Verified today
Application Security Specialist Engineer
About the role
Application Security Engineer responsible for vulnerability operations, tooling ownership, and automation across global portfolio. Leads triage, remediation, inventory, metrics, and dashboards. Drives security maturity with CI/CD integration and cloud platforms.
What you’ll do
- Triage, validate, prioritize vulnerabilities SAST, SCA, DAST, IaC, secrets, container.
- Administer, tune, maintain security tooling ecosystems, ensuring CI/CD integration.
- Create, track, manage remediation tickets with engineering teams, enforcing SLAs.
- Maintain inventories, classify by criticality, exposure, sensitivity.
- Contextualize vulnerabilities with impact, exploitability, controls, asset risk.
- Develop dashboards for vulnerability posture, aging, SLA compliance, reporting.
- Conduct trend analysis to identify recurring vulnerabilities, improvements.
- Build automation scripts to streamline triage, ticketing, enrichment, reporting.
What you’ll bring
- Bachelor's in CS, Cybersecurity, or equivalent.
- 3–5+ years in Application, Product, or Vulnerability Security.
- Hands‑on SAST, SCA, DAST, IaC, container, or secrets scanning.
- Strong CVSS, exploitability, and vulnerability class knowledge.
- Python scripting (Go/JS acceptable) and CI/CD integration.
- Cloud platforms (AWS, Azure, GCP) and modern app architecture.
- Analytical, investigative, problem‑solving, high attention to detail.
- Collaborative in fast‑paced global engineering environment.
Nice to have
- Large‑scale, multi‑business‑unit vulnerability program experience.
- Kubernetes, container security, cloud‑native scanning expertise.
- Dashboard building with PowerBI, Tableau, Grafana, or Looker.
- Knowledge of NIST CSF, ISO 27001, SOC 2, EO 14028.
- Software composition analysis, supply chain security, SBOM familiarity.
- Security automation via APIs, webhooks, serverless, workflow engines.
- Security certifications: GWAPT, GXPN, GCSA, CSSLP, OSCP, or equivalent.
Skills
Education
Bachelor's