Senior Application Security Engineer

Automatic Data Processing, Inc.
Roseland, NJ, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Cloud Computing Security Cyber Security DevOps Python (Programming Language) Node.Js Open Source Technology Open Web Application Security Systems Development Life Cycle Prometheus Standard Sql
+11 more
SQL Databases Software Vulnerability Management Sonatype Software Security Sonatype Nexus Kubernetes Information Technology Tenable Nessus Free and Open-Source Software Npm(Software) Artifactory

Job description

We are seeking a Senior Application Security Engineer to secure our software supply chain by assessing, governing, and mitigating risks associated with open-source software. This role partners closely with engineering, DevOps, and security teams to drive secure OSS adoption at scale.

What You’ll Do

  • Generate and analyze SBOMs and conduct OSS security assessments using tools like Snyk and Syft.
  • Evaluate and onboard security tools through POCs.
  • Build and operate cloud-based data pipelines to identify vulnerabilities, license risks, and supply chain threats.
  • Develop dashboards and reports to communicate security risk to engineering teams and leadership.
  • Design and integrate OSS security tooling, including JFrog Artifactory/Xray or Sonatype Nexus/Lifecycle.
  • Partner with engineering teams to guide secure open-source usage and remediation.
  • Support incident response efforts, including zero-day vulnerability management.
  • Create OSS security standards, documentation, and training materials.

Requirements

  • 7+ years of experience in cybersecurity, application security, or software supply chain security.
  • Hands-on experience with SBOMs, OSS scanning tools, and vulnerability management.
  • Experience with JFrog or Sonatype artifact repository platforms.
  • Strong background in cloud-native security and automation.
  • Primary qualification: Python, AWS + Kubernetes + SQL + Security certifications (CISSP, CSSLP, etc.) are a plus

TO SUCCEED IN THIS ROLE:

  • You’ll have a bachelor’s degree in computer science, Information Security, or related field (or equivalent experience).

Skills & Technologies

  • Programming: Python; npm / Node.js ecosystems
  • Cloud & Platforms: AWS, Kubernetes, SQL
  • OSS & Supply Chain: JFrog Artifactory/Xray, Sonatype Nexus/Lifecycle
  • Reporting & Monitoring: Amazon QuickSight, Prometheus, * Knowledge of OWASP, NIST, and secure SDLC practices.
  • Strong communication and cross-functional collaboration skills.
  • Security certifications (CISSP, CSSLP, etc.) are a plus., * Have courageous team collaboration. Courage comes from how associates are willing to have difficult conversations, speak up, be an owner, and challenge one another’s ideas to net out the best solution.

Benefits & conditions

  • Deliver at epic scale. We deliver real user outcomes using strong judgment and good instincts. We’re obsessed with the art of achieving simplicity with a focus on client happiness and productivity.
  • Be surrounded by curious learners. We align ourselves with other smart people in an environment where we grow and elevate one another to the next level. We encourage our associates to listen, stay agile, and learn from mistakes.
  • Act like an owner & doer. Mission-driven and committed to leading change, you will be encouraged to take on any challenge and solve complex problems. No tasks are beneath or too great for us. We are hands-on and willing to master our craft.
  • Give back to others. Always do the right thing for our clients and our community and humbly give back to the community where we live and work. Support our associates in times of need through ADP’s Philanthropic Foundation.
  • Join a company committed to equality and equity. Our goal is to impact lasting change through our actions.

What are you waiting for? Apply today!

Find out why people come to ADP and why they stay: https://youtu.be/ODb8lxBrxrY

(ADA version: https://youtu.be/IQjUCA8SOoA )

LI-SD4

LI-Hybrid

Base salary offers for this position may vary based on factors such as location, skills, and relevant experience. Some positions may include additional compensation in the form of bonus, equity or commissions. We offer the following benefits: Medical, Dental, Vision, Life Insurance, Matched Retirement Savings, Wellness Program, Short-and Long-Term Disability, Charitable Contribution Match, Holidays, Personal Days & Vacation, Paid Volunteer Time Off, and more. The compensation for this role is $0.00 - $0.00 / Year*

*Actual compensation will not be less than the applicable minimum wage or minimum exempt salary requirement under federal, state and local laws.

About the company

A little about ADP: We are a comprehensive global provider of cloud-based human capital management (HCM) solutions that unite HR, payroll, talent, time, tax and benefits administration and a leader in business outsourcing services, analytics, and compliance expertise. We believe our people make all the difference in cultivating a down-to-earth culture that embraces our core values, welcomes ideas, encourages innovation, and values belonging. We’ve received recognition for our work by many esteemed organizations, learn more at ADP Awards and Recognition (https://www.adp.com/about-adp/awards-and-recognition.aspx) ., Ethics at ADP: ADP has a long, proud history of conducting business with the highest ethical standards and full compliance with all applicable laws. We also expect our people to uphold our values with the highest level of integrity and behave in a manner that fosters an honest and respectful workplace. Click https://jobs.adp.com/life-at-adp/ to learn more about ADP’s culture and our full set of values.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

4:37 min

Executing verified publishing workflows on Sonatype Maven Central

Johan Hutting Johan Hutting · WWC 2024

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · WWC 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

3:44 min

Integrating static security scanning in the build phase

Milecia Mcgregor · LIVE

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · WWC 2023

Videos

See all

Related articles

See all