Senior Application Security Engineer

Russell Tobin

New York (NY)

Hybrid

USD 96,000 - 103,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health coverage
Retirement 401(k)
Life & disability
Employee discounts

Job summary

PrideGlobal is seeking a security-focused software engineer to join the Cloud Security & Developer Enablement team in New York. The role focuses on architecting, engineering, deploying and operating security controls across enterprise applications.

You will implement policy in CI/CD tooling, collaborate with Development/DevOps/Security, and define code-level rules for multiple languages while ensuring scalable, secure platforms and robust compliance automation.

Qualifications

  • 5+ years of software development experience, Python-focused.
  • Experience with RESTful APIs and CI/CD pipelines.
  • Strong Linux and bash scripting skills; Windows scripting is a plus.
  • Identify and implement secure coding practices across services.

Responsibilities

  • Implement Brokerage security policies in CI/CD tools (SAST/OSS/SCA).
  • Collaborate with Development, DevOps, Security to automate security/compliance in DevSecOps.
  • Define code-level security rules for .NET, Java, React, Python apps.
  • Provide secure, stable platform for enforcing application security controls.
  • Support security architecture patterns for resiliency and scale.
  • Work with partners to integrate security tooling in GitHub repos to reduce vulnerabilities.

Skills

Python
REST APIs
Unit testing
Multithreading
Linux Bash
CI/CD Pipelines
Windows Scripting
Data processing

Education

Bachelor's degree in IT

Tools

Jenkins
GitHub Actions
TeamCity
Kubernetes
Docker
Puppet

Job description

Duration: 12 months contract with possibility of extension or C2H.

Location: New York, NY (Hybrid)

Pay rate range: $70 - $75/hr

Job Description:
About the Team:
  • The mission of the Cloud Security & Developer Enablement team is to implement the Firm's Cybersecurity Strategy by architecting, engineering, deploying and operating technical security controls and capabilities for the Enterprise. This is achieved by continued focus on architectural rigor, automation, agile delivery and adoption of Cloud and application security control implementations by development community.
What You'll Do:
  • Be part of a team of engineers to implement Brokerage specific security policies in the CI/CD security tools including but not limited to SAST, OSS and SCA applications.
  • Work with Development, DevOps and Security teams to identify and develop automated security and compliance capabilities in support of DevSecOps processes.
  • Define the security rules that needs to be adhered to at a code level in web and mobile applications written in .NET, Java, React, Python and other languages.
  • With your development background and security knowledge, provide secure stable platform for enforcing application security controls.
  • Support security standards, design & implement architectural patterns to increase the resiliency and scalability of security platform.
  • Work with our partners to implement, manage, and optimize security measures within our GitHub repositories to continuously improve code integrity and protect against vulnerabilities.
Required skillset:
  • Must have: 5+ years software development experience using Python
  • Working with APIs, including but not limited to ReST
  • Unit testing frameworks
  • Multi-process and multi-thread architecture
  • Must have: 5+ years in linux, strong bash scripting skills.
  • Deep understanding of CI CD pipelines
  • Working knowledge of windows environment, simple scripting dos-batch etc.
  • Bachelor's degree with 10+ years of work experience in the IT field
  • Ability to process large datasets for reporting and analysis.
Desired Skillset:
  • A self-starter, with a strong desire for learning new technologies and applying them to solve problems
  • Knowledge of SAST, OSS technologies
  • Ability to perform Python code reviews with minimal assistance
  • Expertise in monitoring, alerting, reporting, data analysis is desired.
  • Experience with application build environments like Jenkins, GitHub Actions, Teamcity etc.
  • DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc) is a plus
  • Experience with evaluation, integration and onboard of security tools such as DAST, RASP, WAF, vulnerability scanner results, container analyzers, open source scanning is a plus

PrideGlobal and it's affiliates offers eligible employee's comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance, critical illness insurance and hospital indemnity), 401(k)-retirement savings, life & disability insurance, an employee assistance program, legal support, pet insurance and employee discounts with preferred vendors.

PrideGlobal and it's affiliates are an equal opportunity employer. We do not discriminate on the basis of the race, religious creed, color, national origin, ancestry, physical disability, mental disability, reproductive health decision making, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other characteristic protected by applicable federal, state, or local law.

PrideGlobal and it's affiliates are a Fair Chance employer. We consider all qualified applicants, including those with criminal histories, in a manner consistent with applicable state and local Fair Chance laws and ordinances, including, the California Fair Chance Act and all applicable local Fair Chance ordinances.

Accommodations

We are committed to providing reasonable accommodations to applicants and employees with disabilities. If you require a reasonable accommodation to participate in the application or interview process, or to perform the essential functions of this role, please contact us.

Only applicable for San Francisco Candidates : Under the San Francisco Lactation in the Workplace Ordinance, we will provide written notice of lactation accommodation rights, and this notice will automatically be given upon hiring, any inquiry of parental leave or lactation accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Russell Tobin • New York (NY)

Hybrid
USD 96,000 - 103,000
Healthcare coverage
401k plan
Life & disability insurance
+1
Application Security Engineer
Application Security Engineer

Russell Tobin • Alpharetta (GA)

On-site
USD 96,000 - 103,000
Systems Engineer - III (Risk and Compliance)
Systems Engineer - III (Risk and Compliance)

Russell Tobin • Kirkland (WA)

Hybrid
USD 140,000 - 180,000
Staff Backend Engineer, Identity Threat Protection
Staff Backend Engineer, Identity Threat Protection

United States Digital Space LLC • San Francisco (CA)

On-site
USD 194,000 - 267,000
Equity
Bonus
Health, dental, and vision insurance
+3
Application Developer Security Analyst
Application Developer Security Analyst

Beacon Hill • Indianapolis (IN)

On-site
USD 120,000 - 170,000
Human Resources Operations Specialist
Human Resources Operations Specialist

Russell Tobin • West Palm Beach (FL)

On-site
USD 54,443,000 - 68,770,000
Healthcare coverage
401(k) retirement plan
Life & disability insurance
+1
Data Analyst
Data Analyst

Russell Tobin • Fremont (CA)

On-site
USD 130,183,000 - 137,760,000
Flexible hours
Staff TDI Site Reliability Engineer, Okta Federal
Staff TDI Site Reliability Engineer, Okta Federal

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 174,000 - 239,000
Technical Editor/Writer
Technical Editor/Writer

Russell Tobin • South Jordan (UT)

Hybrid
USD 52,000 - 76,000
Staff Site Reliability Engineer (FedRAMP)
Staff Site Reliability Engineer (FedRAMP)

United States Digital Space LLC • Washington

On-site
USD 174,000 - 239,000
Health insurance
Dental insurance
Vision insurance
+2