Application Security Engineer II

Federal Home Loan Bank of Des Moines

Des Moines (IA)

Hybrid

USD 102,000 - 121,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work schedule
401(k) plan matching
Paid time off and holidays

Job summary

The Application Security Engineer II at Federal Home Loan Bank of Des Moines partners with software development and technology teams to embed security throughout the SDLC. This role performs security assessments, design reviews, DevSecOps initiatives, and vulnerability management to protect member data.

You will administer code and pipeline security tooling, secure IaC deployments, and provide guidance to developers.

Qualifications

  • 3-5 years in Application Security, Information Security, DevSecOps, or related field.
  • Experience performing application security assessments and validating remediation efforts.
  • Experience with SDLC and working with development teams.

Responsibilities

  • Administer code and pipeline security tooling (SAST, DAST, SCA, etc.).
  • Maintain and enhance secure code training program.
  • Integrate security controls into CI/CD pipelines and developer workflows.
  • Provide security guidance to developers and stakeholders on architecture and design.

Skills

Application security
DevSecOps
SDLC
SAST/DAST/SA
CI/CD tooling
Vulnerability management
IaC security
REST APIs
Docker/Kubernetes
Secure coding

Education

Bachelor's or master's in CS/Cybersecurity/SE

Tools

Code scanning tools
Git
Pipeline automation tools

Job description

At FHLB Des Moines, we work each day to develop an inclusive culture that supports and leverages the complexity of a diverse workforce. This enables us to effectively serve the needs of our members and help them succeed.

The Application Security Engineer II serves as the technical subject matter expert for application security, partnering with software development and technology teams to embed security throughout the Software Development Life Cycle (SDLC). This role performs application security assessments, secure design reviews, DevSecOps initiatives, vulnerability management, and secure coding practices while helping developers deliver secure, resilient applications that protect the organization's information assets and support regulatory compliance.

Key Responsibilities
  • Administer code and pipeline security tooling (SAST, DAST, SCA, etc.) as well as container security tooling (image runtime security, vulnerability assessments, etc.).
  • Maintain and enhance secure code training program.
  • Provide information security recommendations for code repository and development pipeline implementations.
  • Administer and secure enterprise source code repositories.
  • Integrate and automate security controls into CI/CD pipelines and developer workflows.
  • Partner with stakeholders to prioritize highest risk issues for remediation, disseminate the information and monitor progress for completion.
  • Serve as a point of contact with application development stakeholders to answer questions, provide security guidance, and foster a strong relationship between departments.
  • Define processes ensuring third party libraries originate from trusted, approved repositories
  • Secure Infrastructure as Code deployments to ensure successful system implementations.
  • Implement automated security scanning of IaC templates.
  • Identify architectural security risks early in the software development lifecycle
  • Review application architecture and solution designs for security risks.
  • Provide security guidance during application design and planning phases.
  • Contribute security best practice for Bank initiatives that involve updating or creating applications, pipelines, and/or repositories.
  • Assist in detection engineering/refinement to enable detection, prevention and response to incidents in development environments, pipelines, and developed applications.
  • Create scripts or tooling to improve application security processes.
  • Respond to security alerts relating to development environments, pipeline events, and application behavior.
  • Provide security best practice on code reviews where sensitive components of an application were changed or impacted.
  • Generate metrics demonstrating risks and remediation progress.
  • Continuously learn about emerging technologies, their risks, and how to securely leverage them.
  • Develop proposals and implement new tools and processes to mature the bank's security program.
  • Advise and assist with operational security and response to information security incidents.
  • Provide information security requirement input in support of project initiatives.
  • Create, develop, implement, and maintain security standards, procedures, and guidelines to mitigate risk in the Bank's information security posture (internal/external).
  • Assist with information security strategies and organizational governance. Communicate security strategies and framework to staff, partners, and other stakeholders.
  • Promote security awareness through Bank-wide communication of policies and security threats.
  • Respond and investigate cybersecurity incidents, collect, and analyze information from multiple event sources and internal and external sources.
  • Examine incidents that may be related to ransomware, host compromise, account compromise, phishing, anomalous user behavior, third parties and data leakage.
  • Monitor for incidents with endpoints, databases, applications, networking, mobile and cloud services.
  • Monitor for vulnerabilities within applications, endpoints, databases, networking, and mobile and cloud services.
  • Collaborate as a purple team with colleagues in offense, defense, operators, threat intelligence and risk management roles.
  • Recommend tactical options to reduce attack surface, containment alternatives and impede attackers.
  • Monitor departmental internal controls and regulatory issues.
  • Other duties and projects as assigned.
Qualifications
Required
  • 3-5 years of experience in Application Security, Information Security, DevSecOps, or a related field.
  • Experience performing application security assessments and validating remediation efforts.
  • Experience working with software development teams throughout the SDLC.
  • Experience with development and security tooling leveraged in a Secure SDLC (such as code scanning, git, pipeline automation tools. etc.)
  • Experience reviewing vulnerabilities and providing remediation guidance.
  • Knowledge of common web application vulnerabilities (OWASP Top 10).
  • Familiarity with secure authentication, authorization, session management, and encryption principles.
  • Working knowledge of one programming or scripting language (Python, Java, C#, JavaScript, PowerShell, etc.).
  • Understanding of REST APIs and modern web application architectures.
  • Understanding of container technologies (Docker/Kubernetes), security concepts, and security tooling.
  • Familiarity with Infrastructure as Code concepts.
  • Strong written and verbal communication.
  • Ability to explain technical security risks to non-security stakeholders.
  • Strong analytical and problem-solving skills.
  • Ability to manage multiple projects simultaneously.
  • Self-directed with strong organizational skills.
Preferred
  • Bachelor's or master's degree in computer science, Cybersecurity, Information Systems, Software Engineering, or a related technical discipline.
  • Experience implementing DevSecOps practices.
  • Experience developing custom security automation.
  • Experience administering application security tooling.
  • Experience performing secure code reviews.
  • Experience integrating security into CI/CD pipelines.
  • Experience building developer security training programs.
  • Experience with threat modeling methodologies.
  • Experience in Agile development environments.
  • Experience supporting cloud-native applications (Azure, AWS, GCP).
  • Working knowledge of one or more of the following: Web Application Firewalls (WAF). API Security platforms, Secrets Management, Kubernetes security, Supply Chai, Security (SBOM, dependency management), Software composition analysis, Threat modeling (STRIDE, PASTA), OWASP ASVS, OWASP SAMM, OWASP API Security Top 10, Secure SDLC maturity frameworks
  • Certifications CSSLP, GWAPT, GWEB, OSCP, CISSP, Security+, Azure/AWS security certifications
Compensation Range

Annual Salary: $102,210.00 - $121,374.00

This salary range represents the Bank's good faith and reasonable estimate of possible compensation at the time of hire. Offer to be determined by selected applicant's education, experience, knowledge, skills & abilities, as well as internal equity and alignment with market data. This role is also eligible to participate in the Bank's annual incentive plan.

As part of our competitive Total Rewards package, the Bank offers 11 paid holidays, 5 weeks of PTO and a work culture that values work/life balance. Most roles are eligible for our hybrid work schedule. We match 100% of the first 6% you contribute to your 401(k) and provide an additional 4% non-discretionary contribution to your 401(k) at the end of year. More information on our Total Rewards program can be found here.

At FHLB Des Moines, we work to create an inclusive culture. This enables us to effectively serve the needs of our members and help them succeed. FHLB Des Moines is proud to be an Equal Opportunity Employer. We prohibit discrimination on the basis of race, color, religion, sex (including pregnancy, sexual orientation or gender identity), national origin, age, disability, veteran status, genetic information (including family medical history), status as a parent or any other characteristic protected by federal, state or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer II
Application Security Engineer II

FHLB Des Moines • Des Moines (IA), Northern (KY)

Hybrid
USD 102,000 - 121,000
Information Security Analyst II
Information Security Analyst II

Federal Home Loan Bank of Des Moines • Des Moines (IA)

Hybrid
USD 81,000 - 97,000
Hybrid work schedule
Paid holidays
Paid time off
+2
Information Security Analyst II
Information Security Analyst II

FHLB Des Moines • Des Moines (IA)

Hybrid
USD 81,000 - 97,000
Information Security Manager - IAM
Information Security Manager - IAM

FHLB Des Moines • Des Moines (IA)

Hybrid
USD 128,000 - 152,000
Hybrid work schedule
Total Rewards program
Paid holidays
Information Security Intern
Information Security Intern

Federal Home Loan Bank of Des Moines • Des Moines (IA)

On-site
USD 25,000 - 36,000
Information Security Intern
Information Security Intern

FHLB Des Moines • Des Moines (IA), Northern (KY)

Hybrid
USD 26,000 - 34,000
Principal Developer
Principal Developer

Federal Home Loan Bank of Des Moines • Des Moines (IA)

Hybrid
USD 145,000 - 160,000
Hybrid work schedule
401(k) matching
Paid holidays
+1
Senior Developer
Senior Developer

FHLB Des Moines • Des Moines (IA), Northern (KY)

Hybrid
USD 91,000 - 108,000
Hybrid work schedule
401(k) matching program
Paid holidays & PTO
Principal Developer
Principal Developer

FHLB Des Moines • Des Moines (IA)

Hybrid
USD 128,000 - 153,000
5 weeks of PTO
401(k) match
11 paid holidays
+1
IT Auditor
IT Auditor

Federal Home Loan Bank of Des Moines • Des Moines (IA)

Hybrid
USD 102,000 - 122,000
Hybrid work schedule
Total Rewards package
401(k) match