Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
Join a forward-thinking company as an Application Security Engineer, where you'll play a crucial role in safeguarding applications and data. This position demands a strong technical background and a passion for security best practices throughout the software development lifecycle. Collaborate with talented software development teams, conduct thorough security assessments, and design secure coding standards. Stay ahead of the latest security trends and technologies, and make a significant impact by implementing robust security measures. If you are driven, analytical, and ready to tackle complex challenges, this role offers an exciting opportunity to advance your career in a dynamic environment.
Indianapolis, IN, 46202, USA
Job Seekers can review the Job Applicant Privacy Policy by clicking HERE.
We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates must possess a solid understanding of the security and privacy of our company's applications and data.
The Application Security Engineer must understand development, coding, security engineering, and secure systems configurations. This position ensures that every step of the software development lifecycle (SDLC) follows security best practices. This involves conducting security assessments with SAST and DAST tools, reading source code, threat modeling, and designing and implementing secure software development practices. They will determine where security vulnerabilities exist and implement fixes. They must understand how an application may be misused and exploited. The Application Security Engineer will collaborate with software development teams and provide guidance on best practices for secure coding. They will also stay up to date on the latest security trends and technologies and integrate them into the organization's security strategy. The ideal candidate will have strong analytical and problem-solving skills, as well as experience in application security and knowledge of programming languages and web technologies. A Bachelor's degree in Computer Science and certifications such as CISSP, OSCP, or CASE are preferred.
Five (5) years or more experience with OWASP, SAST, DAST, SCA, RASP and common security tools, required.
Seven (7) years or more application security, security engineering, software development, or a related field, required.
Five (5) years or more strong understanding of web application security and common attack vectors (e.g., SQL injection, XSS, CSRF), required.
Five (5) years or more experience with secure coding practices, threat modeling, and SDLC methodologies, required.
Five (5) years or more proven experience in diagnosing, isolating, resolving complex issues, and recommending/implementing strategies, required.
Five (5) years or more demonstrated experience with systems integration processes, methodology, and tools, required.
Seven (7) years or more development and scripting experience, required.
Five (5) years or more professional application security role, required.
Five (5) years or more experience with API and Web Security, required.
Three (3) years or more experience with WAF or similar security infrastructure, preferred.
Seven (7) years or more experience in integrating security in CI/CD, DevOps, required.
Six (6) years or more experience in process or operation management.
Six (6) years or more experience with Value Stream Mapping, Continuous Flow, Pull Replenishment, and other process improvements.
Excellent communication skills, both verbal and written, with ability to work effectively across teams.
Ability to build and maintain professional relationships at all organizational levels.
Ability to work independently and collaboratively.
Self-driven and adaptable in a fast-paced environment.
Highly organized with excellent time management skills.
Proficiency in at least one scripting language (. PowerShell, bash, etc.), advanced level, required.
Familiarity with NIST, PCI, ISO 27001, SOC, SOX, CCPA, GDPR, and global regulations, expert level, required.
Experience with CI/CD tools like Azure DevOps, Terraform, or similar, expert level, required.
Skills in risk management, vulnerability prioritization, threat modeling, and mitigation strategies, advanced level, required.
1-10%
Applicants from California, Colorado, Hawaii, New Jersey, New York City, and Washington:
Salary is based on internal equity, market data, and internal salary ranges.
The salary range for this position is $120,000 - $150,000. Employees may be eligible for an annual bonus.
Ryder offers comprehensive health and welfare benefits, including medical, prescription, dental, vision, life insurance, disability insurance, paid time off, and a 401(k) plan.
Information Security
Application Security Engineer • Indianapolis, IN, United States