Application Security Engineer

Details of the offer

As an Application Security Engineer, you will primarily focus on offensive security and closely work with architects and engineering teams to guide the implementation of secure practices across different areas like cloud, API, applications and mobile devices. You will identify trends and risks across multiple platforms, and engage with senior leadership to provide action plans and strategy.
What You'll Do:
Provide securityexpertisefor cloud, web and mobile projects, helping teams meet the enterprise and IT security policies, industry regulations, and best practices.
Participate in developing runtime analysis capabilities to identify security vulnerabilities with high confidence.
Ensure the quality of our applications and products by guiding them through theSecure Development Lifecycle (SDL)process.
Advocate, research, develop new tools to support our security patterns and standards.
Monitor our exposure to, and assess the impact of, newsecurity threats, vulnerabilities and risks.
Work with security and engineering teams to maintain a securityarchitecturethat provides security controls throughout all platforms to mitigate risk, and to meet goals and regulatory requirements.
Report to the Director of Application Security

What we are looking for:
3+ years' experience in the application security industry, solving security problems in large-scale systems.
Experience with integrating security scanning tools with CI/CD, Web Application pentesting, fuzzing and DAST.
Expertise in verifying and measuring common security vulnerabilities, and demonstrated ability in communicating these concepts to your partners in engineering. From the OWASP Top Ten to more advanced concepts, you've seen it before, and can describe it with ease.
Familiarity with the responsibilities and workflow of software developers. The Application Security team works with engineering to meet both business needs and security requirements. You can speak their language, and sympathize with their challenges.

What we would like to see:
Exposure to most of the following technologies: Google Cloud, iOS, IAM, Snyk, Android, CircleCI, Consul, Kubernetes, PKI, React, GraphQL, Splunk, and InfluxDB.
Experience defining security architecture patterns and standards in a large enterprise organization.
Knowledge of cryptography including algorithms, standards, and their practical applications such as x.509 certificates.

Benefits at Credit Karma includes:

Medical and Dental Coverage
Retirement Plan
Commuter Benefits
Wellness perks
Paid Time Off (Vacation, Sick, Baby Bonding, Cultural Observance, & More)
Education Perks
Paid Gift Week in December


Nominal Salary: To be agreed

Source: Greenhouse

Requirements

Cloud Software Engineer

Job Summary NetApp is uniquely placed in the industry and in an enviable position partnering with major hyper scalers (AWS, GCP and Azure) which adds a new c...


Netapp - Karnataka

Published a month ago

Manager Cloud Operations

Remote Work: Hybrid Overview: At Zebra, we are a community of innovators who come together to create new ways of working to make everyday life better. United...


Zebra - Karnataka

Published a month ago

Senior Software Engineer

The Company PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and s...


Paypal - Karnataka

Published a month ago

Aris Bpm

Req ID:302035 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, a...


Nttdata - Karnataka

Published a month ago

Built at: 2024-12-12T15:47:27.940Z