Application Security Engineer
Role details
Job location
Tech stack
Job description
- Implement and manage SAST tools across the organization, ensuring effective integration into development workflows
- Conduct security assessments of applications using SAST tools and support teams in remediation
- Train and guide development teams on SAST usage and secure coding best practices
- Contribute to the development and enforcement of application security policies, standards, and procedures
- Help to define and improve vulnerability management frameworks and working structures
- Research, classify, and analyze security events and vulnerabilities detected by tools and processes
- Act as a point of contact for managing and delivering various vulnerability and remediation reports
- Collaborate closely with IT and project stakeholders to deliver and implement technology solutions that improve productivity, processes, and security
- Work within the BI / reporting framework , following defined processes and ensuring compliant documentation according to SOPs and working instructions
- Present vulnerability management status and updates to risk & information security teams, technology SMEs, and management
Requirements
With a strong emphasis on application security and DevSecOps, candidates should have around 3 years of experience and good communication skills. You'll collaborate with IT teams to enhance productivity and security in development workflows., * Around 3 years of experience in application security.
- Strong background in DevSecOps and application security.
- Hands-on experience implementing and managing SAST tools.
Responsabilidades
-
Implement and manage SAST tools across the organization.
-
Conduct security assessments of applications using SAST tools.
-
Train and guide development teams on SAST usage and secure coding best practices., SAST tools Secure coding practices CI/CD pipelines Kubernetes Python PowerShell Bash Analytical skills Good communication skills Descripción del empleo, * Around 3 years of experience
-
Strong background in DevSecOps and application security
-
Hands-on experience implementing and managing SAST tools (Static Application Security Testing)
-
Solid understanding of secure coding practices and software development lifecycles
-
Experience working with CI/CD pipelines , ideally Jenkins
-
Knowledge of container orchestration platforms such as Kubernetes and/or OpenShift
-
Proficiency in scripting languages such as Python , PowerShell , or Bash
-
Ability to collaborate closely with IT teams , developers, and security stakeholders
-
Strong analytical skills to research, classify, and analyze security events and vulnerabilities
-
Good communication skills to train, guide, and influence development teams and present to management
-
A structured, documentation-oriented mindset, comfortable working with SOPs and defined processes
-
Professional proficiency in English (spoken and written); additional languages are a plus