Security Engineer

Wall Street Consulting Services LLC

New York (NY)

On-site

USD 140,000 - 190,000

Full time

2 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Wall Street Consulting Services LLC is seeking a Security Engineer to help develop, mature, and sustain the Application Security program. You will work with the Information Security team to advance security across Web, Mobile, Databases, APIs, and Containerized environments, driving secure development practices and measurable improvements.

You will collaborate with development teams to assess scans, implement mitigations, and mentor engineers on secure coding.

Qualifications

  • 5+ years of application security experience.
  • 5+ years of experience performing manual testing of APIs and web applications to identify/validate vulnerabilities.
  • 5+ years of experience developing and maintaining enterprise security libraries, components, best practices checklists.
  • 5+ years of experience performing application security risk evaluation with stakeholders to improve CI/CD security.
  • 5+ years of experience creating and maintaining scan profiles for static, dynamic, IAST, and third-party library analysis.
  • 5+ years of experience reviewing vulnerability scan results and tracking closure.

Responsibilities

  • Perform as an application security SME in Web Apps, Mobile Apps, Databases, APIs, Containers and other domains.
  • Support and maintain application security testing platforms and develop integrations with automation platforms
  • Work with Application Development teams to review potential false-positive scan results and evaluate proposed mitigating factors
  • Produce and track application security metrics
  • Support the secure development and testing of critical Advisor and Investor Client applications
  • Mentor and educate product development and quality engineers on secure development and security best practices
  • Monitor and review CVEs, industry developments, and provide inputs for continuous improvement
  • Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects

Skills

Application Security
API Security
Web Security
Vulnerability Testing
CI/CD Security
Threat Modeling

Education

Bachelor’s Degree or equivalent in Information Security, Engineering or Computer Science

Tools

Synopsys
BlackDuck
J-Frog
PrismaCloud
API scanners
Burpsuite
Postman

Job description

As a member of the Information Security team, the Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the company. Application Security is a top area of focus at Client . We have incorporated key industry security best practices, technologies and integrated processes to further strengthen our defense posture. This is an exciting time to join the Information Security Vulnerability Management team as we are continuing to expand the Application Security program.

Responsibilities
  • Perform as an application security SME in the following areas: Web Applications, Mobile Applications, Databases, APIs, Containers and other domains.
  • Support and maintain application security testing platforms and develop integrations with automation platforms
  • Work with Application Development teams to review potential false-positive scan results and evaluate proposed mitigating factors
  • Produce and track application security metrics
  • Support the secure development and testing of critical Advisor and Investor Client applications
  • Mentor and educate product development and quality engineers on secure development and security best practices
  • Monitor and review CVEs, industry developments, and provide inputs for continuous improvement
  • Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects
Requirements
  • 5+ years of application security experience
  • 5+ years of experience performing manual testing of APIs and web applications to identify/validate vulnerabilities.
  • 5+ years of experience developing and maintaining enterprise security libraries, components, best practices checklists.
  • 5+ years of experience performing application security risk evaluation, partnering with key stakeholders to further enhance application security CI/CD pipeline and continually assess security posture for improvement.
  • 5+ years of experience creating and maintaining scan profiles for performing static, authenticated dynamic, IAST, and 3rd party library automated analysis with application scanning tools
  • 5+ years of experience with reviewing and analyzing vulnerability scan results and tracking closure of vulnerabilities
Core Competencies
  • Understanding of OWASP Top 10 Critical Web Application Security Risks, their identification, and architecture, design, coding patterns to mitigate them
  • Knowledge of secure coding best practices, secure SDLC, secure architecture, and DevSecOps methodologies
  • Strong analytical, interpersonal and communication skills
Preferences
  • Bachelor’s Degree or equivalent in Information Security, Engineering or Computer Science.
  • Application development and Security Engineering or Security Architecture experience
  • Experience using Application Security Code Scanning Tools such as Synopsys, BlackDuck, J-Frog, PrismaCloud, API scanners as well as manual tools such as Burpsuite and Postman
  • Experience working with security of applications developed in C#, Java, and web (HTML, CSS, JS, React, Angular, REST) technologies
  • Experience working with DevSecOps and CI/CD pipelines
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Senior Application Security Engineer
Senior Application Security Engineer

Interactive Resources - iR • Jacksonville (FL)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Application Security Engineer ( Only USC Or GC)
Application Security Engineer ( Only USC Or GC)

LinQ Global Group • Philadelphia

Hybrid
USD 110,000 - 160,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • San Francisco (CA)

On-site
USD 120,000 - 160,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Cherry Hills Village (CO)

On-site
USD 80,000 - 110,000
Application Security Engineer
Application Security Engineer

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Montvale (NJ)

On-site
USD 80,000 - 110,000