Senior Application Security Engineer

TekStream Solutions

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in application security or related field.
  • Proficient in Microsoft .NET/C# development.
  • Solid understanding of cybersecurity principles and common vulnerabilities.
  • Familiarity with SAST and DAST tools, including GitGuardian, Veracode, and SonarQube.
  • Strong analytical and problem-solving skills.
  • Excellent oral and written communication abilities for diverse audiences.
  • Ability to collaborate across teams and with external stakeholders.

Responsibilities

  • Guide developers in understanding and addressing security vulnerabilities.
  • Collaborate with teams to ensure security best practices in development.
  • Utilize SAST and DAST tools for testing and validation.
  • Recommend efficient remediation solutions to streamline processes.
  • Build and enhance DevSecOps capabilities within CI/CD pipelines.
  • Automate manual security processes to improve workflow efficiency.
  • Analyze penetration test findings and propose actionable remediation tasks.

Benefits

  • Remote work option with a flexible schedule accommodating Pacific time zone hours.
  • Opportunity to work on a variety of projects in a consulting environment.
  • Engagement in continuous learning and professional growth in cybersecurity.
  • Collaboration with a skilled, cross-functional team focused on digital resilience.
Full Job Description
Location: US-based, remote. Must accomodate Pacific time zone work hours.

TekStream, a Digital Resilience Consulting company, is seeking a skilled and collaborative Application Security Engineer to bridge the gap between our Information Security (InfoSec) team and development personnel. In this role, you will act as a security ambassador, helping developers understand vulnerabilities, automating security into our CI/CD pipelines, and driving remediation efforts to ensure our software is secure by design. The ideal candidate has consulting experience and is open to working west coast hours for our client.

Key Responsibilities
Technical Liaison & Developer Support
  • Guide and assist development personnel in understanding security vulnerabilities and implementing remediation options.
  • Collaborate with developers to ensure adherence to security best practices during development cycles.
  • Utilize SAST and DAST tools for thorough security testing and validation of remediation efforts.
  • Recommend efficient solutions for fixes to streamline the overall remediation process.
DevSecOps Integration
  • Build out capabilities of the DevSecOps Team, actively contributing to integrating security practices into CI/CD pipelines.
  • Automate manual processes to improve the efficiency and speed of development workflows.
Vulnerability & Penetration Test Remediation
  • Analyze findings from penetration tests and propose concrete remediation tasks.
  • Support assigned teams with the technical aspects of the remediation process.
  • Monitor and track progress on remediation tasks to ensure timely completion.
Security Reviews & Assessments
  • Review False Positive (FP) submissions, providing clear guidance on resolution and ensuring proper justification and documentation.
  • Evaluate Risk Acceptance Requests (RARs), providing mitigation recommendations and identifying cases requiring further review.
  • Participate in architecture reviews of security products and architectures to identify potential improvements.
  • Support security assessments, including scoping, report reviews, and remediation planning.
Process Improvement
  • Research and recommend optimization opportunities related to the team's organization, processes, procedures, and tools to improve efficiency and maturity.


Role Requirements & Qualifications
Technical & Development Experience
  • Cybersecurity Knowledge: Solid understanding of cybersecurity principles, including common threats and vulnerabilities.
  • Development Experience: Proficiency in software development, preferably within a Microsoft .NET/C# code base.
  • Cloud & On-Premises Familiarity: Familiarity with testing tools and techniques for both on-premises and cloud environments is highly valued.
  • Tooling Proficiency: Experience with or knowledge of the following tools:
    • SAST/DAST/Secrets: GitGuardian, Veracode, SonarQube, Qualys DAST, Wiz
    • Languages: .NET, C#
Core Competencies
  • Analytical Skills: Ability to analyze risks associated with vulnerabilities and recommend appropriate resolutions or risk reduction strategies.
  • Communication Skills: Excellent oral and written communication skills, with the ability to effectively translate technical details to both technical and non-technical stakeholders in a consulting capacity.
  • Coordination & Collaboration: Proven ability to collaborate with various resources across IT and vendor populations to achieve security objectives while acting as a supportive team member.
  • Documentation & Compliance: Proficient in collecting and synthesizing information into an accurate format suitable for audits. High attention to detail is essential.

Similar Jobs

More Information Technology Jobs

Find similar Senior Application Security Engineer jobs: