As a Senior Security Engineer focused on Application Security, you will play a central role in safeguarding software products by integrating security deeply into the development lifecycle. Your work will center on identifying, analyzing, and resolving vulnerabilities before they reach production, ensuring systems are built with resilience from the start.
Key Responsibilities
- Establish and support a security-focused engineering culture by guiding cross-functional teams in secure development practices.
- Integrate security controls early in design and coding phases to proactively address risks and reduce remediation costs.
- Conduct in-depth technical evaluations of code, features, and infrastructure to verify alignment with security standards.
- Respond to customer inquiries regarding product security and validate reported vulnerabilities for accurate triage.
- Advance software supply chain protection through automation, compliance validation, and control testing.
- Coordinate internal and external penetration testing efforts to uncover and resolve security weaknesses.
- Support compliance initiatives by gathering and organizing evidence for security audits.
- Manage and improve tools for scanning code and third-party software components to maintain their accuracy and efficiency.
Qualifications
Candidates should hold a bachelor’s degree in Computer Science, Cybersecurity, or a related field, or demonstrate equivalent experience. A minimum of five years in software or security engineering is required.
Strong communication skills are essential, particularly when explaining technical risks to both engineers and external stakeholders. Experience with cloud platforms such as Azure or AWS, container technologies, and industry-standard security frameworks is expected. Familiarity with secure coding practices across the software development lifecycle is critical.
Preferred qualifications include experience in SaaS environments at scale, knowledge of legal technology or e-discovery workflows, proficiency in an object-oriented language like .NET, and a solid understanding of SDLC best practices including code reviews, source control, and testing methodologies.