What are the responsibilities and job description for the Lead Application Security Engineer position at Stride?
Job Description
SUMMARY : As an Application Security Engineer, it is your responsibility to ensure that the applications and software systems within your organization are secure and trustworthy. You will collaborate closely with software developers, DevOps teams, and other stakeholders to identify potential security weaknesses and implement measures to prevent them. Your role involves designing, deploying, and maintaining secure cloud applications that meet business requirements. This is an advanced position that requires you to deliver applications at scale with resilience to support business objectives. To succeed in this role, you must be proficient in managing multiple applications and data systems to maintain the required level of rigor to comply with business objectives. Additionally, you must plan and design policies and maintain them. You will work closely with security leadership to continuously assess the threat landscape and adapt quickly to safeguard the organization against risk.
ESSENTIAL FUNCTIONS : Reasonable accommodations may be made to enable individuals with disabilities to perform the essential duties.
- Conduct security testing, including code reviews, penetration testing, and vulnerability assessments to identify potential weaknesses in applications. You will use various tools and methodologies to detect and analyze security issues.
- Analyze application source code to identify security flaws, adherence to security best practices, and potential areas of improvement. You'll work with developers to help them understand and address security concerns in their code.
- Review the application architecture and design to ensure security considerations are adequately incorporated at every stage of development.
- Develop and maintain security tools, scripts, and automation to streamline security testing processes and integrate security into the development lifecycle.
- Protect business applications in compliance with privacy, security, business resiliency and compliance frameworks as defined in corporate policies.
- Attend regular technical project and implementation meetings and serve as the security consultant to help guide secure application and infrastructure configurations.
- Perform threat modeling exercises to identify potential security threats and risks in applications and provide recommendations to mitigate them.
- Manage remediation efforts after security assessment findings outline weaknesses requiring attention.
- Document, formulate and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation.
- Assist in the investigation and resolution of application security incidents. Collaborate with incident response teams to contain and mitigate security breaches.
- Assist with development, maintenance and utilization of scripts (e.g., Python, JavaScript, etc);
- Stay apprised of current and proposed security changes impacting regulatory, privacy and security industry best practice guidance. Apply learned knowledge across key lines of business, including products, practices and procedures.
- Integrate security into the software development life cycle by providing guidance and expertise throughout all phases of development.
- Attend and fully engage in change and project management meetings.
Supervisory Responsibilities : This position has no formal supervisory responsibilities.
MINIMUM REQUIRED QUALIFICATIONS :
Certificates and Licenses : One or more including CISSP, CEH, OSCP, or CSSLP, AWS Certified Security - Specialty, Certified Application Security Engineer (CASE)
OTHER REQUIRED QUALIFICATIONS :
WORK ENVIRONMENT : The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
This position is virtual and open to residents of the 50 states and Washington, D.C.
Compensation & Benefits : Stride, Inc. considers a person's education, experience, and qualifications, as well as the position's work location, expected quality and quantity of work, required travel (if any), external market and internal value when determining a new employee's salary level. Salaries will differ based on these factors, the position's level and expected contribution, and the employee's benefits elections. Offers will typically be in the bottom half of the range.
The above job is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow any other instructions, and perform any other related duties, as assigned by their supervisor. All employment is "at-will" as governed by the law of the state where the employee works. It is further understood that the "at-will" nature of employment is one aspect of employment that cannot be changed except in writing and signed by an authorized officer.
Job Type
Regular
The above job is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow any other instructions, and perform any other related duties, as assigned by their supervisor. All employment is "at-will" as governed by the law of the state where the employee works. It is further understood that the "at-will" nature of employment is one aspect of employment that cannot be changed except in writing and signed by an authorized officer.
Stride, Inc. is a Federal Contractor, an Equal Opportunity / Affirmative Action Employer and a Drug-Free Workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected Veteran status age, or genetics, or any other characteristic protected by law.
Equal Opportunity Employer / Protected Veterans / Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
Salary : $81,046 - $201,089