Senior Application Security Engineer
A sovereign AI and national cyber-defense organization is seeking a Senior Application Security Engineer to strengthen security across its software development lifecycle, cloud infrastructure, and platform environment. The role is hands-on and partners with Security, Engineering, Platform, DevOps, ?
Обязанности
- Own application security across the software development lifecycle, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
- Strengthen cloud and platform security through scalable controls, identity guardrails, and secure-by-default practices.
- Design security controls for multi-account or multi-cloud environments.
- Automate security controls and remediation workflows.
- Define, track, and report metrics covering control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
- Partner with Security, Engineering, Platform, DevOps, and IT teams to reduce organizational security risk.
- Translate technical risk into clear remediation guidance for engineering and leadership stakeholders.
Требования
- At least 6 years of relevant experience in security engineering, application or product security, cloud or platform security, software engineering, or infrastructure engineering.
- Deep expertise in application or product security, with hands-on capability in cloud or platform security, or vice versa.
- Strong programming and automation skills; Python proficiency is required.
- Practical experience with CI/CD and infrastructure as code.
- Experience with threat modeling, secure design and code reviews, application and API testing, and CI/CD security controls.
- Strong knowledge of OWASP risks and secure design principles.
- Hands-on experience securing a major public cloud platform, including IAM, workloads, networks, logging, organizational guardrails, containers or Kubernetes, and secrets and key management.
- Experience with application and cloud security tools such as SAST, DAST, SCA, secrets scanning, CSPM or CNAPP, and cloud-native security services.
- Experience with Kubernetes admission controls, image and dependency scanning, software supply-chain security, and CIS benchmarks.
- Familiarity with OWASP ASVS or SAMM, NIST SSDF or CSF, MITRE ATT&CK, and SOC 2 or ISO 27001 control environments.
Будет плюсом
- Go or Bash experience.
- Experience with multi-account or multi-cloud security controls using Terraform, OPA, Sentinel, or automated remediation.
- Experience running a Security Champions, bug bounty, or responsible disclosure program.
- Experience delivering secure engineering training.
- Experience securing AI-assisted development workflows, enterprise AI tools, agent integrations, or MCP-connected systems.