Application Security Engineer
Join a global SaaS company to lead product and application security efforts. Drive security design, ensure secure coding practices, and validate services against the highest standards. Work closely with R&D and Product teams to mitigate risks throughout the SDLC.
Responsibilities
- Partner with development and product teams to integrate security best practices into the SDLC
- Lead threat modeling and architecture security reviews to proactively identify and mitigate risks
- Conduct security assessments, including code reviews, vulnerability scans, penetration testing, and secure product design reviews
- Stay up to date with emerging security threats, vulnerabilities, and industry trends
- Support and contribute to security incident response activities, including root cause analysis and post-incident improvements
- Automate security processes and integrate security tools within CI/CD pipelines
- Develop and deliver secure coding training to engineering teams
Requirements
- 3+ years of experience in Application Security, Penetration Testing, or Product Security in a SaaS company
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)
- Deep understanding and hands-on experience of web application security, including OWASP Top 10, authentication, encryption, and secure coding principles
- Proficiency in scripting or programming languages (Python, JavaScript, Go, etc.) for security automation
- Experience with cloud security best practices (AWS, GCP, or Azure)
- Hands-on experience with DevSecOps and integrating security tools into CI/CD pipelines
- Strong communication skills, with the ability to explain security risks and recommendations to technical and non-technical stakeholders, including executive management
- Experience working with large-scale, complex R&D environments