This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Under minimal supervision, the Senior Application Security Engineer plays a critical role in establishing and maturing Discount Tire’s enterprise application security program. Partners closely with our Enterprise Cybersecurity, Cloud Security, and Software Engineering teams to ensure that applications, APIs, and underlying infrastructure are securely designed, built, and operated. Drives security enablement across the software development lifecycle while also managing and improving our application security toolchain and automation pipelines.
Job Responsibility:
Lead the establishment, implementation, and continuous improvement of the enterprise Application Security program
Manage and administer application security platforms including Fortify, Trivy, and Wiz
Develop and maintain processes for application vulnerability scanning, triage, and remediation tracking
Partner with DevOps and Engineering teams to integrate application security controls and tooling into CI/CD pipelines
Define standards and best practices for secure development, container hardening, and software composition analysis (SCA)
Collaborate with Cloud Security and Infrastructure teams to ensure consistent coverage across workloads and environments
Prioritize and manage application vulnerability findings, working with product owners and development teams to validate and resolve issues
Build and maintain key performance indicators (KPIs) and metrics to measure program effectiveness and risk reduction
Coordinate and participate in security incident investigations involving application vulnerabilities or exploits
Serve as a subject matter expert and advocate for secure development practices across the enterprise
Contribute to enterprise risk assessments, audits, and compliance initiatives related to application security
Other duties as assigned
Requirements:
Minimum of 5 years’ experience in Information Security with a focus on Application Security or DevSecOps
Hands-on experience administering and integrating security tools such as Fortify, Trivy, and Wiz
Strong understanding of application security principles, common vulnerabilities (OWASP Top 10, SANS CWE), and secure configuration practices
Experience automating security scans and controls within CI/CD pipelines (e.g., Bitbucket Pipelines, GitHub Actions, Jenkins, GitLab CI)
Working knowledge of cloud platforms (AWS, Azure) and containerized environments (Docker, Kubernetes)
Experience with vulnerability management, prioritization, and risk-based remediation workflows
Excellent communication and collaboration skills with the ability to influence technical and non-technical stakeholders
Demonstrated ability to operate independently in a greenfield or rapidly maturing environment
Strong analytical and problem-solving skills, with a focus on measurable risk reduction and program maturity
Bachelor's degree in Computer Science, Information Security, or a related field or equivalent experience is required
Certification within the Information Security or IAM fields or within six (6) months of hire
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.