Description Job Overview and ResponsibilitiesThe Engineer- Application Cybersecurity helps validate that our services, applications, and websites are designed and implemented in accordance with United's secure development standards. The engineer works closely with development teams, product teams, and other teams across the organization to integrate security into the product lifecycle from design through deployment.
The engineer will support the enforcement of security requirements, performing application security assessments, and providing developers with remediation guidance and advice.
- Improve the accessibility of security through automation, continuous integration pipelines, and other means including but not limited to developing and maintaining CI/CD templates
- Perform code analysis of applications, manually and using application security testing solutions including mobile application security tests as well as conducting manual vulnerability analysis, and assisting product teams with vulnerability remediation
- Research, define and communicate security best practices and standards and ensure products development teams understand them
- Support security architecture design reviews and threat modelling of our products
QualificationsWhat's needed to succeed (Minimum Qualifications):- Bachelor's degree (STEM field preferred)
- Minimum of 2 years of experience in related field
- Ability to automate processes and boost tooling maturity through scripting (Python preferred) or coding
- Working knowledge of OWASP Top 10 and/or CWE 25
- Basic understanding of DevSecOps (e.g., CI/CD)
- Working knowledge with application testing (e.g., SAST, DAST, MAST, RAST, IAST)
- Working knowledge of programming languages and scripting
- Basic understanding of SDLC process
- Basic understanding of web and app security stack (e.g., API security)
- Basic understanding of cloud technologies and security
- Working knowledge with technical documentation / Standard Operating Procedures (SOPs) creation
- Ability to work independently and self-motivate
- Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills
- Must be legally authorized to work in the United States for any employer without sponsorship
- Successful completion of interview required to meet job qualification
- Reliable, punctual attendance is an essential function of the position
What will help you propel from the pack (Preferred Qualifications):- AWS Certified Solutions Architect - Associate
- Certified Application Security Engineer
- Experience with AWS technologies
- Working knowledge of C#, Java, Python, Swift, and JavaScript
- Basic understanding of threat modeling
- Basic understanding of compliance frameworks (e.g., NIST 800-53) and processes
- Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computing
- Basic technical understanding of authentication and authorization flows in web applications
- Basic understanding of networks and network security (e.g , WAF, Micro-segmentation)
- Basic understanding of cryptography
- Basic understanding of vulnerability management processes and proficiency in providing remediation guidance
Job Posting Expiration: 9/14/2026