Application Security Engineer

Environmental Systems Research Institute, Inc.
Redlands, CA, United States
1 day ago
Apply on www.esri.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$93,600.0 - $157,560.0
Working hours
Regular working hours
Job source

Tech stack

Clean Code Principles Java (Programming Language) JavaScript (Programming Language) Artificial Intelligence Amazon Web Services Application Layers Software System Penetration Testing Microsoft Azure Bash Shell C Sharp (Programming Language) Code Review Encodings
+22 more
Communications Protocols Cyber Security Github Hypertext Transfer Protocols (HTTP) Python (Programming Language) OAuth Open Source Technology OpenID Windows PowerShell Web Application Security Software Engineering SQL Databases TypeScript Software Vulnerability Management Esri GIS (Software) GitHub Copilot Software Security Kubernetes Information Technology Restful APIs Devsecops Dynamic Application Security Testing

Job description

As someone experienced with securing a wide variety of applications, you are looking for an opportunity to use your skills in an innovative and technology-oriented environment. As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri’s intellectual property and sensitive data against a variety of complex threats with support from all levels of leadership. Our Application Security team collaborates closely with the application development, DevSecOps, and information security departments to design security into our applications up front, perform application layer security testing, and assist developers with vulnerability remediation. We value collaboration, pragmatic security, and continuous improvement. We welcome you to join Esri, where you can make a real difference every day!, * Design, operate, and continuously improve application security testing capabilities and pipelines

  • Assess application risks and recommend mitigations
  • Perform application layer security reviews of the code developed by our application teams, across multiple languages and frameworks used internally
  • Assist with application layer penetration testing to identify potential issues
  • Provide application security guidance and mentorship to development teams as needed

Requirements

  • 5+ years of experience in application security, including manual and automated code reviews, manual penetration testing, dynamic application security testing, and false positive analysis of code, pen test, and open-source security findings
  • Demonstrated experience determining risk based on analysis/findings using a consistent risk management framework
  • Proven ability to develop automations/applications using Python, Typescript, Java, or PowerShell
  • Experience creating and maintaining reusable GitHub Actions workflows, with expertise in all aspects of GitHub workflow management
  • Hands-on experience working in a DevSecOps environment built on Kubernetes with a strong knowledge of Kubernetes security best practices
  • Ability to read and analyze code for security and design vulnerabilities
  • Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more)
  • Experience working with cloud platforms, specifically AWS and Azure
  • Willingness to learn new skills and enhance workflows using various AI tools
  • US citizenship and willingness and ability to maintain a US Security Clearance
  • Bachelor’s degree in computer science or related field, * Proficiency in any of the following languages: C#, Python, Bash/Shell, PowerShell, JavaScript, SQL, Java
  • Familiarity with AI-assisted coding practices, including tools such as GitHub Copilot, and an understanding of the security implications and risks introduced by AI-generated code
  • Practical experience interpreting findings from application pen testing, code scanning and open-source scanners to determine the risk and collaborate with developers to resolve them
  • Understanding of layer 2-7 communication protocols, common encoding and encryption schemes, and algorithms

LI-TM1

Benefits & conditions

Esri’s competitive total rewards strategy includes industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth. Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. A reasonable estimate of the base salary range is $93,600-$157,560 USD

About the company

At Esri, diversity is more than just a word on a map. When employees of different experiences, perspectives, backgrounds, and cultures come together, we are more innovative and ultimately a better place to work. We believe in having a diverse workforce that is unified under our mission of creating positive global change. We understand that diversity, equity, and inclusion is not a destination but an ongoing process. We are committed to the continuation of learning, growing, and changing our workplace so every employee can contribute to their life’s best work. Our commitment to these principles extends to the global communities we serve by creating positive change with GIS technology. For more information on Esri’s Racial Equity and Social Justice initiatives, please visit our website here.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.esri.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all