Responsibilities:
Job Summary: As a Staff Application Security Engineer, you'll consult and collaborate with internal business team Partners and external vendors to collect requirements, build, and test specifications, and implement documented innovative technical solutions of security requirements. You'll also coach and mentor.
Location: Austin, Dallas or San Antonio, TX (Hybrid)
Key Responsibilities & Essential Functions:
-
Masters CI / CD pipelines; creates patterns of automation, infrastructure deployment, maintenance, monitoring, security, and compliance using industry and enterprise best practices
-
Collaborates with Digital Tech teams to design / develop / analyze / implement systems software and applications
-
Builds security standards for teams; integrates platform, including container and vulnerability management tools within CI / CD pipelines
-
Serves as SME for application security; provides guidance / coaches on industry best practices and defense in-depth strategies for security posture of cloud-based digital platforms
-
Collaborates with project teams on testing / evaluation of new solutions; tests cloud configurations and infrastructure for vulnerabilities
-
Ensures cloud infrastructure complies with security and compliance control requirements
-
Designs, develops, documents, automates, implements security infrastructure in code
-
Ensures concise documentation to formalize security processes and guardrails
-
Guides development teams to apply secure automation patterns / encourage secure software development lifecycle (SSDLC) best practices
-
Coaches / mentors team Partners
The responsibilities and essential functions outlined above describe the general nature and level of work assigned to this position. This is not an exhaustive list of all duties, responsibilities, and skills required. Duties and responsibilities may be modified at any time based on business needs. Employees may be required to perform other job-related tasks as requested by their supervisor, subject to reasonable accommodations.
Qualifications & Key Requirements:
Work Experience:
-
10+ years of experience developing / supporting system and security solutions in medium to large size enterprises
-
Experience building / integrating systems in cloud and on-premises environments using enterprise source code management tools and automation tooling.
-
Advanced working understanding of web applications, web servers, application firewalls, frameworks, and protocols related to web application development, deployment, and operation in the cloud
-
Working understanding of log analysis, application performance monitoring, API security, container security, AWS cloud security, Agile and other project management methodologies, PCI DSS, HIPAA regulations
-
Advanced skills in AWS, Azure, or Google Cloud Platform; Terraform, CloudFormation, Pulumi, or Ansible; Python, Golang, PowerShell, Java, or Shell script
-
Advanced skills in Linux-based and Windows Server operating systems management, secrets management, and vaulting technologies
-
Advanced skills using APIs to optimize tasks / achieve automation
-
Advanced skills in cloud resources: virtual networking, access controls (security groups, ACLs), service endpoints, application / network load balancing, API gateways, service principals, functions / serverless, storage buckets, containers, block storage, file shares
Education:
-
A Bachelor's degree or comparable formal training, certification, or work experience in Cyber Security or Application Security Engineering
Licenses/Certifications:
-
One more professional security certifications e.g CISSP, CISA, CEH, GIAC, cloud certifications from AWS, Azure, GCP.
Physical Demands & Working Conditions:
-
Function in a fast-paced, retail, office environment
-
Work extended hours / sit for extended periods
The work environment characteristics described here are representative of those a Partner encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
ISSEC3232
JDSECURITY
JDENGINEERING
DEV3232