Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- We administer and enforce security policies governing system and application access.
- We perform application security testing and reviews to ensure secure configurations and compliance with standards.
- We conduct penetration tests and vulnerability assessments across applications, operating systems, and network layers.
- We lead threat modeling and security design reviews for new technologies and system changes.
- We respond to security incidents, isolating threats and removing unauthorized access.
- We research emerging cybersecurity threats and conduct root cause analysis on issues.
- We implement technical controls to reduce cloud-based risks, including drift, private-cloud gaps, and web-facing vulnerabilities.
- We collaborate with Information Security partners to advance roadmaps and shared initiatives.
- We integrate security testing and controls into development lifecycle phases.
- We provide management with insights on business impact related to data compromise or system unavailability.
- We work within an agile framework to deliver iterative improvements toward team and organizational goals.
- We respond to and investigate cybersecurity incidents, which may be off-hours and on a scheduled rotation.
Technologies:
- AWS
- Cloud
- Incident Management
- Marketing
- Network
- Security
- Web
Requirements
- 5-7 years of relevant experience securing cloud environments, primarily AWS, or equivalent expertise.
- Bachelors degree in a related field or equivalent practical experience.
- Strong time management, organizational skills, and attention to detail.
- Solid background in application security engineering and architecture, including MWAF and software development.
- Demonstrated ability to build partnerships and collaborate with cross-functional teams.
- Strong communication skills, with the ability to clearly present security risks to senior leadership.
- Experience managing security vendors and managed service providers.
- Proven background in incident management and response.
- Security certifications such as CISSP, GIAC, or CISA are a plus.
About the company
We are The Pokémon Company International, managing the Pokémon property outside of Asia across brand management, licensing and marketing, the Pokémon Trading Card Game, the animated TV series, home entertainment, and the official Pokémon website. Pokémon launched in Japan in 1996 and has become one of the worlds most popular childrens entertainment properties. This role is hybrid and offers an innovative, impact-driven culture, company events, competitive cash-based compensation, 100% employer-paid healthcare premiums for you, generous paid family leave, employer-paid life insurance, employer-paid long and short-term income protection insurance, 401(k) employer matching for US employees, pension employer contributions for UK/IRE/MX employees, fitness reimbursement, commuter benefit, LinkedIn Learning, and a comprehensive relocation package for certain roles.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
The 12 Best Jobs for Software Engineers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?