-world solutions and market leadership. PACCAR is not just about trucks; it's about technological advancements that revolutionize how the world moves.

Grow and Develop

PACCAR is deeply invested in the professional growth of its employees. With access to cutting-edge tools and technologies, our team members enjoy unparalleled opportunities for career advancement and skill enhancement through continuous learning and development programs.

Benefits and Culture

PACCAR’s culture is built on a foundation of respect, integrity, and excellence. We offer competitive benefits to ensure the well-being of our employees and their families. From health and wellness programs to retirement plans, we provide the benefits that contribute to a healthy and secure future.

Join Our Team

Discover the wide range of employment opportunities at PACCAR. From engineering to sales, and from supply chain management to customer service, your next career step could be just around the corner. We are actively hiring and looking for ambitious individuals who are ready to make an impact.

Networking and Professional Development

At PACCAR, networking and professional development are part of our DNA. Connect with leaders and peers within the company through various networking events, mentorship programs, and professional groups. Enhance your resume and interview skills through our tailored career development sessions and become a prime candidate for advancement within the company.

Stay Connected

Keep up to date with the latest at PACCAR by joining our career network. Receive personalized job alerts and insider tips that match your interests and skills. Explore the exciting and rewarding career opportunities that await at PACCAR.

Search PACCAR Jobs

Ready to take the next step in your career? Search open positions that align with your skills and interests. We look for passionate, curious, and solution-driven team players who are ready to contribute to our legacy of quality and innovation.

Join PACCAR—where your career journey aligns with outstanding innovation and a thriving company culture.

Learn more about PACCAR
Size
28,500 employees
Market Cap
$34.6 billion
Industry
Net Income
$1.2 billion
Founded
1905
5 Year Trend
+6.7%
Revenue
$18.7 billion
NASDAQ

Similar Jobs

More Jobs at PACCAR

More Information Technology Jobs

Find similar Application Security Engineer jobs: