This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Application security engineers work on a team that identifies threats and risks, vulnerabilities and attack vectors, and works with engineering to develop ways to mitigate and prevent. This is very much a product security role, where you have the opportunity to take ownership in the overall direction of the security of our products, including cloud and mobile apps. This role is on the front lines of securing hundreds of thousands of people’s healthcare and personal information.
Job Responsibility:
Define, maintain and enforce application security best practices
Create secure design patterns and execute training and awareness to engineering team
Conduct architecture reviews, assess and validate application security
Conduct code reviews from a code security perspective
Explain and demonstrate vulnerabilities to application/system owners, provide recommendations for mitigation, and design solution prototypes and/or implement security enhancements
Investigate incidents and lead response efforts while identifying methods to improve using modern security techniques like fuzzing, etc.
Participate in building and maturing security operations
Work with Product and Engineering teams to review new features from a security perspective
Integrate security best practices and tooling into our CI/CD process, combining security with velocity.
Requirements:
Experience of 5 to 8 years in Web development/Full stack development
Experience performing security-based code reviews and/or experience in using static code analysis and inspection tools such as Veracode, Coverity and/or Blackduck
In-depth knowledge of systems and security including cryptography, authentication protocols, intrusion detection systems, firewalls and VPNs
History finding bugs and security flaws in all system layers to minimize risk within an organization
Nice to have:
FDA medical device incident preparedness and response playbook
Development of threat models and performing cybersecurity risk analysis
Experience with cloud infrastructure providers, specifically AWS
Experience with modern container orchestration, specifically Kubernetes