Enable job alerts via email!

Lead Application Security Engineer – Remote @ Triumph Financial

Cyber Crime

Town of Texas (WI)

Remote

USD 146,000 - 227,000

Full time

26 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a Lead Application Security Engineer to spearhead cybersecurity initiatives. In this dynamic role, you will leverage your expertise in application security assessments, code reviews, and vulnerability management to protect applications and enhance security measures. You will collaborate with development teams to implement security strategies within CI/CD pipelines and provide training on secure coding practices. This position offers a unique opportunity to influence the security landscape of a leading financial technology organization while working remotely. Join a team dedicated to operational excellence and continuous improvement in a collaborative environment.

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
401k

Qualifications

  • 5+ years of experience in application security and DevSecOps.
  • Knowledge of OWASP Top 10 and secure coding practices.

Responsibilities

  • Lead application security assessments and vulnerability management.
  • Implement security strategies in CI/CD pipelines and conduct code reviews.
  • Consult and train developers on secure coding practices.

Skills

Application Security
DevSecOps
Penetration Testing
Vulnerability Management
Secure Coding Practices
Critical Thinking
Problem Solving

Education

Bachelor’s Degree in Computer Science

Tools

AWS
Kubernetes
Docker
Jenkins
Github

Job description

Lead Application Security Engineer - Remote
Triumph Financial

TriumphX, a member of the Triumph Financial portfolio of brands, provides a concentration of technology and project management resources to the members of the Triumph Financial portfolio of brands – TriumphPay, Triumph, and TBK Bank – via a shared service model. We’re looking for top tech and project management talent to analyze, recommend, and build strategic solutions that support Triumph Financial’s mission to become a world-class, market-leading financial and technology company.

In this role, you will lead Cybersecurity and apply technical application security testing expertise to assist in identifying application vulnerabilities. As a Lead Application Security Engineer, we hope you possess a solid understanding of application security assessments, code reviews, penetration testing, and vulnerability management. You'll also require the responsibility of serving as a subject matter expert in product security architecture, security testing, secure design review, and security engineering.

A Day in the Life:
  1. Design and implement SDLC practices including code reviews, static/dynamic code analysis, and vulnerability assessments.
  2. Implement various types of scanning (SAST, DAST, SCA, etc.) into the CI/CD pipelines and ensure results are appropriately surfaced to developers.
  3. Develop security-related libraries used in the environment.
  4. Collaborate with developers and conduct regular security assessments.
  5. Develop security integrations to be used in CI/CD pipeline and for development teams.
  6. Work with development teams to ensure that application security risks are identified and remediated in a timely manner while maintaining a balance between security & usability.
  7. Consult and train developers on secure coding practices and ensure development teams are validating for OWASP.
  8. Triage vulnerabilities from dynamic and static scanning tools with development teams.
  9. Implement security strategies to mature the OWASP software assurance maturity model.
  10. Manage and tune web application firewalls.
  11. Design and implement technologies to automate security processes.
  12. Consult on secure architecture, least privileged design, threat mitigations, and security standard methodologies.
  13. Other duties as assigned.
To Succeed in this role you'll need:
  1. Bachelor’s Degree in Computer Science or related field is preferred.
  2. 5+ years of experience in application security, application development, and DevSecOps.
  3. OSWE, GWAPT, or similar certification is preferred.
  4. Ability to communicate and present security concepts to technical and non-technical audiences.
  5. Knowledge with SOX and SOC2 compliance is a plus.
  6. Knowledge of AWS and Kubernetes or related cloud/container technologies is preferred.
  7. Experience with identity lifecycle management and federation technologies such as SAML.
  8. Knowledge of Docker, Kubernetes, Jenkins, and Github.
  9. Extensive knowledge of the OWASP Top 10.
  10. Certification Preferences: Preferably, one or more of the following: GWEB, CSSLP, GPEN, or CRISC.
Additional skills you must have:
  1. Ability to function with moderate supervision.
  2. Strong interpersonal skills.
  3. Quality written and oral communication, and presentation skills.
  4. Critical thinking and problem-solving skills.
  5. Commitment to operational excellence and continuous process improvement.
  6. Willingness to expand and apply security knowledge, skills, and abilities to department initiatives.

#LI-BA1

***Remote U.S. excluding the following states: AK, DE, ID, ND, RI, VT, WY***

COMP: 146,600 - 227,000

We offer Medical, Dental, Vision, Paid Time Off, 401k, and much more.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Lead Application Security Engineer - Remote

Triumph Financial

Remote

USD 168,000 - 273,000

4 days ago
Be an early applicant

Principal Application Security Engineer

Henry Schein

American Fork

Remote

USD 139,000 - 208,000

4 days ago
Be an early applicant

Principal Application Security Engineer

Henry Schein

Austin

Remote

USD 139,000 - 208,000

4 days ago
Be an early applicant

Principal Application Security Engineer

Henry Schein

Seattle

Remote

USD 139,000 - 208,000

4 days ago
Be an early applicant

Lead Application Security Engineer

Athenahealth India

Massachusetts

Remote

USD 90,000 - 150,000

14 days ago

Lead Product Security Engineer

DocuSign, Inc.

Seattle

Remote

USD 170,000 - 252,000

Today
Be an early applicant

Lead Product Security Engineer

DocuSign

Washington

Remote

USD 170,000 - 252,000

Yesterday
Be an early applicant

Principal Cloud Security Engineer

Cotiviti

Remote

USD 163,000 - 220,000

6 days ago
Be an early applicant

Senior/Lead Application Security Engineer

BioRender Inc

California

Remote

USD 90,000 - 150,000

10 days ago