Senior Application Security Engineer / Architect

Compsciprep LLC
United States
10 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Software System Penetration Testing Microsoft Azure Cloud Computing Security Digital Forensics Open Web Application Security Systems Development Life Cycle Secure Coding Software Engineering Software Vulnerability Management Software Security Devsecops
+3 more
Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking a Senior Application Security Engineer / Architect with expertise in Application Security, Secure SDLC, Cloud Security, and DevSecOps. In this role, you will collaborate closely with engineering, product, platform, and architecture teams to enhance secure development practices, offer actionable vulnerability remediation guidance, and promote security awareness within development teams., * Work with cross-functional teams to integrate security best practices into the software development lifecycle.

  • Provide expertise in Application Security, including Wiz/CNAPP, Azure Security, SAST/DAST/SCA, OWASP, NIST, and Threat Modeling.
  • Translate security findings into clear and actionable remediation guidance for developers.
  • Conduct security assessments and penetration testing on applications to identify vulnerabilities.
  • Collaborate with stakeholders to design and implement secure architecture solutions.
  • Develop and implement security policies, standards, and procedures.
  • Stay up-to-date on emerging threats and security technologies to advise on best practices.
  • Participate in incident response and security incident investigations.
  • Conduct security training and awareness programs for development teams.

Requirements

  • Proven experience in Application Security.
  • Familiarity with Secure SDLC, Cloud Security, and DevSecOps.
  • Hands-on experience with Wiz/CNAPP, Azure Security, SAST/DAST/SCA, OWASP, NIST, and Threat Modeling.
  • Ability to communicate security concepts effectively to technical and non-technical stakeholders.
  • Strong problem-solving and analytical skills.
  • Experience in conducting security assessments and penetration testing.
  • Knowledge of security standards and frameworks.
  • Ability to work independently and as part of a team.
  • Excellent written and verbal communication skills.

Preferred Skills:

  • Certifications such as CISSP, CISM, or CEH.
  • Experience with container security and microservices architecture.
  • Knowledge of regulatory compliance requirements (e.g., GDPR, HIPAA).
  • Experience in security incident response and digital forensics.
  • Previous experience in a leadership or mentoring role.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · World Congress 2022

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all