Sr Security Engineer

H&R Block, Inc.

Northern (KY)

Hybrid

USD 140,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

H&R Block, Inc. is seeking a Senior Application Security Engineer to ensure the security of products throughout their lifecycle. You will consult with security stakeholders and guide secure design and development, with emphasis on threat modelling and secure DevOps practices.

Responsibilities include threat modelling, code reviews, SAST/DAST, and automation to embed security in the CI/CD pipeline. You will mentor teams and promote security awareness across engineering and product functions.

Qualifications

  • 5+ years of experience in an application security role.
  • Experience leading architectural changes or cross-team efforts to mitigate security vulnerabilities.
  • Familiarity with threat modelling methodologies and security standards.

Responsibilities

  • Perform threat modelling and vulnerability assessments to identify risks in product design.
  • Implement security tooling and automate SDLC security practices across pipelines.
  • Conduct code reviews, SAST/DAST, and IaC scanning to ensure security controls are in place.
  • Mentor product, engineering, and IT teams on security best practices.

Skills

Application security
Threat modelling
CI/CD security
Python
Security tooling
Code reviews

Education

Bachelor's degree in Computer Science or Cybersecurity

Tools

AWS
Azure
SAST/DAST tools
Terraform
Ansible

Job description

What you'll do...

The Senior Application Security Engineer is responsible for ensuring the security of an organization's products throughout their lifecycle. This role also consults with security adjacent stakeholders and business units to provide suggestions, education, guidance and feedback from a security perspective.

  • Risk Assessment and Mitigation: Perform threat modelling application design solutions and vulnerability assessments to identify relevant risks, security gaps or risks in product design and development.
  • Secure Development Practices: Implement security tooling and automation to scale the Application Security team's practices. Advocate for and integrate security best practices in the Software Development Lifecycle (SDLC). Conduct code reviews, penetration testing, and static/dynamic analysis. Ensure compliance with industry standards (e.g., AICPA SOC2, HIPAA, PCI DSS, SOX ISO 27001, NIST CSF).
  • Security Architecture and Development: Working with product and engineering teams to design, program development, software development and implement security controls and protections within the product via automation. This task ensures the product is built with security in mind from the ground up. Integrate security tools and technologies into the CI/CD pipeline (e.g., static and dynamic application security testing (SAST/DAST), software composition analysis (SCA), and infrastructure-as-code (IaC) scanning).
  • Planning, Collaboration and Training: Product roadmap planning with key stakeholders, collaboration with cross functional teams to develop mitigation strategies. Working closely and mentor Product, Engineering, and IT teams for security best practices. Provide security training and awareness for developers and stakeholders.

Compliance and Reporting: Maintain documentation of security controls and processes. Prepare reports on security risks and mitigation efforts for management and regulatory bodies. Audit source code and perform code review for critical application changes

What you'll bring to the team...
  • 5+ years of experience in an application security role.
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field.
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities.
  • Strong understanding of:
    • Threat modelling methodologies such as MITRE ATT&CK, STRIDE, and PASTA;
    • Amazon AWS Services, MS Azure and their capabilities;
    • Securing web applications;
    • Orchestration tools (ex. Anisible, Terraform).
  • Experience with frameworks such as OWASP Top 10, SAST/DAST tools, and CI/CD pipelines.
  • Fluency in Python, React, and Django Rest Framework.
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline.
  • Experience with securing software development lifecycle including building programs. that eliminate full classes of vulnerabilities.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and within a team.
  • Strong organizational and time-management abilities.
It would be even better if you also had...
  • Certifications such as CISSP, CSSLP, CEH, or equivalent.
  • Experience in IoT, embedded systems, or mobile app security.
  • Knowledge of regulatory and compliance standards (e.g., AICPA SOC2, NIST CSF, GDPR, HIPAA)
Why work for us

Equal Opportunity Employer: H&R Block does not tolerate discrimination based on a person's race, color, religion, ancestry, age, sex/gender (including pregnancy, childbirth, related medical conditions and sex-based stereotypes and transgender status), sexual orientation, gender identity or expression, service in the Armed Forces, national origin, physical or mental disability, genetic information, citizenship status or any other status protected by law.

Follow our LinkedIn page for latest updates/news: https://www.linkedin.com/company/hrb-india/

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Software Security Engineer
Software Security Engineer

Axway • Indiana (PA)

On-site
USD 9,000 - 16,000
Health coverage
Retirement plans
Paid time off
+4
Senior Security Engineer
Senior Security Engineer

Thomson Reuters • Frisco (TX)

On-site
USD 140,000 - 210,000
Hybrid Work
Flexible policies
Career growth
+2
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc • Dallas (TX)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Hitachi Digital Services, LLC • Addison (TX)

Hybrid
USD 150,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Texas City (TX)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1