We are seeking an experienced Application Security Engineer to join our Cyber Security organization and strengthen the security of our applications, APIs, and CI/CD pipelines. In this role, you will partner with engineering, architecture, and DevOps teams to embed security into the SDLC, implement and optimize WAF policies, enhance supply chain and pipeline security, and promote secure API and application design across the enterprise.
Requirements
- 5–8+ years in Application Security, Product Security, or Secure Software Development
- Hands-on experience securing CI/CD pipelines and source repositories (GitHub, GitLab, Jenkins, etc.)
- Knowledge of supply chain security frameworks (SLSA, NIST SSDF)
- Experience with secrets management, artifact signing (Sigstore, Cosign), and build integrity
- Strong background in WAF tuning, API security, and vulnerability remediation
- Proficiency in at least one programming language (Python, Java, Go, JavaScript/Node.js)
- Experience with SAST, DAST, SCA, and container scanning tools
- Cloud security experience (AWS, Azure, or GCP)
- Strong understanding of OWASP Top 10 (Web & API), CWE, and secure coding practices
- Familiarity with OWASP Top 10 for LLM Application and MITRE ATLAS
Benefits
- Health & Wellbeing
- Personal & Professional Development
- Unconditional Inclusion