Senior Application Security Engineer

Eli Lilly and Company

Cork

Hybrid

EUR 90,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Premium workspace
Hybrid working
Healthcare
Pension
Life assurance
Canteen
Onsite gym
Travel subsidies
On-site parking
Educational assistance
Wellbeing initiatives

Job summary

Eli Lilly Cork is seeking an Application Security Engineer to join the Security Architecture and Engineering team. You will integrate application security testing tools into the SDLC and work with engineering teams to enable secure coding practices and coordinated remediation.

This role requires deep knowledge of SAST, DAST, SCA, and secrets management; you’ll secure containers, collaborate with DevOps, and develop security guidance and threat models.

Qualifications

  • Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or related field.

Responsibilities

  • Integrate SAST, SCA, Secrets scanning, and DAST into the Software Development Lifecycle (SDLC).
  • Lead secure coding practices and coordinate remediation.
  • Collaborate with DevOps to embed security checks into development and deployment processes.
  • Secure containers in on-prem and cloud environments.
  • Develop and maintain technical security guidance and threat modeling.
  • Coordinate vulnerability remediation with SecOps and stakeholders.
  • Triage critical and zero-day vulnerabilities and escalate as needed.
  • Improve security processes and metrics for application security.
  • Engage with stakeholders to refine how security metrics are calculated and communicated.

Skills

DevSecOps practices
End-to-end security testing
SDLC security integration

Education

Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or related field

Tools

Checkmarx
Github

Job description

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world.

Eli Lilly Cork is made up of a talented diverse team of over 2000 employees across 60 nationalities who deliver innovative solutions that add value across a variety of Business Service functions including Finance, Information Technology, Medical, Clinical Trials and more. Eli Lilly Cork offers a premium workspace across our campus in Little Island, complete with flexible hybrid working options, healthcare, pension and life assurance benefits, subsidised canteen, onsite gym, travel subsidies and on-site parking. Inhouse People Development services, Educational Assistance, and our 'Live Your BEST Life' wellbeing initiatives are just some of the holistic benefits that enhance the career experience for our colleagues.

Eli Lilly Cork is committed to diversity, equity and inclusion (DEI). We cater for all dimensions ensuring inclusion of all ethnicities, nationalities, cultural backgrounds, generations, sexuality, visible and invisible disabilities and gender, with four pillars: EnAble, Age & Culture, LGBTQ+ and GIN-Gender Inclusion Network. EnAble, our pillar for people with disabilities and those that care for them, partners with the Access Lilly initiative to make our physical and digital environment accessible and inclusive for all. Together they are committed to promoting awareness to create a disability confident culture both at Eli Lilly Cork and beyond.

What You’ll Be Doing:

As an Application Security Engineer at Lilly on the Security Architecture and Engineering team, you will play a pivotal role in ensuring the security of our software development lifecycle (SDLC). Your primary responsibility will be to integrate application security testing tools into the development and deployment pipeline, ensuring that every step of the SDLC follows security best practices. You will partner with engineering teams to enable secure coding practices, conduct security testing, and coordinate vulnerability remediation efforts. Additionally, you will collaborate with various stakeholders across the organization to develop and implement application security strategies.

How You’ll Succeed:
  • Technical expertise: As an Application Security Engineer, you will leverage your deep technical knowledge of application security concepts, tools, and best practices to implement tailored security solutions and effectively mitigate threats and risks.
  • Problem-solving skills: Adept problem-solving abilities are crucial in quickly identifying and addressing security issues, ensuring the development and delivery of robust and secure applications in a timely manner.
  • Collaboration and communication skills: You will actively collaborate with both local and remote team members, playing a pivotal role in defining, designing, and executing application security strategies. Excellent communication skills are essential for this role, as you will need to engage with both technical and non-technical audiences, including software developers, DevOps teams, and other stakeholders.
  • Agility: The ability to quickly adapt to the changing threat landscape and move at the pace of the adversary is critical to success in this role.
  • Knowledge of application security trends: This role requires staying abreast of the latest developments in application security, including emerging threats, tools, and best practices, and integrating these insights into our practices.
  • Balancing security and operational needs: You will balance stringent security guidelines with operational requirements, maintaining the desired corporate security posture while demonstrating empathy and understanding towards the engineering teams’ challenges and needs.
Key Responsibilities:
  • Lead and deliver the integration of security testing tools in the Software Development Lifecycle (SDLC), including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secrets scanning, and Dynamic Application Security Testing (DAST) tools.
  • Support and encourage secrets management practices and tooling.
  • Partner with DevOps teams to build security testing and verification into the application development and deployment processes.
  • Secure containers in on-prem and cloud container hosting services, collaborating with Cloud Service delivery teams to ensure secure configuration and deployment.
  • Build relationships with internal and external customers, partnering with them to monitor and coordinate the remediation of vulnerabilities.
  • Develop and maintain technical specifications, design patterns, standards, and security guidance, with a particular emphasis on application security.
  • Perform threat analysis and modeling to enable business and technical partners to deliver secure solutions integrated with the SecOps lifecycle.
  • Coordinate with other cybersecurity teams to drive key vulnerability remediation initiatives.
  • Triage newly identified critical vulnerabilities and zero-day vulnerabilities, assess the threat and impact, and manage escalation processes for remediation based on risk.
  • Continuously improve processes and procedures, including reporting exceptions/risk acceptance for further review and escalation to the appropriate risk owners.
  • Interact with stakeholders to develop and fine-tune the process of how application security metrics are calculated and communicated.
Your Basic Qualifications:
  • Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or related field
  • 5+ years of experience in Cyber Security, Information Technology, or related field. And
  • 2-6 years of demonstrated experience in application security, with a strong focus on integrating security into the SDLC.
  • Proficiency in DevSecOps practices and conducting end-to-end security testing of applications.
Additional preferences:
  • Experience with Checkmarx (SAST/ DAST)
  • Github
  • Experience with evaluating, mitigating and prioritizing application security vulnerabilities, using manual testing methods and/or industry standard commercial or open-source tools.
  • Experience with automating processes for security testing, escalating, and reporting through scripting and working with APIs.
  • Knowledge of and ability to apply frameworks such as OWASP Top 10 and MITRE ATT&CK Framework.

Lillydoes not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.

#WeAreLillyUKandIreland

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior/Principal Cloud Security Engineer
Senior/Principal Cloud Security Engineer

Eli Lilly and Company • Cork

Hybrid
EUR 90,000 - 120,000
Flexible hybrid working
Healthcare
Pension and life assurance
+4
Cyber Intelligence Analyst
Cyber Intelligence Analyst

Eli Lilly and Company • Cork

Hybrid
EUR 60,000 - 90,000
Healthcare benefits
Pension
Life assurance
+4
Senior Application Security Engineer — SDLC & DevSecOps
Senior Application Security Engineer — SDLC & DevSecOps

Eli Lilly and Company • Cork

Hybrid
EUR 90,000 - 130,000
Premium workspace
Hybrid working
Healthcare
+8
SecOps Engineering – Identity Governance Tech Lead
SecOps Engineering – Identity Governance Tech Lead

Eli Lilly and Company • Cork

On-site
EUR 75,000 - 95,000
Flexible hybrid working options
Healthcare benefits
Subsidised canteen
+2
Intern-Medical Information IT
Intern-Medical Information IT

527 Eli Lilly Cork Limited • Cork

Hybrid
EUR 27,000 - 34,000
Healthcare
Pension
Life Assurance
+4
Associate / Sr. Associate/Manager – CTRS -
Associate / Sr. Associate/Manager – CTRS -

Eli Lilly and Company • Cork

Hybrid
EUR 42,000 - 66,000
Flexible hybrid working options
Healthcare benefits
Pension and life assurance
+4
Intern – Digital Legal Office - Governance, Risk & Compliance (GRC)
Intern – Digital Legal Office - Governance, Risk & Compliance (GRC)

527 Eli Lilly Cork Limited • Cork

Hybrid
EUR 310,000 - 371,000
Intern - Central Clinical Services & Innovation
Intern - Central Clinical Services & Innovation

527 Eli Lilly Cork Limited • Cork

Hybrid
EUR 27,000 - 34,000
Hybrid working options
Healthcare benefits
Pension plan
+3
Senior Application Security Engineer
Senior Application Security Engineer

Uniting Holding • Dublin

Hybrid
EUR 75,000 - 95,000
Competitive remuneration
Company-paid health insurance
Hybrid Working Model
+2
Senior Application Security Engineer
Senior Application Security Engineer

SoftCo • Dublin

Hybrid
EUR 120,000 - 180,000
Performance bonus
Health insurance
Pension
+6