Application Security Engineer (Hybrid)

Transamerica

Philadelphia (Philadelphia County)

Hybrid

USD 70,000 - 84,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Transamerica is seeking an Intermediate Cyber Security Engineer to join our Enterprise Technology team. This hybrid role requires three days in the office per week at our Denver or Cedar Rapids hub.

You will identify weaknesses, support secure SDLC practices, and work with stakeholders across business and technology to reduce application risk. You will also automate vulnerability reporting, develop dashboards, and promote secure coding practices to protect sensitive data and ensure regulatory

Qualifications

  • Bachelor’s degree with emphasis in Computer Science, MIS, Auditing, Finance, or Business or equivalent education and experience required.
  • 1 to 3 years of cyber security engineering work experience required.
  • Experience with one or more application security domain areas, including secure coding, security within the SDLC, application threat modeling, static and dynamic application security testing, software composition analysis, API security, web application firewalls (WAF), container security, vulnerability validation and remediation, application data protection, and alignment with applicable security standards and control frameworks.
  • Knowledge of applicable control frameworks such as: NIST CSF
  • Certifications desirable - OSCP, CISSP, CEH and/or CompTIA Security+/CySA/CASP+.
  • Strong foundation in core security technologies and advanced persistent threat (APT) controls, including SIEM, endpoint security platforms, firewalls, intrusion detection and prevention systems, data loss prevention, syslog servers, vulnerability scanners, web application firewalls, threat intelligence feeds, digital forensics, and application allowlisting.
  • 2-3 years of related work experience with application security
  • Working knowledge of one or more vulnerability management systems including Rapid7, ServiceNow Vulnerability Response (VR), Synk, CrowdStrike, etc.
  • Hands-on experience with application security, dynamic scanning, static scanning, and container security
  • Experience with systems such as ServiceNow, JIRA or equivalent
  • Ability to fluently read, write and speak English
  • Strong background in creating and automating vulnerability reports and dashboards including trending and graphing data

Responsibilities

  • Identify weaknesses and vulnerabilities in relation to industry best practices and provide support to the application of security frameworks and regulatory standards such as NIST CFS
  • Gather and analyze data, draft reports, and create departmental, project, key indicator, and dashboard materials. Build strong working relationships with peers and key stakeholders, including business partners, legal, internal audit, risk, and technology specialists.
  • Review security vulnerabilities across diverse technologies and rapid changing environments including on premise and cloud infrastructure. Supports the analysis, implementation, and management of administrative, technical and physical safeguards to ensure the privacy and protection of company information and supporting technology and services
  • Support application security activities by assisting with secure SDLC practices, static and dynamic application security testing, vulnerability validation, remediation tracking, and coordination with development and technology teams to reduce application risk.
  • Assist in the research, development and implementation of information security initiatives, such as policy, program, process, procedural and technology improvements and solutions
  • Enhance and automate the vulnerability management lifecycle, including intake, prioritization, remediation tracking, reporting, and continuous process improvement.
  • Serve as an application security ambassador by promoting secure coding practices, helping employees and contractors understand their role in reducing application risk, and providing practical guidance on secure SDLC requirements, vulnerability identification, testing expectations, remediation activities, and safe handling of application data.

Skills

Application security
NIST CSF
SDLC security
Vulnerability reports
English language

Education

Bachelor’s degree

Tools

ServiceNow
JIRA
Rapid7
CrowdStrike
Vulnerability Scanners

Job description

Transamerica is seeking an Intermediate Cyber Security Engineer to join our Enterprise Technology team. This hybrid role requires three days in the office per week at our Denver or Cedar Rapids hub.

You will identify weaknesses, support secure SDLC practices, and work with stakeholders across business and technology to reduce application risk. You will also automate vulnerability reporting, develop dashboards, and promote secure coding practices to protect sensitive data and ensure regulatory

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hybrid Application Security Engineer
Hybrid Application Security Engineer

Aegon • Denver (CO)

Hybrid
USD 70,000 - 84,000
Application Security Engineer – SDLC & Vulnerability Expert
Application Security Engineer – SDLC & Vulnerability Expert

Transamerica • Iowa (LA), Northern (KY)

Hybrid
USD 70,000 - 84,000
Mid-Level Application Security Engineer — SDLC & Vulnerability Lead
Mid-Level Application Security Engineer — SDLC & Vulnerability Lead

Transamerica • Cedar Rapids (IA)

On-site
USD 70,000 - 110,000
Intermediate Cyber Security Engineer
Intermediate Cyber Security Engineer

Aegon • Denver (CO)

On-site
USD 70,000 - 84,000
Senior Software Engineer – Cloud & Enterprise Solutions
Senior Software Engineer – Cloud & Enterprise Solutions

Transamerica • Denver (CO)

Hybrid
USD 110,000 - 120,000
401k Match
Employee Stock Purchase Plan
Tuition Reimbursement
+1
Intermediate Cyber Security Engineer
Intermediate Cyber Security Engineer

Transamerica • Cedar Rapids (IA)

On-site
USD 70,000 - 110,000
Hybrid: Mid-Level Business Applications Support Analyst
Hybrid: Mid-Level Business Applications Support Analyst

Transamerica • Iowa (LA), Northern (KY)

Hybrid
USD 59,000 - 75,000
Hybrid-Office environment
Three in-office days per week (Tue–Thu
Hybrid work schedule
Principal Application Security Analyst - Hybrid/Remote
Principal Application Security Analyst - Hybrid/Remote

WPS Health Solutions • Monona (WI)

Hybrid
USD 135,000 - 165,000
Remote and hybrid work options
401(k) with generous company match
Health and dental insurance starting S
+1
Senior Software Engineer - Hybrid, Cloud & API Innovator
Senior Software Engineer - Hybrid, Cloud & API Innovator

Talentify • Philadelphia

Hybrid
USD 110,000 - 120,000
Pension Plan
401k Match
Employee Stock Purchase Plan
+5
Application Security Engineer - Hybrid-Remote
Application Security Engineer - Hybrid-Remote

Strive Health • Denver (CO), Northern (KY)

Hybrid
USD 109,000 - 136,000
Hybrid-Remote Flexibility
Comprehensive Benefits
Financial & Retirement Support
+2