East West Bank

Lead Application Security - DevSecOps & AI-Driven Software Assurance

East West Bank$120K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in application security, DevSecOps, or software security analysis.
  • Hands-on expertise in Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools.
  • Proficient with GitHub and the open-source ecosystem.
  • Experience managing GitHub Advanced Security configurations.
  • Familiarity with third-party software risk analysis and reverse engineering techniques.
  • Knowledge of software supply chain security and trust validation frameworks.
  • Strong communication skills with an emphasis on stakeholder engagement.

Responsibilities

  • Embed security controls in CI/CD pipelines using automation tools.
  • Collaborate with development teams on secure coding practices and threat modeling.
  • Manage GitHub Advanced Security features like secret scanning and impact analysis.
  • Conduct SAST and DAST using approved tools to identify vulnerabilities.
  • Perform manual and automated code reviews for vulnerability remediation.
  • Conduct security analysis of third-party software through source code and binary analysis.
  • Establish a software trust and reputation framework for application onboarding.

Benefits

  • Flexible work hours supporting work-life balance.
  • Opportunities for professional development and certifications.
  • Access to advanced security tools and technologies.
  • Collaborative work environment with cross-functional teams.
Full Job Description
Overview

The Senior Cyber Security Engineer will lead and execute security initiatives across the application lifecycle, integrating security into DevOps pipelines, managing vulnerability assessments, and coordinating penetration testing efforts. This role also extends into advanced software assurance, including third-party software analysis, binary-level inspection, and application trust validation, ensuring that both internally developed and externally sourced applications meet the bank’s security standards prior to execution within the enterprise environment. 

Responsibilities

Application Security & DevSecOps Integration 

  • Embed security controls into CI/CD pipelines using GitHub workflows and automation tools. 

  • Collaborate with development teams to implement secure coding practices and threat modeling during design and development phases.  

  • Manage GitHub Advanced Security configurations, including secret scanning, push protection, and impact analysis. 

Security Testing & Vulnerability Management 

  • Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using approved tools (e.g., CodeQL, Dependabot,, OWASP ZAP).  

  • Perform manual and automated code reviews to identify vulnerabilities and ensure remediation through code fixes or configuration changes.  

  • Maintain accurate mapping of applications to GitHub repositories to support vulnerability tracking and reporting.  

Advanced Software Analysis & Trust Establishment  

  • Perform security analysis of third-party software, including both source code review and compiled binary analysis where source is not available. 

  • Conduct binary decomposition and reverse engineering techniques, as appropriate, to evaluate software behavior and identify embedded risks. 

  • Support the establishment and execution of a software trust and reputation framework, enabling secure decision-making for application onboarding and whitelisting within the enterprise environment. 

  • Analyze open-source and GitHub-hosted code, including dependencies and contribution risk. 

  • Partner with AppSec leadership to support application security activities and formalize secure software approval processes. 

API & Web Application Security 

  • Conduct API security assessments and integrate monitoring tools to protect application endpoints.  

  • Support WAF policy management and application-layer threat monitoring. 

  • Threat Intelligence Integration 

  • Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software. 

  • Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications. 

Penetration Testing & Third-Party Risk 

  • Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software.  

  • Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications. 

Qualifications
  • Proven experience in application security, DevSecOps, or software security analysis.  

  • Strong hands-on expertise in: 

    • SAST/DAST tools and secure SDLC practices 

    • GitHub and open-source ecosystems  

    • GitHub Advanced Security   

  • Experience with third-party software risk analysis, software composition analysis (SCA), or reverse engineering / binary analysis 

  • Familiarity with software supply chain security and trust validation frameworks 

  • Experience integrating threat intelligence into security decision-making 

  • Strong understanding of secure SDLC, threat modeling (e.g., STRIDE), and vulnerability management.  

  • Experience coordinating penetration tests and working with third-party vendors.  

  • Strong communication and stakeholder engagement skills. 

 

Applicants must have legal authorization to work in the United States. We do not offer visa sponsorship at this time.  

CompensationThe base pay range for this position is USD $120,000.00/Yr. - USD $180,000.00/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.

About East West Bank

East West Bank is a bank based in California that provides personal and commercial banking services. The bank was founded in 1973 and has grown to become one of the largest banks in the United States. East West Bank has over 120 locations in the United States and China, and offers a range of financial products and services to its customers. The bank is committed to providing excellent customer service and helping its customers achieve their financial goals.
Learn more about East West Bank
Size
3,100 employees
Market Cap
$9 billion
Industry
Net Income
$567.8 million
Founded
1998
5 Year Trend
+7.3%
NASDAQ

Similar Jobs

More Jobs at East West Bank

More Information Technology Jobs

Find similar Lead Application Security - DevSecOps & AI-Driven Software Assurance jobs: