DigiCert is seeking an Application Security Engineer to help safeguard the company's web applications and services by integrating security practices into the Software Development Life Cycle (SDLC).
Requirements
- Support the integration of security controls and best practices across various phases of the SDLC.
- Assist in security assessments, including static and dynamic code analysis, open-source dependency analysis, and limited penetration testing.
- Collaborate with software engineers to promote secure development practices, including the use of security testing tools in CI/CD pipelines.
- Contribute to the evaluation, deployment, and tuning of DevSecOps tools such as SAST, DAST, and SCA platforms.
- Stay up to date on current security threats, vulnerabilities, and best practices in application security.
- Assist with triaging vulnerabilities from internal scans, bug bounty submissions, or external assessments.
- Document processes and playbooks to support consistent and scalable security practices.
- Provide input to the development of internal security standards and reference architectures.
- Support remediation efforts in collaboration with engineering teams.
- Participate in promoting a security-first culture across the organization.
Benefits
- Generous time off policies
- Top shelf benefits
- Education, wellness and lifestyle support