Application Security Engineer, Information Security

Ascensus

Dresher (Montgomery County)

On-site

USD 120,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Tuition reimbursement
Paid time off
Medical benefits
401(k) match
HSA contributions

Job summary

Ascensus is seeking an experienced Application Security Engineer to own and advance the company’s application security program. You will partner with scrum teams to embed secure development practices and ensure confidentiality, integrity, and availability of web apps and APIs.

This role requires strategic thinking, initiative, and collaboration across Tech leadership. You will act as a trusted advisor, shaping security controls, architecture reviews, and threat modeling while integrating

Qualifications

  • Secure software development practices and secure SDLC.
  • Ability to define software security and privacy requirements.
  • Threat modeling and risk mitigation.
  • Experience with CI/CD security integrations.
  • Familiarity with common security testing tools.

Responsibilities

  • Protect confidential data and ensure secure handling.
  • Develop a DevSecOps approach for SDLC across teams.
  • Provide security consultation to scrum teams and owners.
  • Participate in sprint planning to embed security requirements.
  • Conduct app security analysis, architecture reviews, and threat modeling.
  • Build and monitor policies for SAST, DAST, and SCA.
  • Assist with static and dynamic testing and remediation guidance.
  • Other tasks as assigned.

Skills

Secure Software Development
DevSecOps
Threat Modeling
CI/CD
Security Architecture
OWASP Top 10

Tools

SAST
DAST
SCA
Burp Suite
Nessus
Qualys
Kubernetes

Job description

Section 1: Position Summary

Reporting to the BISO, the Application Security Engineer is responsible for the application security program. This position requires a passion for data protection, possesses a combination of either application development and/or security experience, strong communication and organizational skills, collaborative abilities, self-motivation, innovation, efficiency and attention to detail. This position willperforma variety of application security responsibilities across Ascensus and be the primary resource forour application security program. This role serves as a trusted application security advisor to Ascensus scrum teams to drive best practices for application security, to help ensure the confidentiality, integrity and availability of our web and application program interfaces (API).The Application Security Engineeris deeply involved with our application scrum teams and is instrumental in helping define the strategy to meet the information security organizations high level goals, while still being embedded within the scrum team processes and serve as a subject matter expert in secure development practices. This is a critical role at Ascensus requiring strategic thinking, taking initiative, and proactive interaction at many levels. This role will receive strong support of the Head of Technology and the Information Security Leadership, to effectively execute on defined organizational goals and strategic plans.

Section 2: Job Functions, Essential Duties and Responsibilities
  • Responsible for protecting, securing, and proper handling of all confidential data held by Ascensus to ensure against unauthorized access, improper transmission, and/or unapproved disclosure of information that could result in harm to Ascensus or our clients.
  • In conjunction with security and development leadership develops a comprehensive, agile, and innovative DevSecOps approach that supports all phases of the software development lifecycle (SDLC), identifies and effectively manage risk.
  • Provide security consultation to scrum teams, application owners, and technology teams on relevant security controls and secure SDLC process.
  • Participate in sprint planning meetings and various decision‑making sessions to ensure that security requirements and considerations are built into the development practices.
  • Conduct application security analysis, including architecture review, analysis of data flows, penetration testing support, and threat modeling.
  • Build and monitor compliance with application security policies, coding standards, and security controls in support of mitigating threats.
  • Responsible for the deployment and integration of services to support SAST, DAST and SCA functions.
  • Assist development teams in performance of static and dynamic testing, triage findings and provide remediation guidance where necessary.
  • Assist with other tasks and projects as assigned.

Supervision N/A

Section 3: Experience, Skills, Knowledge Requirements
  • Secure Software Development
  • A minimum of 7 years’ experience in Secure Software Development and/or DevSecOps (preferred)
  • Ability to define software security and privacy requirements
  • Solid understanding of threat modeling, risk, and mitigation from internal and external threats
  • Experience with development of system security architecture diagrams and security architecture specification per security architecture standards
  • Experience performing software security design reviews
  • Experience running security testing tools into a CI/CD pipeline including tools such as Static and Dynamic Application Security Testing (SAST/DAST) and Software Composition Analysis (SCA)
  • Experience with application testing tools (e.g., Burp Suite, Fiddler, Zap, Wireshark, Metasploit)
  • Experience with configuration WAF, API Gateway, API Security Tools
  • Solid understanding of the most common application and API security risks (OWASP Top 10, SANS/CWE Top 25)
  • Solid understanding of application, database and network vulnerability testing principles
  • Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM)
  • Experience with assessing secure adoption of third‑party components such as open source or commercial software .NET/Java Experience a plus
  • Information Security Understanding of information security frameworks such as ISO27001, NIST, CSA and operating in a environment regulated against FFIEC, SEC and/or HIPAA requirements
  • Solid understanding f authentication and authorization systems
  • Solid understanding of cryptographic standards(e.g., encryption, hashing, key management, digital signatures, etc.)
  • Ability to provide vulnerability remediation guidance and mentoring to product development software engineers
  • Ability to translate security risks to business impact
  • Experience running or managing vulnerability assessments using automated tools (e.g., Nessus, Qualys, etc) as well as managing penetration testing engagements.
  • Understanding of privacy regulations as it relates to the handling and protection of information.
  • Experience with fraud detection and analysis as it relates to custom developed applications
  • DevSecOps Experience integrating automated testing tools into a CI/CD pipeline
  • Experience in implementing Cloud security controls following owing Cloud Security Alliance (CSA) or Cloud Service Provider (CSP) best practices (Azure, AWS, etc.)
  • Experience implementing and supporting security automation tools (e.g., K8 and CSP platform configuration, hardening, and monitoring).

We are proud to be an Equal Opportunity Employer

Be aware of employment fraud. All email communications from Ascensus or its hiring managers originate from @ascensus.com or @futureplan.com email addresses. We will never ask you for payment or require you to purchase any equipment.

Ascensus helps millions of people save for a better future.

What makes any career at Ascensus so rewarding?
  • Collaborative, idea‑sharing environment
  • Professional Development with in‑house training and tuition reimbursement
  • Generous reward programs
  • Paid time off
  • Medical, dental & vision benefits
  • Health Savings Account with employer contribution up to $1,100
  • 401(k) & 529 college savings match programs
  • Volunteer and charitable‑giving programs
  • Business casual dress
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer, Information Security
Application Security Engineer, Information Security

Ascensus • Northern (KY)

Hybrid
USD 110,000 - 160,000
Application Security Engineer, Information Security
Application Security Engineer, Information Security

Socket.dev • Dresher

On-site
USD 120,000 - 180,000
Principal Software Engineer, IT Software Engineers
Principal Software Engineer, IT Software Engineers

Ascensus • Dresher

On-site
USD 140,000 - 180,000
Medical, dental & vision benefits
Health Savings Account
401(k) & 529 match programs
+1
Sr DevOps Engineer
Sr DevOps Engineer

Ascensus • Town of Texas (WI)

Hybrid
USD 150,000 - 200,000
401(k) match
Medical benefits
Dental benefits
+2
Associate Software Engineer
Associate Software Engineer

Ascensus • Dresher

On-site
USD 65,000 - 80,000
401(k) match
Medical
Dental
+3
Application Architect
Application Architect

Ascensus • Northern (KY)

Hybrid
USD 70,000 - 120,000
Senior Business Systems Analyst
Senior Business Systems Analyst

Ascensus • New Jersey

Hybrid
USD 110,000 - 150,000
401(k) match
Medical
Dental
+5
Senior UX Designer, Digital Program
Senior UX Designer, Digital Program

Ascensus • Massachusetts

Hybrid
USD 110,000 - 170,000
Professional Development with in-house
Tuition reimbursement
Generous reward programs
+3
Application Architect
Application Architect

Ascensus • Kansas

On-site
USD 95,000 - 125,000
Business Program Manager
Business Program Manager

Ascensus • Dresher

On-site
USD 95,000 - 125,000
401(k) matching
Tuition reimbursement
Paid time off
+2