Network Temps Inc Logo

Network Temps Inc

Senior Application Security Engineer

Posted 2 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
Senior level
In-Office
New York, NY, USA
Senior level
Lead application security by performing risk analyses, vulnerability assessments, SAST/DAST and SCA testing, secure design and code review, threat simulations, cloud and WAF hardening, CI/CD security integration, and reporting to senior management while coordinating remediation with development and IT teams.
The summary above was generated by AI

Description


TASKS:

? Perform comprehensive cybersecurity risk analysis, identifying and prioritizing risks specifically 

related to application security.

? Develop, socialize, and implement security strategies to address vulnerabilities in web 

applications, microservices, APIs, and mobile applications.

? Track and manage progress against security plans, ensuring timely remediation of identified 

vulnerabilities.

? Lead the security implementation in application development projects, ensuring "secure by 

design" practices.

? Create and maintain architecture diagrams, outlining secure communication flows, and 

develop both high-level and low-level security design documents.

? Troubleshoot and resolve application security issues in collaboration with internal teams and 

external vendors.

? Translate application compliance requirements into specific security controls, recommending 

compensating measures where appropriate.

? Regularly report on the organization’s security posture, with a focus on application 

vulnerabilities, to senior management.

? Perform/coordinate application vulnerability assessments and ensure timely remediation in 

collaboration with the Development, IT, and Systems teams.

? Implement secure coding practices, perform static and dynamic application security testing 

(SAST/DAST), and support developers with secure code reviews.

? Monitor security incidents and respond to application-level threats, ensuring quick resolution 

of potential vulnerabilities.

? Establish and enforce secure configurations for applications and their underlying 

infrastructure, such as databases and APIs.

? Perform threat simulations to detect risks and recommend improvements for securing 

application designs, API security, identity management, and access control measures.

? Collaborate with teams to ensure continuous integration and continuous deployment (CI/CD) 

pipelines incorporate security control

Requirements


Senior Application Security Engineer 

Mandatory Skills/Experience 

• 12 years of experience in application security, with a proven track record of conducting vulnerability assessments, penetration testing, and secure code reviews. • Extensive experience in secure application development, including knowledge of security frameworks like OWASP Top 10, and the ability to guide development teams in implementing secure coding practices. • Proficiency in Software Composition Analysis (SCA) tools (e.g., Veracode, AppSec) for identifying and managing vulnerabilities in open-source libraries and third-party components. • Advanced knowledge of static and dynamic application security testing (SAST/DAST) tools (e.g., Veracode, AppSec, Burp Suite) and integrating these tools into CI/CD pipelines for automated security checks. • Strong cloud security expertise, including securing applications and workloads on AWS, Azure, or GCP, and experience with Web Application Firewalls (WAF) and cloud-native security services. Desirable Skills/Experience • Advanced cloud security experience: Experience securing cloud environments (AWS, Azure, GCP) with tools like Web Application Firewalls (WAF), and implementing IAM, encryption, and monitoring tools. • Experience with scripting and automation, using Python, Bash, or PowerShell, to automate security tasks, integrate security testing tools, and improve the efficiency of security operations. • Strong communication skills: Ability to effectively explain complex security concepts and risks to both technical teams and non-technical stakeholders, ensuring alignment on security measures. • Leadership and mentoring skills: Experience leading security teams or initiatives, mentoring junior engineers, and fostering a culture of security awareness within the organization. • Collaboration and cross-functional teamwork: Proven ability to work effectively with development, DevOps, and IT teams to integrate security into all aspects of the business, ensuring security goals align with business objectives. • Highly flexible/willing to learn new technologies. • Highly organized with excellent analytical, problem solving and decision-making skills.

Additional Qualifications:

• Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Cloud Security Professional (CCSP), or GIAC Web Application Penetration Tester (GWAPT) are highly preferred.

• Knowledge of compliance standards like NIST, PCI-DSS, and GDPR and how they apply to application security.

Similar Jobs

12 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-165K Annually
Senior level
140K-165K Annually
Senior level
Fintech • Financial Services
Own and evolve the application security program: embed secure SDLC practices, partner with engineering on design and code reviews, manage AppSec tooling (SAST/DAST/ASM/WAF/mobile), harden AWS deployments, integrate security into CI/CD, and lead vulnerability investigation and remediation efforts.
Top Skills: AppdomeAsmAWSCi/Cd PipelinesCloudflare WafCryptographic Key ManagementDastEcsGithub Advanced SecurityGoHadrianIamInvictiMobile Application Security ToolsPythonReact NativeRuby On RailsSastScaSecret ScanningSsl Certificates
5 Days Ago
Remote or Hybrid
USA
160K-250K Annually
Senior level
160K-250K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead application security for products by performing threat modeling, manual secure code reviews, and penetration testing. Collaborate with engineers to remediate defects, build AppSec automation and tooling, secure cloud/containerized applications, and drive bug-bounty responses to harden platform security.
Top Skills: Ai TechnologiesApi SecurityAppsec ToolsAspmAWSAzureBug BountyChromeCspmDastDockerDspmElectronFirefoxGCPGo (Golang)JavaScriptKotlinKubernetesNode.jsPythonReactSastScalaStrideTypescriptWebassembly (Wasm)
2 Days Ago
In-Office
New York, NY, USA
150K-200K Annually
Senior level
150K-200K Annually
Senior level
Healthtech
Lead AppSec across the SDLC: design and implement application security controls, perform hands-on testing of web apps/APIs/cloud services, integrate automated security tooling into CI/CD, reduce developer friction, review architecture and code, support vulnerability management and incident response, evaluate third-party risks, and ensure healthcare regulatory compliance (e.g., HIPAA, GDPR).
Top Skills: APIsAWSAzureCi/CdContainer ScanningDastDatadogEntitleFlare.IoGCPGitlabIac ScanningOktaOrcaOwasp Top 10PrismaSastSecrets DetectionSumologicTorq

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account