Senior AppSec Engineer: Secure SDLC & AI APIs

myhrhome

Irving (TX)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OneMain Holdings, Inc. is seeking an experienced Application Security Engineer to lead the implementation and continuous improvement of security tooling across software delivery.

You will work with engineering to embed secure-by-design practices and enforce secure SDLC governance. You will manage API security, SAST/DAST/IAST, and software supply chain security, and collaborate with stakeholders to raise security maturity and automate controls in pipelines.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 5+ years of application security engineering experience.
  • Experience implementing and administering application security platforms including SAST, DAST, SCA, IAST, container security, API security testing, and software supply chain security capabilities.
  • Experience securing APIs across the development lifecycle, including API discovery, authentication/authorization validation, schema testing, and remediation guidance.
  • Experience integrating security tooling and automated security controls into CI/CD pipelines using infrastructure-as-code (IAC).
  • Experience supporting secure SDLC governance, policy enforcement, compliance reporting, and remediation management.
  • Working knowledge of application security principles, secure coding, OWASP Top 10, and remediation techniques.
  • Experience developing and maintaining technical standards, procedures, policies, and security documentation.
  • Strong written and verbal communication skills with the ability to influence technical stakeholders.
  • Ability to independently manage moderately complex security initiatives and contribute to broader cybersecurity objectives.
  • Industry certifications such as CSSLP, GSEC, CISSP, GWAPT, or similar (preferred).
  • Experience supporting financial services or other highly regulated environments (preferred).
  • Experience assessing AI-assisted software development workflows, secure use of code-generation tools, guardrails, and risk monitoring (preferred).
  • Experience with security automation, scripting, and workflow orchestration (preferred).
  • Experience creating security metrics and dashboards (preferred).

Responsibilities

  • Implement, administer, and continuously improve application security tooling supporting secure software development.
  • Integrate security testing and security controls into software delivery pipelines and engineering workflows.
  • Develop, maintain, and enhance application security standards, policies, procedures, documentation, and operational guidance.
  • Analyze security findings, metrics, and compliance trends to identify improvements and elevated risk areas.
  • Partner with engineering teams to improve security adoption and enable secure-by-design development practices.
  • Support secure SDLC governance, vulnerability management, and remediation tracking activities.
  • Collaborate with cybersecurity, architecture, platform, and engineering stakeholders to improve application security maturity.
  • Contribute to security automation initiatives that increase efficiency and reduce manual effort.
  • Support secure implementation of emerging software development practices, including AI-assisted development workflows.

Skills

Application security engineering
SAST/DAST/IAST
API security testing
CI/CD security/IaC
Security standards & governance

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field

Tools

SAST tools
DAST tools
IAST tools
Container security tooling
API security testing tools

Job description

OneMain Holdings, Inc. is seeking an experienced Application Security Engineer to lead the implementation and continuous improvement of security tooling across software delivery.

You will work with engineering to embed secure-by-design practices and enforce secure SDLC governance. You will manage API security, SAST/DAST/IAST, and software supply chain security, and collaborate with stakeholders to raise security maturity and automate controls in pipelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer: Secure SDLC & API Defense
Senior Application Security Engineer: Secure SDLC & API Defense

Relha LLC • Irving (TX)

On-site
USD 120,000 - 180,000
Senior Engineer – Cybersecurity Application Security
Senior Engineer – Cybersecurity Application Security

Relha LLC • Irving (TX)

On-site
USD 120,000 - 180,000
Senior Engineer - Cybersecurity Application Security
Senior Engineer - Cybersecurity Application Security

myhrhome • Irving (TX)

On-site
USD 140,000 - 190,000
Senior App Security Engineer: Secure SDLC & AI Risk Lead
Senior App Security Engineer: Secure SDLC & AI Risk Lead

Clear Capital • Reno (NV)

On-site
USD 111,000 - 145,000
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Senior AppSec Engineer: AI-Driven Secure SDLC Lead
Senior AppSec Engineer: AI-Driven Secure SDLC Lead

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Application Security Engineer — Secure SDLC & AI
Senior Application Security Engineer — Secure SDLC & AI

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 145,000
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Application Security Engineer — SDLC & WAF/API
Senior Application Security Engineer — SDLC & WAF/API

Creative Solutions Services, LLC • Reston (VA)

Hybrid
USD 108,000 - 180,000
Senior AppSec Engineer: AI-Driven Secure Coding & CI/CD
Senior AppSec Engineer: AI-Driven Secure Coding & CI/CD

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Senior Application Security Engineer - Secure SDLC & CI/CD
Senior Application Security Engineer - Secure SDLC & CI/CD

Maisa • Spain (TX)

On-site
USD 100,000 - 130,000
Senior AppSec Engineer: Secure SDLC & Cloud Security (Hybrid)
Senior AppSec Engineer: Secure SDLC & Cloud Security (Hybrid)

Doist • New York (NY)

Hybrid
USD 150,000 - 200,000