Application Security Engineer

Sequoia

Tempe (AZ)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sequoia is seeking an Application Security Engineer in Tempe, AZ to provide application security expertise throughout the Software Development Life Cycle (SDLC). You'll validate and test web applications to ensure compliance with industry best practices while conducting penetration tests and threat modeling.

Ideal candidates should have over 5 years of experience in application development or security, with strong programming skills in various languages. Sequoia values integrity, innovation, and caring for others, providing competitive compensation and a comprehensive benefits package.

Qualifications

  • 5+ years' experience in application development, application security or related fields.
  • 3+ years programming experience in languages like Python, Ruby, or Java.
  • Experience with threat modeling and penetration testing.

Responsibilities

  • Conduct application security reviews to identify vulnerabilities.
  • Perform penetration testing to assess existing security controls.
  • Develop security guidance documentation for internal teams.

Skills

Application development
Application security
Programming in Python
Threat modeling
Penetration testing

Education

Bachelor's degree in computer science or equivalent

Tools

OWASP Dependency-Check
Burp Suite
MetaSploit

Job description

Who We Are:

Sequoia is the strategic partner helping investor-backed companies of all sizes achieve their business goals through smarter people spend. For 24 years, we’ve guided the most innovative employers to navigate growth and get the most out of their global people investment. With our expert advisory team and integrated platform, we help clients drive business impact through their total comp and benefits, improving executive decision making, controlling costs, protecting the business, and elevating the employee experience. Visit Sequoia.com or follow us on LinkedIn to learn more.

As an Application Security Engineer, you will be providing application security expertise throughout the Software Development LifeCycle (SDLC) as well as being responsible for managing and driving forward the Application Security Analytics practices. A key part of your role will also involve validating and testing web applications in order to ensure applications meet the requirements of the SDLC Policy and industry best practices. In addition, undertaking threat modelling and conducting periodic penetration testing using best of breed tools, a good understanding of the OWASP Top 10 vulnerabilities and maintaining documentation.

You’ll perform various day-to-day activities related to ensuring the security of Sequoias application environment. These tasks may include conducting application security reviews to identify vulnerabilities in software applications that could be exploited by attackers, performing penetration testing to assess the effectiveness of existing security controls and identify potential weaknesses, providing training and outreach to internal development teams to improve their understanding of security best practices, developing security guidance documentation to help others understand how to implement secure systems and applications, developing security tools to automate or streamline security processes, delivering security metrics to stakeholders and working on improving the overall security posture of your organization.

What You Get to Do:
  • Application security reviews
  • Mobile security reviews
  • Secure architecture design
  • Threat modeling
  • Projects and research work as needed
  • Security training and outreach to internal development teams
  • Security guidance documentation
  • Security tool development
  • Security metrics delivery and improvements
  • Assistance with recruiting activities and administrative work
What You Bring:
  • 5+ years' experience with emphasis on application development, application security or related fields.
  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object-oriented language experience
  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • 3+ years' experience in application security technologies with knowledge of application security threats. Experience with threat modeling, attack surface analysis, penetration testing, software vulnerability assessments, and understanding of software security threat vectors.
  • Knowledge of Component Analysis using tools such as OWASP Dependency-Check, Bytesafe Dependency Checker, Patton, PHP Security Checker, etc.
  • Experience with static and dynamic application security testing.
  • Experience with AWS products and services
  • Bachelor's degree in computer science or equivalent
Preferences:
  • Experience as an application security engineer using a suite of tools used for the following:
  • Recon and Information Gathering (e.g. Nmap, NetCat, Spiders, OWASP Zed Attack Proxy).
  • Mapping and Discovery (e.g. Burp Suite with plug-ins)
  • Exploitation of top OWASP vulnerabilities such as SQL Injection, Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF) attacks, etc. Experience with tools such as MetaSploit, AppScan or WebInspect.
  • Knowledge of Threat modeling using PASTA and STRIDE methodology.
  • Knowledge of OWASP Best practices
  • Knowledge of OWASP Testing Guide 4.0
  • Knowledge of OWASP Code Review 2.0
  • Knowledge of Software Component Verification
Sequoia’s Culture – Our most important asset
  • Integrity
  • Passion for service
  • Innovative
  • Growth oriented
  • Caring for others
  • Promise-centric
  • Focused on relationship building

Sequoia provides equal opportunity to all applicants without regard to race, color, creed, religion, citizenship, national origin, age, sex, sexual orientation, gender identity, pregnancy, marital status, military or veteran status, disability, or any other basis prohibited by applicable law.

Compensation & Benefits

Sequoia provides competitive compensation including base salary, performance-based bonus programs, and comprehensive benefits package.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Application Security Engineer
Application Security Engineer

Awardco, Inc. • Lindon (UT)

On-site
USD 110,000 - 140,000
Application Security Engineer-68257
Application Security Engineer-68257

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Application Security Engineer - Chandler, AZ
Application Security Engineer - Chandler, AZ

Motion Recruitment • Chandler (AZ)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Application Security Engineer — SDLC & Threat Modeling
Application Security Engineer — SDLC & Threat Modeling

Sequoia • Tempe (AZ)

On-site
USD 100,000 - 130,000
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Application Security Engineer
Application Security Engineer

Spry Methods, Inc. • Washington

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+4
Application Security Engineer
Application Security Engineer

ManpowerGroup Global, Inc. • Phoenix (AZ)

Hybrid
Medical and Prescription Drug Plans
Dental Plan
Vision Plan
+3