Enable job alerts via email!

Application Security Engineer

PENNYMAC

Cary (NC)

Remote

USD 95,000 - 155,000

Full time

13 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join an established industry player as an Application Security Engineer, where you'll be at the forefront of integrating security into the product lifecycle. This role emphasizes collaboration with development teams to ensure secure coding practices and manage vulnerabilities across cloud environments. Your expertise will help shape a security-first culture while automating processes and performing code analysis across various programming languages. With a focus on continuous improvement and mentorship, this position offers a unique opportunity to contribute to an inclusive and innovative environment that values your skills and growth.

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
Wellness Programs
401k

Qualifications

  • Experience with secure coding practices and vulnerability management.
  • Proficient in multiple programming languages and automation scripting.

Responsibilities

  • Integrate security into the product lifecycle and manage CI/CD security.
  • Conduct threat modeling, risk assessments, and security testing.

Skills

Cyber Security
Scripting (BASH/PowerShell)
Secure Coding
Problem-Solving
Communication Skills

Education

2+ years in Cyber Security
3+ years in programming/scripting

Tools

Gitlab
Azure DevOps
AWS
GCP

Job description

Application Security Engineer

Pennymac (NYSE: PFSI) is a specialty financial services firm focused on mortgage production and servicing. Our people are the foundation of our success, working towards helping Americans achieve homeownership.

Job Overview

The Application Security Engineer will join our Information Security team, collaborating with development, product teams, and stakeholders. Responsibilities include integrating security into the product lifecycle, emphasizing cloud environments, secure coding, vulnerability management, attack surface reduction, and DevOps practices. The role requires managing security across applications, CI/CD pipelines, IaC, and conducting risk assessments, with a focus on AWS and some GCP, Linux, and Windows systems. Proficiency in scripting (BASH/PowerShell) and understanding multiple programming languages are essential.

Key Responsibilities
  1. Work with product teams to ensure secure coding practices throughout SDLC.
  2. Implement security platforms like DAST, SAST, SCA, CSPM.
  3. Provide expertise in application security, threat modeling, and secure coding.
  4. Perform code analysis and security reviews across languages such as Ruby, Python, Bash, TypeScript, Java, JavaScript, C++, Go.
  5. Automate security processes with scripting.
  6. Stay updated on security threats and technologies.
  7. Build relationships with development teams to promote security culture.
  8. Support cybersecurity incident responses.
  9. Configure security for serverless and containerized applications.
  10. Collaborate across teams to develop secure systems.
  11. Lead security best practices and standards implementation.
  12. Support secure development standards and governance.
  13. Conduct threat modeling, risk assessments, and security testing.
  14. Maintain open communication to integrate security early in projects.
  15. Mentor junior staff in DevSecOps and security practices.
Qualifications
  • 2+ years in Cyber Security.
  • 3+ years in programming/scripting.
  • Experience with Gitlab, Azure DevOps, AWS, and security controls.
  • Knowledge of secure configuration management, SAST, DAST, penetration testing, and multiple programming languages.
  • Strong problem-solving and communication skills.
  • Ability to work independently and continuously improve processes.
Why Join Us

Join Pennymac, a top mortgage lender committed to sustainable growth and an inclusive environment. We offer comprehensive benefits such as medical, dental, vision, paid time off, wellness programs, 401k, and more. Learn more about our benefits here.

Salary range: $95,000 - $155,000. This role is REMOTE.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Application Security Engineer

PennyMac Mortgage Investment Trust

Cary

Remote

USD 95,000 - 155,000

Yesterday
Be an early applicant

Application Security Engineer

Fingerprint

Chicago

Remote

USD 150,000 - 160,000

11 days ago

Application Security Engineer - Remote

Ryder System, Inc.

Indianapolis

Remote

USD 120,000 - 150,000

2 days ago
Be an early applicant

Sr. Application Security Engineer

Alteryx, Inc

Remote

USD 129,000 - 161,000

2 days ago
Be an early applicant

Application Security Engineer with Security Clearance

ShorePoint, Inc

Herndon

Remote

USD 90,000 - 150,000

Yesterday
Be an early applicant

Senior/Lead Application Security Engineer

BioRender

Remote

USD 90,000 - 150,000

2 days ago
Be an early applicant

Sr. Application Security Engineer

Prosper Marketplace

Remote

USD 100,000 - 150,000

Yesterday
Be an early applicant

Application Security Engineer

U.S. Bank

Washington

Remote

USD 111,000 - 132,000

Yesterday
Be an early applicant

Application Security Engineer

Suncoast Credit Union

Tampa

Remote

USD 88,000 - 148,000

Today
Be an early applicant