Demo

Engineer, Application Security- (Open to remote)

Penguin Random House LLC
New York, NY Remote Full Time
POSTED ON 4/12/2025
AVAILABLE BEFORE 6/10/2025

Penguin Random House is seeking an Application Security Engineer to join the IT Security team.  This position will be responsible for advancing Secure Software Development Life Cycle (SDLC) practices and incorporating Application Security services and technologies to achieve a security-first design in all of Penguin Random House’s applications.  In addition, the individual will be expected to contribute to and help deliver services and projects across various aspects of information security.   

 

The individual will collaborate with developers and business stakeholders from relevant technical teams to evaluate the security architecture of new products and features through application security assessments.  They will prioritize and provide guidance on mitigating identified weaknesses and vulnerabilities while working with development teams to define and promote security best practices. 

 

The ideal candidate will have experience in at least one of the following areas: securing workflows in AWS and Azure, proficiency in SecDevOps and automation, familiarity with secure coding practices, or a background in application development with a desire to move into application security. In this role, you will establish cross-functional relationships with team members while being a trusted resource for Development. You will also maintain a hands-on role in implementing solutions and crafting specifications for those teams.   

 

Specific responsibilities include:

 

  • Develop and refine our core infrastructure architecture to minimize the vulnerability of essential services and reduce the impact of potential security exploits. 
  • Strategize and implement application security architectures that are in line with the company’s business objectives, ensuring adherence to privacy standards and compliance requirements. 
  • Utilize scripting languages (Python, Ruby, Bash, etc.) to build automation tools as needed. 
  • Create and deliver presentations and documentation to educate developers and operations teams on application security best practices and secure coding techniques.  
  • Identify and assess threats, vulnerabilities and potential exploits through architecture design reviews, threat modeling, code reviews, SCA/SAST/DAST assessments and collaborate with developers/engineers to remediate issues. 
  • Formulate and establish application security policies, standards and guidelines to support the secure development of products and services. 
  • Collaborate with the DevOps team to enhance Application Security, integrating security tools into the CI/CD pipeline, including container security, SCA/SAST, DAST, IAST, and third-party vulnerability Scanning. 
  • Partner with security stakeholders across the organization to assist delivery teams in conceptualizing and implementing security-focused projects and initiatives. 

  

Preferred qualifications include: 

 

  • Bachelor's degree in computer science or a related field, supplemented by a minimum of five years of professional experience encompassing a robust technical understanding and practical involvement in secure software development, security engineering, DevOps, application penetration testing, and/or negative QA testing. 
  •  Proficient in effective communication, interpersonal relations, and organizational management. 
  • Experience with application security tools such as SCA, SAST, DAST, Penetration testing, and Fuzzing. 
  • Comprehensive knowledge of prevalent software and web application security vulnerabilities, including OWASP Top 10 and SANS/CWE Top 25. 
  •  Expertise in conducting security assessments for web and mobile applications based on OWASP ASVS/M-ASVS and other testing guidelines. 
  • DevOps experience with building and deploying applications/infrastructure with the following technologies:  GitLab/GitHub, Ansible, Jenkins, etc. Advanced understanding and experience with web architectures, web applications, APIs, mobile applications, desktop applications, Unified Communications (including VoIP and SMS), and the underlying technology of cloud infrastructure. 
  • Experience securing DevOps, including continuous integration, configuration management, and continuous deployment. 
  •  Demonstrated ability in leading code reviews, executing threat modeling, and conducting penetration tests. 
  • Industry-recognized certification in security is a plus (e.g., CISSP, CISA, CISM, CRISC, CEH, etc.) 
  • Bilingual in Spanish preferred. 

 

 This position is open to remote candidates.     

 

The salary range for this position is $100,000 - $135,000. All positions are currently eligible for annual profit award or bonus, subject to Company results.   

 

Please apply by April 4th using our online application process, and please include your resume, cover letter, and salary requirements.  

 

Salary : $100,000 - $135,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Engineer, Application Security- (Open to remote)?

Sign up to receive alerts about other jobs on the Engineer, Application Security- (Open to remote) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$92,369 - $122,605
Income Estimation: 
$117,024 - $149,811
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$117,024 - $149,811
Income Estimation: 
$137,568 - $176,908
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Penguin Random House LLC

Penguin Random House LLC
Hired Organization Address New York, NY Full Time
Manager, Internal Communications, Corporate Communications, Penguin Random House (Hybrid) Penguin Random House, the home...
Penguin Random House LLC
Hired Organization Address New York, NY Full Time
Random House Children’s Books has an opportunity for a senior level editor to manage approximately 35 titles per year in...
Penguin Random House LLC
Hired Organization Address New York, NY Full Time
Are you a lover of great books and fantastic fan merchandise? Are you a highly organized and adaptable individual who wa...
Penguin Random House LLC
Hired Organization Address New York, NY Full Time
The marketing team at Ballantine Bantam Dell is seeking an experienced, creative, detail-oriented and strategic marketer...

Not the job you're looking for? Here are some other Engineer, Application Security- (Open to remote) jobs in the New York, NY area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!