Application Security Engineer

Actus Consulting Group, Inc.
Plano, TX, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

C (Programming Language) Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Android Software Development Apple IOS Software System Penetration Testing User Authentication Authentication Protocols Automation of Tests Microsoft Azure C++ (Programming Language)
+43 more
Cloud Computing Cloud Computing Security Cyber Security Computer Engineering Linux Identity and Access Management Systems Analysis Internet Security Mobile Application Software Information Systems Security Architecture Professional Python (Programming Language) Key Management Network Security Wireless Security Network Segmentation OAuth Open Web Application Security X.509 Software Tools Cloud Services Requirements Management Reverse Engineering Security Assertion Markup Language (SAML) Software Engineering SSL Certificate Management Data Logging Scripting Transport Layer Security Cloud Platform System Software Security Test Scripts Swift (Programming Language) Kotlin Kubernetes Information Technology Wireless Technologies Data Management Api Gateway Serverless Computing Docker Vulnerability Analysis Programming Languages Microservices

Job description

This role is responsible for performing advanced product security testing to strengthen the cybersecurity posture across next-generation vehicle and connected services platforms. As part of the Product Security Testing Team (PSTT) within the Product Cybersecurity Group (PCG), the position conducts hands-on security assessments, penetration testing, and vulnerability research across APIs, mobile applications (iOS and Android), cloud-hosted services, Linux systems, and wireless technologies. Responsibilities include validating security requirements against implementation, developing proof-of-concept exploits, reverse engineering software components, and clearly communicating security risks and remediation guidance to engineering teams. This role requires strong technical depth, an offensive security mindset, and close collaboration with cross-functional stakeholders., Conduct analysis of security requirements specifications against implementation Perform security assessments and penetration testing including but not limited to mobile applications (iOS and Android), wireless security, APIs, cloud environments, and Linux OS Evaluate cloud infrastructure security across AWS, Azure, or GCP environments, including IAM policies, network segmentation, storage configurations, and serverless architectures Assess container and orchestration security (Docker, Kubernetes) for vehicle-connected cloud services and microservices deployments Review cloud-native application security controls such as API gateways, service meshes, secrets management, and logging/monitoring configurations Communicate complex technical findings and recommend the appropriate course of action, supporting the mitigation and re-validation efforts Support testing Connected Services ecosystems to identify and report security vulnerabilities and ensure compliance with security standards Develop and maintain security testing tools to support penetration testing and security verification activities, ensuring thorough identification of vulnerabilities Develop skills through continuous learning and apply what you have learned relevant to emerging attack vectors, vulnerabilities, and exploits across application and cloud domains Travel to clients or partners sites as needed to provide on-site support for security testing and verification activities

Requirements

Bachelor’s degree (or higher) in Computer Engineering, Computer Science, Cybersecurity or related is strongly desired Strong understanding of OWASP Top 10, SANS Top 25, and common cloud & mobile application vulnerabilities Hands-on experience securing cloud environments (AWS, Azure, or GCP), including identity and access management, network security groups, and cloud-native security tooling Foundational knowledge in security assessment on OS or application-level of iOS/Android applications Demonstrated ability to perform penetration testing against APIs, mobile applications (Android and iOS), and cloud infrastructure Familiarity with programming languages such as C/C++, Java, Swift, Kotlin, and Python through practical experience Familiarities with network security principles and various wireless security protocols Knowledge of APIs security, application security, and authentication protocols such as OAuth, SAML, etc. Basic knowledge and understanding of X.509, SSL/TLS certificate, and general certificate management process Basic understanding of API security best practices Willingness to learn developing security tools and automation scripts to support vulnerability assessment and penetration testing Strong interest to acquire and develop additional skills such as Embedded systems security fundamentals, Demonstrates strong capability in conducting penetration testing and security assessments across applications, APIs, cloud environments, operating systems, and wireless technologies to identify, validate, and prioritize security risks Applies deep knowledge of application, API, and cloud security principles-including authentication, authorization, and secure architectures, to assess real-world risk and recommend effective mitigations Analyzes complex systems, reverse engineers software components, and develops proof-of-concept exploits to understand root causes, attack paths, and potential impact Collaborates effectively with engineering and product teams to communicate findings, influence secure design decisions, and support remediation and re-validation efforts Develops or enhances security testing tools, scripts, and automation to improve testing efficiency, consistency, and coverage Continuously builds knowledge of emerging attack techniques, vulnerabilities, and security trends and applies learnings to improve security testing effectiveness

Skills: Amazon Web Services (AWS), Android, Application Programming Interface (API), Applications Security, Architectural Analysis, Authentication, Best Practices, C Programming Language, C++ Programming Language, Cloud Applications, Cloud Computing, Communication Skills, Computer Engineering, Computer Science, Computer Security, Digital Certificates, Docker, Ecosystems, Embedded Systems, Engineering Software, Establish Priorities, GCP (Good Clinical Practices), Identity Data Management, Internet Security, Java, Kotlin, Linux Operating System, Machine Tool, Maintain Compliance, Microservices, Microsoft Windows Azure, Mobile Applications, Network Security, On Site Support, Operating Systems, Penetration Testing, Product Testing, Programming Languages, Python Programming/Scripting Language, Regulatory Compliance, Requirements Management, Requirements Validation/Verification, Reverse Engineering, Risk, SSL-TLS (Secure Socket Layer - Transport Layer Security), Scripting (Scripting Languages), Security Analysis, Security Compliance, Security Protocols, Software Engineering, Systems Analysis, Test Automation, Test Scripts, Test Tools, Testing, Willing to Travel, Wireless Communications, Wireless Protocols/Standards, Wireless Security, X.509 Digital Certificate, iOS

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:15 min

Scaling DevSecOps and researching mobile application security standards

Moataz Nabil Moataz Nabil · LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all