Enable job alerts via email!

Application Security Engineer

Private National Mortgage Acceptance Company, LLC

Agoura Hills (CA)

Remote

USD 95,000 - 155,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Pennymac seeks an Application Security Engineer to enhance security across their software systems and applications. This role involves integrating security into the product lifecycle, managing vulnerabilities, and implementing advanced security measures in cloud and on-prem environments. Ideal candidates will possess strong technical skills, a problem-solving mindset, and the ability to collaborate with various teams. Join a leading mortgage lender and contribute to fostering secure applications while enjoying competitive compensation and benefits.

Benefits

Comprehensive Medical, Dental, and Vision
Paid Time Off Programs
Wellness Programs and Employee Recognition
401k match and tuition reimbursement
Philanthropy Programs

Qualifications

  • 2+ years experience in Cyber Security.
  • 3+ years experience in programming and/or scripting.
  • Excellent problem-solving and communication skills.

Responsibilities

  • Implement and maintain security measures for software applications.
  • Conduct risk assessments and collaborate with development teams.
  • Drive innovation in security practices and mentor junior staff.

Skills

Cyber Security
Secure Coding
Vulnerability Management
Risk Assessment
Problem Solving
Collaboration

Education

Bachelor's Degree in Computer Science or related field

Tools

Gitlab
Azure DevOps
AWS
GCP
SAST
DAST
SCA

Job description

PENNYMAC

Pennymac (NYSE: PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U.S. mortgage loans and the management of investments related to the U.S. mortgage market.

At Pennymac, our people are the foundation of our success and at the heart of our dynamic work culture. Together, we work towards a unified goal of helping millions of Americans achieve aspirations of homeownership through the complete mortgage journey.


A Typical Day

TheApplication Security Engineer will be a part of our Information Security department and work closely with development teams, product teams, and other stakeholders across the organization. TheApplication Security Engineerwill integrate security into the product lifecycle from design through deployment, with a strong emphasis on cloud environments, secure coding, vulnerability management, attack surface reduction and DevOps practices. The engineer will be responsible for implementing and maintaining advanced security measures to safeguard Pennymac's software systems, applications, code, and related components. The ideal candidate will have a strong background in both cloud and on-premises environments, proficiency in scripting languages (particularly BASH and/or PowerShell), and the ability to understand multiple programming languages. Key responsibilities include managing security across multiple applications, CI/CD pipelines, Infrastructure as Code (IaC) practices, and conducting risk assessments. The role requires a blend of technical expertise in cloud platforms (primarily AWS, with some GCP exposure), system administration skills across Linux and Windows environments, and the ability to effectively communicate complex security concepts to both technical and non-technical audiences. This position offers the opportunity to drive security innovation, mentor junior staff, and contribute to the development of comprehensive, multi-year cybersecurity strategies for Pennymac.

TheApplication Security Engineerwill:

  • Work with product teams throughout the entire SDLC to ensure code is secure by design, secure by default, secure in deploymentand communication.
  • Implement and maintain key security platforms including DAST, SAST, SCA, CSPM to enhance the organization's security posture.
  • Provide subject matter expertise on application security domains, including secure coding practices, continuous integration anddeployment, and threat modeling.
  • Perform application code analysis and contribute to security-related code reviews and scanning capabilities across multipleprogramming languages (e.g., Ruby, Python, Bash, TypeScript, Java, JavaScript, C++, Go).
  • Develop and maintain scripts to automate security processes and enhance efficiency.
  • Stay current with emerging security threats, technologies, and best practices, applying this knowledge to continuously improvePennymac's security posture.
  • Build relationships with development teams to foster an inclusive culture.
  • Provide subject matter expertise on application security domains including secure coding practices, continuous integration andcontinuous deployment, and threat modeling.
  • Participate in and provide support during high-priority cybersecurity incidents.
  • Configure cybersecurity systems to monitor and protect serverless and container based computing applications.
  • Work cross-functionally with DevOps, application development, database, and infrastructure teams to develop and maintain complexsystems that involve integration across in-house developed, COTS, and open-source components.
  • Establish oneself as a trusted security advisor leading the design, definition and implementation of security best practices andstandards and ensure product development teams integrate them into their development workflow.
  • Support the establishment, implementation, and governance of secure development standards and security baseline requirements.
  • Drive threat modeling, risk assessment, penetration test findings analysis, and security technology assessments.
  • Maintains an open communication channel with operations, development, and product teams to ensure security is integrated earlyand is working to solve business needs.
  • Mentor junior staff to develop understanding of DevSecOps, Application Security, and Information Security.

What You’ll Bring

  • 2+ Years Experience in Cyber Security
  • Approximately 3+ years of experience in programming and/or scripting languages.
  • Ability or aptitude to operate within Gitlab and Azure DevOps source code and CI/CD technology stacks.
  • Experience dealing with secure network and system design in Amazon Web Services (AWS)
  • Expert understanding of secure configuration management and security controls.
  • Experience reviewing SAST, DAST, penetration test, and SCA results and providing remediation recommendations.
  • Experience performing application code analysisacross multipleprogramming languages (e.g., Ruby, Python, Bash, TypeScript, Java, JavaScript, C++, Go).
  • Capable of architecting, engineering, and operationalizing application security technologies through plan, development, build, test,release, deploy, operate, and monitor phases of the SDLC.
  • Experience in developing and/or reviewing secure development standards that incorporate regulatory and industry best practices.
  • Desired experience with Web Penetration Testing tools for validation of security requirements.
  • Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills.
  • Must have a mindset of continuous improvement of people, processes and technology.
  • Ability to work independently and self-motivate.

Why You Should Join

As one of the top mortgage lenders in the country, Pennymac has helped over 4 million lifetime homeowners achieve and sustain their aspirations of home. Our vision is to be the most trusted partner for home. Together, 4,000 Pennymac team members across the country are guided by our core values: to be Accountable, Reliable and Ethical in all that we do.Pennymac is committed to conducting a business that makes positive contributions and promotes long-term sustainable growth and to fostering an equitable and inclusive environment, where all employees and customers feel valued, respected and supported.

Benefits That Bring It Home: Whether you're looking for flexible benefits for today, setting up short-term goals for tomorrow, or planning for long-term success and retirement, Pennymac's benefits have you covered. Some key benefits include:

  • Comprehensive Medical, Dental, and Vision
  • Paid Time Off Programs including vacation, holidays, illness, and parental leave
  • Wellness Programs, Employee Recognition Programs, and onsite gyms and cafe style dining (select locations)
  • Retirement benefits, life insurance, 401k match, and tuition reimbursement
  • Philanthropy Programs including matching gifts, volunteer grants, charitable grants and corporate sponsorships

To learn more about our benefits visit: https://pennymacnews.page.link/benefits

For residents with state required benefit information, additional information can be found at: https://www.pennymac.com/additional-benefits-information

Compensation: Individual salary may vary based on multiple factors including specific role, geographic location / market data, and skills and experience as defined below:

  • Lower in range - Building skills and experience in the role
  • Mid-range - Experience and skills align with proficiency in the role
  • Higher in range - Experience and skills add value above typical requirements of the role

Some roles may be eligible for performance-based compensation and/or stock-based incentives awarded to employees based on company and individual performance.


Salary

$95,000 - $155,000
Work Model

REMOTE
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Application Security Engineer

Pennymac

Agoura Hills

Remote

USD 95,000 - 155,000

Yesterday
Be an early applicant

Sr. Application Security Engineer (Remote)

Rula

Los Angeles

Remote

USD 110,000 - 150,000

Yesterday
Be an early applicant

Application Security Engineer

Physna

Remote

USD 116,000 - 156,000

Yesterday
Be an early applicant

Senior Application Security Engineer

Avalara Technologies

Remote

USD 120,000 - 180,000

2 days ago
Be an early applicant

Application Security Engineer

Prelim

Remote

USD 120,000 - 150,000

7 days ago
Be an early applicant

Senior Application Security Engineer

House Rx

Washington

Remote

USD 150,000 - 180,000

3 days ago
Be an early applicant

Application Security Engineer

SIDRAM TECHNOLOGIES

Alaska

Remote

USD 90,000 - 130,000

3 days ago
Be an early applicant

Associate Application Security Engineer

Veeva Systems

Remote

USD 90,000 - 130,000

5 days ago
Be an early applicant

Senior Application Security Engineer

Promote Project

Ohio

Remote

USD 67,000 - 123,000

5 days ago
Be an early applicant