Enable job alerts via email!

Senior Application Security Engineer

First American

Santa Ana (CA)

On-site

USD 146,000 - 183,000

Full time

9 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player seeks a Senior Application Security Engineer to enhance their security posture. This role involves developing and implementing a comprehensive application security strategy, conducting thorough security assessments, and integrating security best practices into the software development lifecycle. You'll collaborate with cross-functional teams and mentor junior members, all while ensuring compliance with industry standards. Join a company that values diversity and fosters an inclusive culture, where your expertise will make a significant impact on securing applications in a dynamic environment.

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401k Plan
Paid Time Off
Employee Stock Purchase Plan

Qualifications

  • 8-10 years of experience in application security, especially in fintech.
  • Proven track record of securing complex applications.

Responsibilities

  • Develop and maintain an application security strategy aligned with business goals.
  • Conduct security assessments and collaborate with development teams for remediation.

Skills

Application Security Principles
Secure Coding Practices
Risk Management
Analytical Skills
Communication Skills
Leadership
Collaboration

Education

Bachelor's or Master's degree in Computer Science

Tools

Veracode
Burp Suite
GitHub
Jenkins

Job description

Senior Application Security Engineer page is loaded

Senior Application Security Engineer
Apply locations USA, California, Santa Ana USA, Arizona, Remote USA, Washington, Remote USA, Idaho, Remote USA, Nevada, Remote time type Full time posted on Posted 9 Days Ago job requisition id R050147
Who We Are
Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For list for ten consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.
What We Do
Job Profile Summary
The Security Engineer is responsible for providing operational security solutions that would enable the success of IT and business initiatives. Security Engineer interfaces with IT Groups across the company, client managers, business customers, third-parties, vendors, and auditors. The Security Engineer co-designs (along with Security Architect) and operationalizes security solutions that can be effectively delegated to Security Analysts or other support/operations functions. The scope of Security Engineers extends across technical and administrative controls that enable the protection and availability of business and IT systems. The Security Architect is responsible for defining the organizations information security architecture and standards and creating prioritized risk based upon technical security control roadmap. The Security architect will coordinate technical design/review activities and develop secure architectural frameworks, operational guidelines and metrics to support a secure computing environment consistent with the organizations Information security policies, standard and overall strategy security risks for the company.

What You'll Do

  • Application Security Strategy: Develop, implement, and maintain a comprehensive application security strategy that aligns with the company's business goals and regulatory requirements, utilizing industry-leading tools.
  • Security Assessments: Conduct thorough security assessments, including static and dynamic application security testing (SAST/DAST), penetration testing, and code reviews using tools like Veracode and Burp Suite to identify vulnerabilities in our applications. Collaborate with development teams to remediate identified issues.
  • Risk Management: Proactively identify and assess security risks associated with applications and systems. Develop and implement risk mitigation strategies to address identified vulnerabilities, ensuring compliance with frameworks such as OWASP, NIST, and ISO 27001.
  • Secure Software Development Lifecycle (SDLC): Integrate security best practices into the software development lifecycle. Provide guidance and training to development teams on secure coding practices, security testing methodologies, and the use of development tools such as GitHub and Jenkins for continuous integration and deployment.
  • Incident Response: Lead and coordinate incident response efforts related to application security breaches. Conduct root cause analysis and implement corrective actions to prevent future incidents.
  • Security Tools and Technologies: Evaluate, implement, and manage security tools and technologies to enhance the security posture of our applications. Stay updated on the latest security trends, emerging threats, and advancements in security technologies.
  • Compliance: Ensure compliance with industry standards, regulatory requirements, and internal security policies, including PCI-DSS and SOC 2. Prepare and maintain documentation to support audits and assessments.
  • Collaboration: Work closely with cross-functional teams, including development, operations, and compliance, to ensure security requirements are integrated into all phases of the application lifecycle.
  • Mentorship: Provide mentorship and guidance to junior members of the security team. Foster a culture of security awareness and continuous improvement within the organization.

What You'll Bring

Required Education, Experience, Certification/Licensure

  • Education: Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • Experience: Minimum of 8-10 years of experience in application security or a related field, with a proven track record of securing complex applications in a fintech environment.
  • Certifications: Relevant certifications such as CISSP, CEH, OSCP, or CSSLP are highly desirable.
  • Technical Expertise: In-depth knowledge of application security principles, secure coding practices, and security testing methodologies, including proficiency with tools like Veracode, Burp Suite, and development environments like GitHub and Jenkins.
  • Analytical Skills: Strong analytical and problem-solving skills, with the ability to identify and mitigate security risks effectively.
  • Communication: Excellent verbal and written communication skills, with the ability to convey complex security concepts to both technical and non-technical stakeholders.
  • Leadership: Proven leadership experience, with the ability to lead and coordinate security initiatives across multiple teams.
  • Adaptability: Ability to adapt to a fast-paced and dynamic environment, with a strong focus on delivering results.
  • Collaboration: Strong interpersonal skills, with the ability to build effective working relationships with cross-functional teams.

Salary Range: $$146,200.00 - $182,700.00

This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location

What We Offer
By choice, we don’t simply accept individuality – we embrace it, we support it, and we thrive on it! Our People First Culture celebrates diversity, equity and inclusion not simply because it’s the right thing to do, but also because it’s the key to our success. We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work. First American is an equal opportunity employer in every sense of the term.

** Note that the following statements only apply to candidates who will be working from an unincorporated area within Los Angeles County. **

First American will consider for employment all qualified applicants, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws (e.g., the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act).

First American intends to conduct a review of an applicant’s criminal history in connection with a conditional offer. First American reasonably believes that a criminal history may have a direct, adverse and negative relationship with the following material job duties for this position potentially resulting in the withdrawal of the conditional offer of employment: handling of confidential, proprietary or trade secret information belonging to First American or its customers, administrating or facilitating financial transactions, and the ability to meet customer-imposed criminal history requirements.

Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.
Similar Jobs (2)
Senior Vulnerability Engineer
locations 6 Locations time type Full time posted on Posted 30+ Days Ago
Senior Security Engineer
locations USA, California, Santa Ana time type Full time posted on Posted 25 Days Ago

Our people are the foundation of First American’s success and that is the reason we put them first.

This philosophy has cultivated a culture of happy employees who are highly engaged, passionate about their work and leave each day feeling they have made a difference.

Privacy Policy

By submitting this application, you may convey certain personal information to First American. This information is collected for the sole purpose of determining your qualification for the position you are applying.

Notice Regarding LA County Fair Chance Ordinance
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Application Security Engineer (Remote US)

Experian

Costa Mesa

Remote

USD 90.000 - 150.000

3 days ago
Be an early applicant

Senior Application Security Engineer (Remote US)

Experian Health

Costa Mesa

Remote

USD 87.000 - 152.000

8 days ago

Sr. Application Security Engineer

Alteryx, Inc

Remote

USD 129.000 - 161.000

3 days ago
Be an early applicant

Senior Application Security Engineer

Experian Health

Costa Mesa

Remote

USD 87.000 - 152.000

23 days ago

Sr. Application Security Engineer

Prosper Marketplace

Remote

USD 100.000 - 150.000

2 days ago
Be an early applicant

Senior Application Security Engineer

First American Financial

Remote

USD 146.000 - 183.000

10 days ago

Senior Application Security Engineer

First American

California

On-site

USD 146.000 - 183.000

6 days ago
Be an early applicant

Senior Application Security Engineer

First American Financial Corp.

Santa Ana

On-site

USD 146.000 - 183.000

10 days ago

Senior Application Security Engineer Remote, US

GitLab Inc.

Remote

USD 124.000 - 217.000

22 days ago