Talent.com
Application Security Engineer
Application Security EngineerISC2 • Harrisburg, PA, United States
Application Security Engineer

Application Security Engineer

ISC2 • Harrisburg, PA, United States
4 days ago
Job type
  • Full-time
Job description

Overview

Your Future. Secured. ISC2 is a force for good. As the world's leading nonprofit member organization for cybersecurity professionals, our core values - Integrity, Advocacy, Commitment, Inclusion, and Excellence - drive everything we do in support of our vision of a safe and secure cyber world. Our globally recognized, award-winning portfolio of certifications provide an independent and globally recognized endorsement of cybersecurity knowledge, skills and experience for all career levels. Our charitable arm, the Center for Cyber Safety and Education, enables ISC2 and our members to serve the public by educating the most vulnerable about cyber risks and empowering access to enter and thrive in the cyber profession. Learn more at ISC2 online and connect with us on Twitter, Facebook and LinkedIn. When you join ISC2, you'll demonstrate your commitment to an inclusive and equitable environment. Your support of the unique perspectives and experiences shared by our global cybersecurity workforce and profession will be recognized. We invite you to take an active role in helping us create a true sense of belonging across our organization - an environment of authenticity, trust, empowerment and connectedness that empowers all of our successes. Learn more.

Position Summary

The Application Security Engineer will be an integral part of the security team and will work cross-functionally with several lines of business to ensure the secure delivery of products and applications. The Application Security Engineer will be expected to attend stand-ups and strategy sessions to identify areas of risk and offer consulting on best practices. The Application Security Engineer will act as a champion and will formalize the integration of application security into our current processes and tools.

Responsibilities

The Application Security Engineer will be expected to facilitate technical design reviews, perform code analysis, offer remediation recommendations, perform manual and dynamic security testing, and document and present all findings. The Application Security Engineer will work closely with the Development, Release, and QA teams to identify and coordinate security testing, validate, test, and vet both internally and externally developed applications. As an Application Security Engineer, you will act as a DevSecOps Engineer that will be responsible for secure application delivery as well as the underlying infrastructure. The Application Security Engineer must be comfortable with securing cloud-based products in environments such as AWS, Azure and Salesforce. Additionally, this position will provide security risk assessments, create threat models and assist the team with vulnerability testing.

Additionally, this position manages the ISC2 responsible reporting program that supports the organization's secure application delivery objectives. In addition to the daily duties described, the individual will assist the security engineering team in the management of security technologies administered by the group (e.g., WAF, Firewall, IDS, and SEIM). This would be an "as needed" function, which is primarily to provide coverage for those duties when individuals on the security engineering team are out of the office for training or vacation. Additionally, the Application Security Engineer will be expected to participate in the Incident Response team and act as a Subject Matter Expert when dealing with the continuity of our operations and when responding with cyber incidents.

Conduct security assessments : Perform comprehensive security assessments of applications, including static code analysis, dynamic application testing, and penetration testing. Identify vulnerabilities, weaknesses, and potential attack vectors.

Secure code review : Review application source code to identify security flaws, such as insecure authentication mechanisms, input validation vulnerabilities, and potential injection attacks. Provide recommendations for remediation and best practices for secure coding.

Threat modeling : Collaborate with development teams to identify and assess potential threats and risks associated with the application. Use threat modeling techniques to prioritize security controls and countermeasures.

Develop and implement security controls : Design, develop, and implement security controls and countermeasures to protect applications against common security threats, such as cross-site scripting (XSS), cross-site request forgery (CSRF), and SQL injection. Implement secure coding practices and security guidelines.

Vulnerability management : Establish and maintain a vulnerability management program for applications. Track and prioritize vulnerabilities based on their severity and impact. Coordinate with development teams to ensure timely remediation of identified vulnerabilities.

Security testing automation : Develop and maintain automated security testing tools and scripts to streamline the application security testing process. Integrate security testing into the continuous integration and deployment (CI / CD) pipeline.

Security training and awareness : Conduct security training and awareness programs and determine skills training needs for development teams, promoting secure coding practices andawareness of common security vulnerabilities. Stay updated with the latest security trends, attack techniques, and best practices.

Incident response : Provide support during security incidents or breaches related to applications. Participate in incident response activities, including containment, investigation, and remediation.

Compliance and regulatory requirements : Ensure that applications adhere to relevant security compliance standards, industry regulations, and data privacy requirements (e.g., GDPR (General Data Protection Regulation), HIPAA (Health Insurance Portability and Accountability)). Collaborate with compliance teams to address any compliance-related concerns.

Security documentation and reporting : Prepare and maintain security documentation, including security policies, procedures, and guidelines. Generate periodic reports on the security posture of applications and present findings to relevant stakeholders.

Other responsibilities include :

Maintain and manage all pipelines from a security perspective.

Onboard new pipelines for security tooling.

Keep pipeline diagrams up to date with current security details.

Serve as the primary SME for the DAST scanner.This includes configuration, testing, vulnerability management, and remediation oversight.

Recommend continuous improvements for the SAST scanner.

Security code release approvals

Maintain and manage the WAF, including signatures, configuration, and threat intel feeds.

Serve as the SME and provide recommendations for ongoing improvements.

Establish baseline WAF signatures for XD Prod following the Silverline migration.

Baseline WAF signatures after code releases.

Serve as the primary point of contact for vetting bug reports and managing the informed disclosure process.

Assist with attestation data gathering.

Support and assist with threat modeling.

Act as the formal backup for the threat modeling and attestation processes.

Review and approve Security Assessment Review reports as needed.

Perform other duties as required.

Behavioral Competencies

Ability to demonstrate and support the ISC2 Core Values : ? Integrity, Excellence, Inclusion, Advocacy and Commitment

Function as an architect, who can conduct architecture reviews of new systems and solutions.

Serve as a builder who can build and integrate application security in our SDLC.

Act as a collaborator, who likes to engage with the team and the industry.

Serve as a team player, who will jump in and assist in other security functions as needed.

Function as a leader, who will use your knowledge and to train and guide developers and engineers.

Demonstrate a passion for application security, creative and critical thinking, strong analysis skills, the ability to work in a fast-paced environment, and have familiarity with agile, continuous integration, and continuous deployment.

Experience in securing SaaS-delivered offerings in multiple cloud environments deployed with automation & orchestration.

Qualifications

Ability to write some code, as needed, to conduct security-focused testing.

Application Experience with common testing tools such as Veracode, Fortify, Zap, Burp, and fiddler, among others.

Application Understanding of common vulnerabilities & remediation.

Application Knowledge and understanding of automation and scripting languages.

Design & code review skills.

A solid understanding of Microsoft platforms such as .NET, Windows, C#, Azure.

General Knowledge of cloud security, API (Application Programming Interface) security, and associated best practices.

Education and Work Experience

Bachelor's degree in computer science, information systems, related engineering field. Will consider a high school diploma and 10+ years of relevant work experience, as well as current additional credentials (CCSP, GDSP, etc..) in lieu of a degree.

A CISSP and CSSLP are required for this position.

8+ years of experience in Information Security.

8+ years of experience with static and dynamic analysis for coding and vulnerability identification and remediation.

5+ years of Secure Development experience.

Application Experience with implementing Secure Development Lifecycle in an agile environment.

First-hand experience with architectural reviews, application reviews, and penetration testing.

Application Experience with Continuous Integration processes, particularly with building security practices into the pipeline.

Physical and Mental Demands

Ability to travel up to 10% of time. May also include overnight travel.

Work extended hours, when necessary.

Work in an office environment using dual monitor computer screens.

Sitting for extended periods.

Equal Employment Opportunity Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic as protected by applicable law. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

Job Locations US-Remote

Posted Date 1 week ago (11 / 19 / 2025 1 : 29 PM)

Job ID 2025-2253

# of Openings 1

Category Information Security

Create a job alert for this search

Application Security Engineer • Harrisburg, PA, United States

Related jobs
Security Engineer

Security Engineer

Nutanix • Harrisburg, PA, United States
Full-time
Hungry, Humble, Honest, with Heart.Are you a forward-thinking security professional with a passion for implementing cutting-edge technology and a strong understanding of Zero Trust principles? If s...Show more
Last updated: 2 days ago • Promoted
Hardware Security Consulting Engineer

Hardware Security Consulting Engineer

Oracle • Harrisburg, PA, United States
Full-time
As consulting hardware security engineer, you will be responsible for defining security requirements for hardware used within OCI, conducting security / architectural reviews and assessments, offensi...Show more
Last updated: 30+ days ago • Promoted
Security Engineer - Secure Software Development

Security Engineer - Secure Software Development

Sedgwick • Harrisburg, PA, United States
Full-time
By joining Sedgwick, you'll be part of something truly meaningful.It's what our 33,000 colleagues do every day for people around the world who are facing the unexpected. We invite you to grow your c...Show more
Last updated: 30+ days ago • Promoted
Cyber SDC - Attack & Penetration - Senior - Consulting - Location OPEN

Cyber SDC - Attack & Penetration - Senior - Consulting - Location OPEN

EY • Harrisburg, PA, United States
Full-time
At EY, we’re all in to shape your future with confidence.We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Join EY and help ...Show more
Last updated: 17 days ago • Promoted
Security Engineer II

Security Engineer II

Trustmark • Harrisburg, PA, United States
Full-time
Trustmark's mission is to improve wellbeing - for everyone.It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust.Tr...Show more
Last updated: 30+ days ago • Promoted
Sr. Security Research Engineer

Sr. Security Research Engineer

Proofpoint • Harrisburg, PA, United States
Full-time
We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead...Show more
Last updated: 17 days ago • Promoted
Staff Security Data Engineer

Staff Security Data Engineer

CVS Health • Harrisburg, PA, United States
Full-time
At CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.As the nation's leading h...Show more
Last updated: 11 days ago • Promoted
Security Engineer

Security Engineer

Zoom Corporation • Harrisburg, PA, United States
Full-time
The Security Engineer is responsible for security design and reviews across our products and services, with a specific focus on Platform services and core infrastructure components.The ideal candid...Show more
Last updated: 5 days ago • Promoted
Security Engineer

Security Engineer

META • Harrisburg, PA, United States
Full-time
Meta), formerly known as Facebook Inc.When Facebook launched in 2004, it changed the way people connect.Apps and services like Messenger, Instagram, and WhatsApp further empowered billions around t...Show more
Last updated: 30+ days ago • Promoted
Mobile App Product Manager, Vehicle Security

Mobile App Product Manager, Vehicle Security

Ford Motor Company • Harrisburg, PA, United States
Full-time
We are the movers of the world and the makers of the future.We get up every day, roll up our sleeves and build a better world together. At Ford, we're all a part of something bigger than ourselve...Show more
Last updated: 8 days ago • Promoted
C&I Application Director

C&I Application Director

S&C Electric Company • Harrisburg, PA, US
Full-time
Focus on the core content of the job post, making it beautiful and easy to read.Remove all unnecessary metadata, links, buttons, and any extra information that doesn't contribute to the job descrip...Show more
Last updated: 22 days ago • Promoted
Security Analyst

Security Analyst

JFC Staffing • Camp Hill, PA, United States
Permanent
Security Analyst opening on a permanent hybrid basis up to 85k is available! This role offers a chance to contribute to a stable, essential industry, with a focus on advancing security protocols wi...Show more
Last updated: 3 days ago • Promoted
Application Penetration Tester

Application Penetration Tester

ASM Research, An Accenture Federal Services Company • Harrisburg, PA, United States
Full-time
As an Application Security Penetration Tester, you will be entrusted with the critical responsibility of safeguarding web applications and REST APIs from potential threats.Your role will require a ...Show more
Last updated: 4 days ago • Promoted
Lead Adversarial Security Engineer

Lead Adversarial Security Engineer

Trellix • Harrisburg, PA, United States
Full-time
Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show more
Last updated: 6 days ago • Promoted
Senior Security Engineer & Workday

Senior Security Engineer & Workday

Hudson Manpower • Harrisburg, PA, United States
Full-time
We are looking for a hands on WorkDay developer.This person will fully understand how the HCM modules work and will be able to customize workflows and finetune the system.They will be highly focuse...Show more
Last updated: 13 days ago • Promoted
System Security Specialist III

System Security Specialist III

Solvere Technical Group • Mechanicsburg, PA, United States
Full-time
Solvere Technical Group is seeking an Information System Security Specialist III to provide support across IT and Control systems. Providing oversight of and backup support in the following areas : .D...Show more
Last updated: 3 days ago • Promoted
Cyber Security Manager - Diego Garcia

Cyber Security Manager - Diego Garcia

Amentum • Harrisburg, PA, United States
Full-time
Please note this position is based on Contract Award and is located on the island of Diego Garcia.Facility-Related Control System (FRCS) Cybersecurity Manager. The Contractor shall provide a FRCS Cy...Show more
Last updated: 30+ days ago • Promoted
Offensive Security Engineer, Assessments (Web3)

Offensive Security Engineer, Assessments (Web3)

Coinbase • Harrisburg, PA, United States
Full-time
Ready to be pushed beyond what you think you’re capable of?.At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, ...Show more
Last updated: 30+ days ago • Promoted