Demo

Application Security Engineer

Pearson
Raleigh, NC Full Time
POSTED ON 2/17/2025
AVAILABLE BEFORE 5/14/2025

Application Security Engineer Position

Pearson is a Global organization that does business in nearly every country; the majority of our systems are cloud based, using modern infrastructure and development practices. Pearson services a number of federal and highly sensitive workloads, ensuring security is routinely prioritized.

While we have a global reach, impacting the lives and work of many, we are a close-knit and passionate team of engineers with expertise ranging across the board in the realm of Cybersecurity. Here, you will always be a stone's throw away from exciting projects with many opportunities for growth and developing knowledge in cutting-edge technologies.

As an Application Security Engineer, you will be responsible for ensuring the holistic security of various applications and services used throughout the organization. You will be working with various application teams throughout the organization to ensure security best practices are adopted and implanted throughout the SDLC. You will work to identify, track, and advise the application teams to remediate vulnerabilities and the associated risks. Vulnerailities may come from various tools and testing done by yourself or other internal or third-party penetration testers.

The primary job responsibilities include :

Engagement with internal and external partner teams

Collaborate with product and platform teams on security controls

Plan, implement, upgrade, and monitor security measures related to application security

Collaborate with functional area architects, engineers, and security specialists across Pearson to implement suitable security solutions and controls.

Provide security expertise and assist project teams in adhering to enterprise and IT security policies, industry regulations, and best practices

Evaluate Pearson's current security and future architecture, offering solutions to address any gaps.

Assess and understand the current and planned security posture for platforms, provide recommendations for improvements and risk reduction

Develop security configuration standards, procedures, and guidelines for various platforms, including baseline security configurations and hardening guides.

Communicate security risks and solutions to business partners and IT staff

Coach developers on application security

Implement industry-leading security engineering practices across the organization.

Escalate and document risks when observed

  • Secure DevOps / Secure SDLC

Perform threat modeling

Perform thorough security reviews of software applications.

Identify and propose process improvements and identify opportunities for new processes and procedures to reduce risk

  • Tuning of Security Prevention Tools
  • Assist with configuring Web Application Firewalls (WAF)

    Assist with the tuning of Runtime Application Self Protection (RASP) tools

  • Incident Response
  • Assist in security incident response efforts as necessary

    Aid teams in implementing appropriate logging practices

    Collaborate with security operations teams to develop detection capabilities

  • Research
  • Conduct research, design, and advocate for new technologies and security products that fulfill the security requirements of the enterprise, as well as those of its customers, business partners, and vendors.

    Contribute to the development and maintenance of the information security strategy

  • Security Tooling
  • Administer, configure, and support security tools

    Assist with adoption of new / existing security tools as needed

    Create / support integrations of security tools into central analytics system

    Embrace a culture of continuous service improvement and service excellence

    Stay up to date on security industry trends

    Essential Skills :

    Bachelor's degree in Computer Science, MIS, or equivalent technology discipline

    Working knowledge of application development tools, techniques, and platform technologies

    Familiar with Continuous Integration / Continuous Deployment (CI / CD) processes and concepts

    Familiar with REST API technology and methods

    Ability to develop scripts in Python (or comparable language)

    Experience in OOAD, agile processes, design patterns

    Threat modeling experience

    Proficient in OWASP top 10 Vulnerabilities, Secure Coding Practices and Security Controls

    Familiarity with SCA (Software Composition Analysis) techniques and working with application teams to remediate such vulnerabilities

    Managing technical security debt

    Desirable Skills :

    3 years minimum software development required (Java or .NET), application security experience, or pen testing

    Experience working in an agile environment

    Experience with automation

    Familiarity with government attestations, including FedRAMP and StateRAMP

    Experience with relational database platforms such as MSSQL, MySQL, and NoSQL databases.

    Understanding of incident response methods and technologies

    Implemented security controls in a global enterprise IT environment

    Drive a culture of security awareness

    Experience in creating design documents, performing code reviews

    Desire to expand knowledge in many development languages, applications, and tools

    Proven ability to quickly learn new processes and tools, business domains and technical applications

    Ability to think technically and analytically

    Ability to assimilate information, distill knowledge, apply experience and provide solution alternatives and recommendations

    Must be a self-starter and detail-oriented

    Must have a “positive” and energetic demeanor

    Effective written and verbal communication skills

    Creative problem-solving skills

    Experience in containerized and serverless environments

    Who we are :

    At Pearson, our purpose is simple : to help people realize the life they imagine through learning. We believe that every learning opportunity is a chance for a personal breakthrough. We are the world's lifelong learning company. For us, learning isn't just what we do. It's who we are. To learn more : We are Pearson.

    Pearson is an Affirmative Action and Equal Opportunity Employer and a member of E-Verify. We want a team that represents a variety of backgrounds, perspectives and skills. The more inclusive we are, the better our work will be. All employment decisions are based on qualifications, merit and business need. All qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We strive for a workforce that reflects the diversity of our communities.

    If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing TalentExperienceGlobalTeam@grp.pearson.com.

    Note that the information you provide will stay confidential and will be stored securely. It will not be seen by those involved in making decisions as part of the recruitment process.

    Job : ENGINEERING

    Organization : Corporate Strategy & Technology

    Schedule : FULL_TIME

    Workplace Type : Req ID : 18391

    location

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Application Security Engineer?

    Sign up to receive alerts about other jobs on the Application Security Engineer career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $88,984 - $115,784
    Income Estimation: 
    $111,369 - $141,168
    Income Estimation: 
    $117,871 - $153,580
    Income Estimation: 
    $109,939 - $144,341
    Income Estimation: 
    $114,500 - $144,633
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $91,486 - $118,193
    Income Estimation: 
    $111,369 - $141,168
    Income Estimation: 
    $117,871 - $153,580
    Income Estimation: 
    $109,939 - $144,341
    Income Estimation: 
    $114,500 - $144,633
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $68,659 - $89,193
    Income Estimation: 
    $88,984 - $115,784
    Income Estimation: 
    $92,017 - $124,111
    Income Estimation: 
    $90,707 - $120,959
    Income Estimation: 
    $91,486 - $118,193
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Pearson

    Pearson
    Hired Organization Address Bismarck, ND Full Time
    Our Organization At Pearson, we are committed to a world that’s always learning and to our talented team who makes it al...
    Pearson
    Hired Organization Address Helena, MT Full Time
    Our Organization At Pearson, we are committed to a world that’s always learning and to our talented team who makes it al...
    Pearson
    Hired Organization Address Boise, ID Full Time
    Pearson’s PRoPL interim assessment is intended to represent individual state academic standards with rigorous content, m...
    Pearson
    Hired Organization Address Boise, ID Full Time
    Pearson VUE (www.pearsonvue.com) is the global leader in computer-based testing for information technology, academic, go...

    Not the job you're looking for? Here are some other Application Security Engineer jobs in the Raleigh, NC area that may be a better fit.

    Senior Application Security Engineer

    ServiceNow, Raleigh, NC

    Application security

    Futran Tech Solutions Pvt. Ltd., Raleigh, NC

    AI Assistant is available now!

    Feel free to start your new journey!