Application Security Engineer 3

Bloomberg BNA

Arlington (VA)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bloomberg Industry Group is seeking an Application Security Engineer III to lead security engineering initiatives and guide teams across the SDLC. You will design scalable controls for cloud‑native apps, perform risk assessments, and drive automation in security testing and deployment.

The role requires deep expertise in AppSec, strong coding skills (Python/Java/JavaScript), and experience with SAST/DAST/SCA, IaC, containers, and Kubernetes.

Qualifications

  • Deep expertise in application security and risk management, including OWASP ASVS, OWASP Top10, and NIST800-53.
  • Experience conducting complex security assessments and building automated security controls for large engineering environments.
  • Proficiency in multiple programming languages (Python, Java, JavaScript) and hands‑on experience with SAST, DAST, SCA, IaC, container, and cloud security tools.
  • Strong understanding of modern architectures (cloud‑native, microservices, Kubernetes, containers, serverless) and DevSecOps processes.

Responsibilities

  • Design and implement security architectures and controls for large‑scale, cloud‑native applications.
  • Conduct in‑depth risk assessments, including penetration testing and code reviews.
  • Collaborate with developers and DevOps to integrate security across the SDLC.
  • Drive security for AI‑powered features by defining secure architectures and testing AI models and MCP servers.

Skills

Python
Java
JavaScript
SAST
DAST
SCA
IaC
Kubernetes
Containers

Education

Bachelor's degree in Information Security or Computer Science

Tools

AWS
GCP
Azure

Job description

About the Team

Bloomberg Industry Group’s Application Security team focuses on providing best‑in‑class security for all internal and external applications.

Job Summary

As an Application Security EngineerIII, you will lead security engineering initiatives, perform advanced risk assessments, and design scalable security controls across critical applications. You will serve as a subject‑matter expert (SME) in application security, guiding engineering teams, influencing security strategy, and driving automation across the SDLC. This role requires deep technical expertise, leadership potential, and the ability to shape long‑term Application Security direction.

What You Will Do
  • Design and implement security architectures and controls for large‑scale, cloud‑native applications.
  • Conduct in‑depth risk assessments, including penetration testing and code reviews.
  • Collaborate with developers and DevOps teams to integrate security at all stages of the software development lifecycle (SDLC).
  • Drive security for AI‑powered features by defining secure architectures, assessing AI/ML risks, and implementing advanced testing and controls for AI models, agents, and MCP servers.
  • Identify areas of improvement in security tools and practices, remediating identified gaps with innovative solutions.
  • Evaluate third‑party security tools and vendor‑provided controls for technical effectiveness, enterprise fit, and alignment with Bloomberg’s security architecture and standards.
  • Collaborate with vendors to provide actionable technical feedback, drive product improvements, and ensure controls are implemented and configured appropriately for Bloomberg Industry Group’s environment.
  • Build, improve, and scale security automation, integrating tooling across CI/CD pipelines and cloud platforms.
  • Provide guidance to junior engineers and cross‑functional teams on security best practices.
  • Participate in incident response efforts and investigations into security incidents.
  • Stay ahead of the curve by keeping informed of industry trends and emerging threats, applying this knowledge to continually improve security.
You Need to Have
  • Deep expertise in application security, secure software design, and risk management, including frameworks such as OWASP ASVS, OWASP Top10, and NIST800‑53.
  • Extensive experience conducting complex security assessments and building automated security controls for large engineering environments.
  • Proficiency in multiple programming languages (e.g., Python, Java, JavaScript) and hands‑on experience with SAST, DAST, SCA, IaC, container, and cloud security tools.
  • Strong understanding of modern architectures (cloud‑native, microservices, Kubernetes, containers, serverless) and DevSecOps processes.
  • Advanced understanding of AI/ML security, including model vulnerability analysis, AI threat modeling, secure LLM integration patterns, and familiarity with NIST AI RMF or OWASP Top10 for LLMs.
  • 5‑7 years of relevant experience in Application Security, AppSec engineering, Cloud Security, or Software Engineering.
We would Love to See
  • Certifications such as AWS Certified Security – Specialty, CSSLP, CISSP, Certified DevSecOps Expert (CDE), or equivalent.
  • A bachelor’s degree in information security, Computer Science, or a related field, or equivalent experience.
Equal Opportunity

Bloomberg Industry Group maintains a continuing policy of non‑discrimination in employment. It is Bloomberg Industry Group’s policy to provide equal opportunity and access for all persons, and the Company is committed to attracting, retaining, developing, and promoting the most qualified individuals without regard to age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or maternity/parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law (“Protected Characteristic”). Bloomberg prohibits treating applicants or employees less favorably in connection with the terms and conditions of employment, in all phases of the employment process, because of one or more Protected Characteristics (“Discrimination”).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer 3
Application Security Engineer 3

Bloomberg BNA • Arlington (TX)

On-site
USD 120,000 - 150,000
Application Security Engineer I
Application Security Engineer I

Bloomberg Industry Group • Arlington (VA)

On-site
USD 90,000 - 110,000
Application Security Engineer I
Application Security Engineer I

Bloomberg BNA • Arlington (TX)

On-site
USD 90,000 - 110,000
Senior Application Security Engineer — Cloud, AI & Automation
Senior Application Security Engineer — Cloud, AI & Automation

Bloomberg BNA • Arlington (VA)

On-site
USD 140,000 - 180,000
Infrastructure Engineer - Security & Compliance
Infrastructure Engineer - Security & Compliance

Bloomberg L.P. • New York (NY)

On-site
USD 130,000 - 225,000
Comprehensive benefits plan
401(k) + match
Paid time off
Infrastructure Engineer - Security & Compliance New York, NY Posted today
Infrastructure Engineer - Security & Compliance New York, NY Posted today

Bloomberg L.P. • New York (NY)

On-site
USD 130,000 - 225,000
Medical benefits
401(k) + match
Paid time off
Web Application Architect 3 (INDG)
Web Application Architect 3 (INDG)

Bloomberg BNA • Arlington (TX)

On-site
USD 90,000 - 120,000
Web Application Architect 3
Web Application Architect 3

Bloomberg Industry Group • Arlington (VA)

On-site
USD 100,000 - 130,000
Technical Architect Lead
Technical Architect Lead

Bloomberg BNA • Arlington (TX)

Hybrid
USD 152,000 - 185,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000