Specialist, Application Security
Job Title: Specialist, Application Security Job Description: We are seeking a highly skilled and motivated Application Security Engineer to join our growing security team. In this role, you will play a critical part in securing our applications by embedding security throughout the Software Development Lifecycle (SDLC), identifying vulnerabilities, and enabling development teams to build secure, resilient systems.
Key Responsibilities
- Perform secure code reviews , dependency analysis (SCA) , and dynamic security testing (DAST) across a range of applications
- Conduct manual security assessments and penetration testing to identify vulnerabilities
- Integrate security best practices into SDLC and CI/CD pipelines
- Collaborate closely with engineering teams to design and implement secure-by-design applications
- Design and implement robust authentication and authorization mechanisms
- Drive adoption of modern application security practices and frameworks
- Stay up to date with the latest security threats, vulnerabilities, and mitigation techniques
- Deliver secure coding training sessions and awareness programs for developers
- Conduct risk assessments and provide actionable recommendations for mitigation
Qualifications & Skills
- 6+ years of combined experience in software development, cybersecurity, and application security
- Hands-on experience with SAST, DAST, and SCA tools
- Strong knowledge of secure SDLC practices and CI/CD security integration
- Proficiency in Python, Java, or JavaScript
- Understanding of AI technologies such as Generative AI and Agentic systems
- Knowledge of security frameworks (OWASP Top 10, NIST, CIS)
- Strong grasp of cryptography, authentication, and authorization protocols
- Experience in threat modeling (experience with commercial tools is a plus)
- Familiarity with cloud and container security (AWS, Azure, Kubernetes)
- Excellent communication and collaboration skills
Preferred Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, or related field
- Industry certifications such as: OSCP / OSWE GWAPT / eWPT CISSP, CSSLP, or CEH (with application security focus)
Experience Level Senior Level