Stand out for this role — generate a tailored resume and cover letter in about a minute.
Federal Home Loan Bank of Des Moines is seeking an Application Security Engineer II to embed security across the Software Development Life Cycle. You will lead assessments, secure design reviews, DevSecOps initiatives, and vulnerability management to protect member data and regulatory compliance.
You will collaborate with development teams, administer tooling, and automate security in CI/CD pipelines. Strong communication and technical skills are essential for guiding stakeholders and maturing
At FHLB Des Moines, we work each day to develop an inclusive culture that supports and leverages the complexity of a diverse workforce. This enables us to effectively serve the needs of our members and help them succeed.
The Application Security Engineer II serves as the technical subject matter expert for application security, partnering with software development and technology teams to embed security throughout the Software Development Life Cycle (SDLC). This role performs application security assessments, secure design reviews, DevSecOps initiatives, vulnerability management, and secure coding practices while helping developers deliver secure, resilient applications that protect the organization’s information assets and support regulatory compliance.
Administer code and pipeline security tooling (SAST, DAST, SCA, etc.) as well as container security tooling (image runtime security, vulnerability assessments, etc.).
Maintain and enhance secure code training program.
Provide information security recommendations for code repository and development pipeline implementations.
Administer and secure enterprise source code repositories.
Integrate and automate security controls into CI/CD pipelines and developer workflows.
Partner with stakeholders to prioritize highest risk issues for remediation, disseminate the information and monitor progress for completion.
Serve as a point of contact with application development stakeholders to answer questions, provide security guidance, and foster a strong relationship between departments.
Define processes ensuring third party libraries originate from trusted, approved repositories
Secure Infrastructure as Code deployments to ensure successful system implementations.
Implement automated security scanning of IaC templates.
Identify architectural security risks early in the software development lifecycle
Review application architecture and solution designs for security risks.
Provide security guidance during application design and planning phases.
Contribute security best practice for Bank initiatives that involve updating or creating applications, pipelines, and/or repositories.
Assist in detection engineering/refinement to enable detection, prevention and response to incidents in development environments, pipelines, and developed applications.
Create scripts or tooling to improve application security processes.
Respond to security alerts relating to development environments, pipeline events, and application behavior.
Provide security best practice on code reviews where sensitive components of an application were changed or impacted.
Generate metrics demonstrating risks and remediation progress.
Continuously learn about emerging technologies, their risks, and how to securely leverage them.
Develop proposals and implement new tools and processes to mature the bank’s security program.
Advise and assist with operational security and response to information security incidents.
Provide information security requirement input in support of project initiatives.
Create, develop, implement, and maintain security standards, procedures, and guidelines to mitigate risk in the Bank’s information security posture (internal/external).
Assist with information security strategies andorganizational governance. Communicate security strategies and framework to staff, partners, and other stakeholders.
Promote security awareness through Bank-wide communication of policies and security threats.
Respond and investigate cybersecurity incidents, collect, and analyze information from multiple event sources and internal and external sources.
Examine incidents that may be related to ransomware, host compromise, account compromise, phishing, anomalous user behavior, third parties and data leakage.
Monitor for incidents with endpoints, databases, applications, networking, mobile and cloud services.
Monitor for vulnerabilities within applications, endpoints, databases, networking, and mobile and cloud services.
Collaborate as a purple team with colleagues in offense, defense, operators, threat intelligence and risk management roles.
Recommend tactical options to reduce attack surface, containment alternatives and impede attackers.
Monitor departmental internal controls and regulatory issues.
Other duties and projects as assigned.
Annual Salary: $102,210.00 - $121,374.00
At FHLB Des Moines, we work to create an inclusive culture. This enables us to effectively serve the needs of our members and help them succeed. FHLB Des Moines is proud to be an Equal Opportunity Employer. We prohibit discrimination on the basis of race, color, religion, sex (including pregnancy, sexual orientation or gender identity), national origin, age, disability, veteran status, genetic information (including family medical history), status as a parent or any other characteristic protected by federal, state or local law.