Senior Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
Experteer Overview In this role you will lead application security testing and governance to strengthen software security across web, API, and cloud apps. You will drive vulnerability management, collaborate with development teams to embed secure practices in the SDLC, and contribute to risk-based security reporting. You will work within a security-focused function that partners with cross-functional teams to scale secure development and compliance. This is a chance to shape security maturity in a global consulting environment. Compensation / Benefits * Perform SAST, DAST, SCA, penetration testing, API security testing and manual security reviews across web, API, cloud and enterprise apps * Validate findings, analyze false positives, and retest to verify remediation effectiveness * Lead vulnerability management activities including prioritization, remediation tracking, and reporting * Advise development teams on secure coding, remediation strategies, and secure SDLC integration in CI/CD/DevSecOps * Support security governance, risk assessments, threat modeling, secure design reviews, and compliance activities * Create security dashboards and metrics (vulnerability trends, SLAs, MTTR, testing coverage) and communicate risks to stakeholders Tasks * 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related disciplines * Strong hands-on with SAST, DAST, SCA, penetration testing, API security testing, and manual assessments * Extensive experience with Burp Suite; familiarity with HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools) * Deep understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, and risk-based prioritization * Experience collaborating with development teams to drive remediation and security maturity * Strong written and verbal communication with stakeholders * Preferred: Azure Cloud & Azure DevOps, ServiceNow, Power BI, and governance frameworks (NIST, MITRE ATT&CK, CIS) * Certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP/OSWE, Security+, AZ-500 are a plus Key requirements *
Requirements
effectiveness * Support security governance, risk assessments, threat modeling, secure design reviews, and compliance activities * Create security dashboards and metrics (vulnerability trends, SLAs, MTTR, testing coverage) and communicate risks to stakeholders Tasks * 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related disciplines * Strong hands-on with SAST, DAST, SCA, penetration testing, API security testing, and manual assessments * Extensive experience with Burp Suite; familiarity with HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck (or similar SCA tools) * Deep understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, and risk-based prioritization * Experience collaborating with development teams to drive remediation and security maturity * Strong written and verbal communication with stakeholders * Preferred: Azure Cloud & Azure DevOps, ServiceNow, Power BI, and governance frameworks (NIST, MITRE ATT&CK, CIS) * Certifications such as CISSP, CSSLP, GWAPT, GWEB, OSCP/OSWE, Security+, AZ-500 are a plus Key requirements *
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The 8 Best Code Testing Tools
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Why Upskilling And Reskilling is Important For Developers
9 Ways to Make Money Hacking