Sr. Software Engineer (Security Specialist)

BAMM

United States

Remote

USD 140,000 - 200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote work
Competitive salary

Job summary

BAMM is seeking a Sr. Software Engineer to advance its software security practice. The role focuses on analyzing vulnerabilities in Java and JavaScript applications and guiding remediation across code, libraries and dependencies.

You will lead secure coding reviews, design security improvements, and collaborate with engineering teams to mature the security program. This is a remote EST-hours position with a strong emphasis on collaboration and impact.

Qualifications

  • Bachelor's degree required in CS or CE, with AWS and security certs preferred.
  • Experience in software security testing and Software Composition Analysis (SCA).
  • Ability to communicate security risks to developers and stakeholders clearly.

Responsibilities

  • Set up and operate software security testing techniques per reference architecture and policies.
  • Analyze open-source threats and vulnerabilities and assess impact on code, libraries and dependencies.
  • Identify and prioritize high-risk components, considering exploitability and exposure.

Skills

JavaScript
Java
Python
Software security
SCA

Education

Bachelor's degree in Computer Science or Computer Engineering

Tools

Sonatype
Qualys
SonarQube
AWS Inspector
GitHub
AWS ECS/EKS
AWS Lambda
Docker
Terraform

Job description

REMOTE: EST HOURS

We are seeking a Sr. Software Engineer to join our progressive information technology Software and Platform Engineering optimization team to help us mature our software security practice. This highly skilled and experienced Application Security Engineer/Specialist will bring hands-on expertise in analyzing risk from vulnerabilities and assessing their impact on custom applications and open-source libraries. The ideal candidate will have a deep understanding of open-source vulnerability remediation, along with practical experience in remediation for Java and JavaScript software. The candidate should also understand risk mitigation techniques to ensure the security of software applications.

Essential Duties and Responsibilities:
  • Set up and operate software security testing techniques in conformity with the technical reference architecture and the companies security policies and guidelines
  • Conduct in-depth analysis of open-source threats and vulnerabilities (including zero-day), collaborate with engineering teams to evaluate and assess the impact of vulnerabilities on current code, including libraries, frameworks, and dependencies.
  • Identify and prioritize high-risk open-source components within our codebase, considering factors such as exploitability, severity, and exposure.
  • Develop and implement remediation and risk mitigation plans to address identified vulnerabilities
  • Coaching and hands on experience for code refactoring, patching, and dependency updates.
  • Identify and recommend engineering design changes to help reduce vulnerabilities.
  • Champion and evangelize secure coding practices with the engineering community.
  • Develop and lead security reviews and drive innovative security remediation efforts.
  • Provide technical designs for innovative software solutions to address security risks.
  • Coaching and assisting in administration and configuring of security tools, documenting secure configurations.
  • Serve as an Application security consultant and advisor for software engineering teams in assisting with secure coding best practices, threat detection, Software security vulnerabilities, security reviews, remediation recommendations throughout the delivery lifecycle.
  • Building relationships and developing partnerships with engineering/development, security operations, enterprise and application architecture teams to mature Security Coding practices for the company owned applications and platforms.
  • Stay informed about emerging threats and vulnerabilities in the open-source community, understanding impact of attacks, controls and mitigation measures in the application security space.
  • Communicate project related security risks, control and remediation measures accurately and in a timely manner to stakeholders and impacted teams.
  • Integrate and adhere with the defined development and delivery process/ Change Management, SLA Compliance, productivity and other enterprise goals.
  • Serve as a thought leader, change agent and influencer within the enterprise providing feedback to leadership, engineering, architecture and security operation team members.
Desired Competencies:
  • Strong spoken and written communication skills
  • Analytical and Problem-solving mindset
  • Developer background with experience in all types of application security testing specific to Software composition Analysis.
  • Good understanding of web application security, static security testing, cloud security, container security - tools, scan, triage, risk evaluation and remediation.
  • Thorough understanding and experience in identifying and mitigating application vulnerabilities publicized by OWASP, WASC, CWE, CVE etc.
  • Strong knowledge on industry best practices, code review and analysis
  • Proficient with source code security review and remediation.
  • Experience working with application development teams, architecture teams, security teams, and infrastructure teams.
  • Has advised and guided teams with secure coding practices and design best practices for security risk recommendation and remediation.
  • Thorough familiarity with different industry standard tools for code repository management, code quality, DevOps, containers, and AWS cloud services.
  • Hands on experience with tools such as Sonatype, Qualys, SonarQube, and AWS Inspector.
  • Proficient with the following languages: JavaScript, Java, and Python
  • Working knowledge of GitHub, AWS ECS/EKS, AWS Lambda, Docker, Terraform.
Essential Soft Skills
  • Interested in learning and applying new technologies and concepts while staying up to date with technology tools and trends in the industry.
  • Possess a positive, can-do attitude and enjoys making a difference in the business through technical contributions
  • Ability to think creatively, stimulate new ideas and challenge existing thinking.
  • Excellent communication skills and ability to articulate technology topics to both technical and non-technical audiences
  • Mortgage Industry Experience would be a plus
Educational Requirements:
  • Position requires a bachelor’s degree in computer science or computer engineering with AWS certifications and security certifications and/or equivalent experience.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • West Palm Beach (FL)

On-site
USD 120,000 - 170,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Texas City (TX)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Jacksonville (FL)

On-site
USD 110,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Miami (FL)

On-site
USD 120,000 - 180,000
Professional growth
Competitive compensation
Fortune 500 projects
+1
Software Development Engineer, Amazon Integrated Security
Software Development Engineer, Amazon Integrated Security

Amazon • Seattle (WA)

On-site
USD 144,000 - 194,000