We're seeking a highly skilled and experienced Senior Application Security Engineer to lead and enhance our secure software development lifecycle (SSDLC) and drive security best practices across our cloud and DevOps environments. This is a 100% remote role, offering flexibility and autonomy while working with cross-functional teams across the organization.
Requirements
- Lead secure code reviews, threat modeling, and vulnerability assessments across web, mobile, and API-based applications.
- Collaborate with development teams to integrate security into CI/CD pipelines and DevSecOps workflows.
- Develop and maintain security tooling (e.g., SAST, DAST, IAST, SCA) and ensure effective coverage and tuning.
- Provide guidance on secure coding practices and conduct security training for engineering teams.
- Partner with product and engineering teams during design and architecture phases to ensure security is built-in.
- Define and implement security controls for cloud-native applications and infrastructure (AWS, Azure, GCP).
- Work closely with DevOps teams to secure containerized environments (Docker, Kubernetes) and infrastructure-as-code (Terraform, CloudFormation).
- Monitor and respond to cloud security events and misconfigurations using CSPM and SIEM tools.
- Drive automation of security processes and compliance checks within CI/CD pipelines.
- Evaluate and implement cloud security tools and services to enhance visibility and protection.
- Contribute to security policies, standards, and procedures related to application and cloud security.
- Support internal and external audits, ensuring compliance with frameworks such as SOC 2, ISO 27001, and NIST.
Benefits
- Health & life insurance
- Referral rewards
- Generous leave policies
