Position: Senior Security Engineer - Application Security
Location: New York City, NY (HYBRID: 4 days a week in office)
Duration: DIRECT HIRE – FULL TIME
Summary:
We are seeking an experienced Application Security professional to protect applications, cloud infrastructure, systems, and customer data. As part of a lean security team, this individual will contribute across application security, cloud security, security operations, IT security, and compliance while helping design and implement new security solutions.
Skills/Experience Needed:
- 4+ years of experience in application, product, or software security, or software engineering experience followed by a transition into security.
- Strong understanding of application security vulnerabilities and attack techniques, including the OWASP Top 10 and API security risks.
- Experience manually testing modern web applications, APIs, and distributed systems.
- Ability to assess application architecture and source code for security weaknesses.
- Experience integrating application security tools into modern CI/CD workflows.
- Familiarity with SAST, DAST, secrets detection, container security, dependency scanning, and Infrastructure-as-Code scanning.
- Understanding of authentication, authorization, session management, cryptography, secrets management, and secure API design.
- Strong cloud security experience with AWS, Google Cloud Platform, or Azure.
- Proficiency with modern programming languages and familiarity with generative coding tools and their security implications.
- Experience researching, establishing, and implementing enterprise-wide security policies and guidelines
Responsibilities:
- Develop and implement application security controls throughout the Software Development Lifecycle (SDLC).
- Partner with engineering teams to incorporate security into architecture, design, development, testing, and deployment.
- Perform hands-on security testing of web applications, APIs, cloud-native services, and supporting infrastructure.
- Build and improve automated security testing within CI/CD pipelines, including static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing.
- Evaluate application security tools, improve the quality of results, reduce false positives, and minimize developer friction.
- Review application architecture and source code for security weaknesses.
- Develop secure coding standards and developer-focused documentation.
- Support vulnerability management, security investigations, incident response, and post-incident reviews.
- Evaluate third-party applications, libraries, APIs, and integrations for security risks.
- Ensure compliance with applicable healthcare and data-protection requirements, including HIPAA and GDPR.