What are the responsibilities and job description for the Senior Application Security Engineer position at BAMM USA?
s a Senior Application Security Engineer, you will work to support the various processes and procedures related to application security and gather information from product engineering teams related to these activities. You will make a difference in promoting a culture of security inside the engineering organization and work with engineers to produce more secure applications. You will work to both collect and disseminate information throughout the business to ensure processes and procedures are operating efficiently and effectively. You will support the developers in their efforts to secure our applications and assist in the documentation and tracking of various application security and cloud.
What You Will Do
- Collaborate with engineers, consultants, and leadership to address security risks and provide mitigation recommendations within the Secure Development Lifecycle (SDLC)
- Build automated code scanning tools to identify security vulnerabilities in application code and infrastructure code using both open source and commercial tools Integrating open-source and / or commercial static application code scanning tools with the CI / CD Pipeline
- Enable secure-by-default best practices by developing libraries and frameworks to prevent future vulnerabilities
- Operate at enterprise scale by building and managing tools that help test, monitor, and improve application security
- Develop security standards, preferred implementation patterns, secure common frameworks, and developer documentation and educational materials
- Provide secure developer training to software engineers on how to write secure code and follow best practices
- Conduct web app penetration testing, code scanning, dependency scanning that can be incorporated into SDLC process and CI / CD pipeline
- Work closely and together with the development team to provide guidance and mitigate security vulnerabilities
- Perform security architecture and design reviews of all systems and applications.
- Provide a leadership role in the development, implementation and maintenance of consistent application and infrastructure architecture security programs
Qualifications
Benefits / Compensation