Lead Application Security - DevSecOps & AI-Driven Software Assurance

East West Bank

San Marino (CA)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

East West Bank seeks a Senior Cyber Security Engineer to lead security initiatives across the application lifecycle, integrating security into DevOps and overseeing vulnerability management and testing across enterprise applications.

The role covers third-party software analysis, binary inspection, and secure software onboarding within a regulated banking environment. Strong collaboration with Dev teams and stakeholders is essential.

Qualifications

  • Proven experience in application security, DevSecOps, or software security analysis.
  • Strong hands-on expertise in SAST/DAST tools and secure SDLC practices.
  • Experience with GitHub and open-source ecosystems; GitHub Advanced Security.

Responsibilities

  • Embed security controls into CI/CD pipelines using GitHub workflows.
  • Collaborate with development teams to implement secure coding practices and threat modeling.
  • Manage GitHub Advanced Security configurations, including secret scanning and impact analysis.
  • Conduct SAST/DAST and perform code reviews to identify vulnerabilities.
  • Maintain mapping of applications to GitHub repositories for vulnerability tracking.
  • Analyze third-party software including binary analysis where source is unavailable.
  • Support software trust framework and secure onboarding decisions.
  • Analyze open-source dependencies and contribution risk.
  • Integrate threat intelligence into software risk assessments.
  • Reassess software trust posture as threat conditions change.

Skills

SAST/DAST tools
Secure SDLC
GitHub & OSS
GitHub Advanced Security
Third-party software risk analysis
Software supply chain security
Threat intelligence integration
Threat modeling (STRIDE)
Penetration testing coordination
Stakeholder communication

Tools

CodeQL
OWASP ZAP
Dependabot

Job description

Since 1973, East West Bank has served as a pathway to success. With over 110 locations across the U.S. and Asia, we are the premier financial bridge between the East and West. Our teams of experienced, multi-cultural professionals help guide businesses and community members on both sides of the Pacific looking to explore new markets and create new opportunities, and our sustained growth and expertise in industries like real estate, entertainment and media, private equity and venture capital, and high-tech help build sustainable businesses and expand our associates’ potential for career advancement. Headquartered in California, East West Bank (Nasdaq: EWBC) is a top-performing commercial bank with a strong foundation, an enterprising spirit and a commitment to absolute integrity. East West Bank gives people the confidence to reach further.

Overview

The Senior Cyber Security Engineer will lead and execute security initiatives across the application lifecycle, integrating security into DevOps pipelines, managing vulnerability assessments, and coordinating penetration testing efforts. This role also extends into advanced software assurance, including third-party software analysis, binary-level inspection, and application trust validation, ensuring that both internally developed and externally sourced applications meet the bank’s security standards prior to execution within the enterprise environment.

Responsibilities
Application Security & DevSecOps Integration
  • Embed security controls into CI/CD pipelines using GitHub workflows and automation tools.
  • Collaborate with development teams to implement secure coding practices and threat modeling during design and development phases.
  • Manage GitHub Advanced Security configurations, including secret scanning, push protection, and impact analysis.
Security Testing & Vulnerability Management
  • Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using approved tools (e.g., CodeQL, Dependabot,, OWASP ZAP).
  • Perform manual and automated code reviews to identify vulnerabilities and ensure remediation through code fixes or configuration changes.
  • Maintain accurate mapping of applications to GitHub repositories to support vulnerability tracking and reporting.
Advanced Software Analysis & Trust Establishment
  • Perform security analysis of third-party software, including both source code review and compiled binary analysis where source is not available.
  • Conduct binary decomposition and reverse engineering techniques, as appropriate, to evaluate software behavior and identify embedded risks.
  • Support the establishment and execution of a software trust and reputation framework, enabling secure decision-making for application onboarding and whitelisting within the enterprise environment.
  • Analyze open-source and GitHub-hosted code, including dependencies and contribution risk.
  • Partner with AppSec leadership to support application security activities and formalize secure software approval processes.
API & Web Application Security
  • Conduct API security assessments and integrate monitoring tools to protect application endpoints.
  • Support WAF policy management and application-layer threat monitoring.
  • Threat Intelligence Integration
  • Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software.
  • Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications.
Penetration Testing & Third-Party Risk
  • Integrate threat intelligence insights into software risk assessments, including monitoring for newly disclosed vulnerabilities or exposures in previously approved software.
  • Reassess software trust posture when threat conditions change, ensuring continuous validation of approved applications.
Qualifications
  • Proven experience in application security, DevSecOps, or software security analysis.
  • Strong hands-on expertise in:
  • SAST/DAST tools and secure SDLC practices
  • GitHub and open-source ecosystems
  • GitHub Advanced Security
  • Experience with third-party software risk analysis, software composition analysis (SCA), or reverse engineering / binary analysis
  • Familiarity with software supply chain security and trust validation frameworks
  • Experience integrating threat intelligence into security decision-making
  • Strong understanding of secure SDLC, threat modeling (e.g., STRIDE), and vulnerability management.
  • Experience coordinating penetration tests and working with third-party vendors.
  • Strong communication and stakeholder engagement skills.

Applicants must have legal authorization to work in the United States. We do not offer visa sponsorship at this time.

Compensation

The base pay range for this position is USD $120,000.00/Yr. - USD $180,000.00/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Architect
Cybersecurity Architect

East West Bank • Dallas (TX)

On-site
USD 160,000 - 220,000
Senior DevSecOps & AI-Driven Application Security Engineer
Senior DevSecOps & AI-Driven Application Security Engineer

East West Bank • San Marino (CA)

On-site
USD 120,000 - 180,000
ITU Data Analytics & Reporting Analyst
ITU Data Analytics & Reporting Analyst

East West Bank • Pasadena (CA)

On-site
USD 90,000 - 150,000
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Sr Application Penetration Tester at KeyBank Brooklyn, OH
Sr Application Penetration Tester at KeyBank Brooklyn, OH

KeyBank • Brooklyn (OH)

On-site
USD 94,000 - 175,000
Eligible for incentive compensation
Inclusive company culture
Professional development opportunities
DevSecOps - Automations Engineer
DevSecOps - Automations Engineer

Washington Trust Bank • Spokane (WA)

On-site
USD 99,830 - 149,745
Health, Retirement, and Work/Life Ben­
Incentive plan eligibility
Banking Operations Senior Business Analyst
Banking Operations Senior Business Analyst

East West Bank • El Monte (CA)

On-site
USD 80,000 - 150,000
Senior Configuration Management Engineer
Senior Configuration Management Engineer

East West Bank • El Monte (CA)

On-site
USD 28,000 - 62,000
External Attack Surface Management Analyst
External Attack Surface Management Analyst

Us Bank • Irving (TX)

On-site
USD 93,000 - 109,000
Healthcare benefits
401(k) plan
Paid vacation and holidays
+3