Talent.com
Application Security Engineer

Application Security Engineer

PennyMac Mortgage Investment TrustLos Angeles, CA, United States
30+ days ago
Job type
  • Full-time
Job description

PENNYMACPennymac (NYSE : PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U.S. mortgage loans and the management of investments related to the U.S. mortgage market. At Pennymac, our people are the foundation of our success and at the heart of our dynamic work culture. Together, we work towards a unified goal of helping millions of Americans achieve aspirations of homeownership through the complete mortgage journey. A Typical DayThe Application Security Engineer will be a part of our Information Security department and work closely with development teams, product teams, and other stakeholders across the organization. The Application Security Engineer will integrate security into the product lifecycle from design through deployment, with a strong emphasis on cloud environments, secure coding, vulnerability management, attack surface reduction and DevOps practices. The engineer will be responsible for implementing and maintaining advanced security measures to safeguard Pennymac's software systems, applications, code, and related components. The ideal candidate will have a strong background in both cloud and on-premises environments, proficiency in scripting languages (particularly BASH and / or PowerShell), and the ability to understand multiple programming languages. Key responsibilities include managing security across multiple applications, CI / CD pipelines, Infrastructure as Code (IaC) practices, and conducting risk assessments. The role requires a blend of technical expertise in cloud platforms (primarily AWS, with some GCP exposure), system administration skills across Linux and Windows environments, and the ability to effectively communicate complex security concepts to both technical and non-technical audiences. This position offers the opportunity to drive security innovation, mentor junior staff, and contribute to the development of comprehensive, multi-year cybersecurity strategies for Pennymac. The Application Security Engineerwill : Work with product teams throughout the entire SDLC to ensure code is secure by design, secure by default, secure in deployment and

and maintain key security platforms including DAST, SAST, SCA, CSPM to enhance the organization's security posture.Provide subject matter expertise on application security domains, including secure coding practices, continuous integration and deployment, and threat modeling.Perform application code analysis and contribute to security-related code reviews and scanning capabilities across multiple programming languages (e.g., Ruby, Python, Bash, TypeScript, Java, JavaScript, C++, Go).Develop and maintain scripts to automate security processes and enhance efficiency.Stay current with emerging security threats, technologies, and best practices, applying this knowledge to continuously improve Pennymac's security posture.Build relationships with development teams to foster an inclusive culture.Provide subject matter expertise on application security domains including secure coding practices, continuous integration and continuous deployment, and threat modeling.Participate in and provide support during high-priority cybersecurity incidents.Configure cybersecurity systems to monitor and protect serverless and container based computing

cross-functionally with DevOps, application development, database, and infrastructure teams to develop and maintain complex systems that involve integration across in-house developed, COTS, and open-source components.Establish oneself as a trusted security advisor leading the design, definition and implementation of security best practices and standards and ensure product development teams integrate them into their development workflow.Support the establishment, implementation, and governance of secure development standards and security baseline requirements.Drive threat modeling, risk assessment, penetration test findings analysis, and security technology assessments.Maintains an open communication channel with operations, development, and product teams to ensure security is integrated early and is working to solve business needs.Mentor junior staff to develop understanding of DevSecOps, Application Security, and Information Security. What You'll Bring2+ Years Experience in Cyber Security Approximately 3+ years of experience in programming and / or scripting languages.Ability or aptitude to operate within Gitlab and Azure DevOps source code and CI / CD technology stacks.Experience dealing with secure network and system design in Amazon Web Services (AWS)Expert understanding of secure configuration management and security controls.Experience reviewing SAST, DAST, penetration test, and SCA results and providing remediation

performing application code analysis across multiple programming languages (e.g., Ruby, Python, Bash, TypeScript, Java, JavaScript, C++, Go).Capable of architecting, engineering, and operationalizing application security technologies through plan, development, build, test, release, deploy, operate, and monitor phases of the SDLC.Experience in developing and / or reviewing secure development standards that incorporate regulatory and industry best practices.Desired experience with Web Penetration Testing tools for validation of security requirements.Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills.Must have a mindset of continuous improvement of people, processes and technology.Ability to work independently and self-motivate. Why You Should JoinAs one of the top mortgage lenders in the country, Pennymac has helped over 4 million lifetime homeowners achieve and sustain their aspirations of home. Our vision is to be the most trusted partner for home. Together, 4,000 Pennymac team members across the country are guided by our core values : to be Accountable, Reliable and Ethical in all that we do. Pennymac is committed to conducting a business that makes positive contributions and promotes long-term sustainable growth and to fostering an equitable and inclusive environment, where all employees and customers feel valued, respected and supported. Benefits That Bring It Home : Whether you're looking for flexible benefits for today, setting up short-term goals for tomorrow, or planning for long-term success and retirement, Pennymac's benefits have you covered. Some key benefits include : Comprehensive Medical, Dental, and VisionPaid Time Off Programs including vacation, holidays, illness, and parental leave Wellness Programs, Employee Recognition Programs, and onsite gyms and cafe style dining (select locations)Retirement benefits, life insurance, 401k match, and tuition reimbursement Philanthropy Programs including matching gifts, volunteer grants, charitable grants and corporate sponsorshipsTo learn more about our benefits visit : benefitsFor residents with state required benefit information, additional information can be found at : additional-benefits-informationCompensation : Individual salary may vary based on multiple factors including specific role, geographic location / market data, and skills and experience as defined below : Lower in range - Building skills and experience in the roleMid-range - Experience and skills align with proficiency in the role Higher in range - Experience and skills add value above typical requirements of the role Some roles may be eligible for performance-based compensation and / or stock-based incentives awarded to employees based on company and individual performance. Salary$95,000 - $155,000 Work ModelREMOTE

Create a job alert for this search

Application Security Engineer • Los Angeles, CA, United States

Related jobs
Senior Security Engineer, Application Security

Senior Security Engineer, Application Security

Trail of BitsUS
Remote
Full-time
Quick Apply
Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challengi...Show moreLast updated: 30+ days ago
Application Security Architect

Application Security Architect

DatavantUnited States
Remote
Full-time
Datavant is a data logistics company for healthcare whose products and solutions enable organizations to move and connect data securely. We are a data logistics company for healthcare whose products...Show moreLast updated: 30+ days ago
  • Promoted
Application Security Engineer

Application Security Engineer

VirtualVocationsNorth Hollywood, California, United States
Full-time
A company is looking for an Application Security (AppSec) and DevSecOps Engineer to embed security throughout the software development lifecycle and CI / CD pipelines. Key Responsibilities Integrate...Show moreLast updated: 30+ days ago
Senior Application Security Engineer

Senior Application Security Engineer

OpenSeaUS
Remote
Full-time
OpenSea is the first and largest marketplace for NFTs, offering a diverse range of unique and verifiable digital assets backed by blockchain. We're excited about building a platform that supports a ...Show moreLast updated: 30+ days ago
Associate Director, Application Security

Associate Director, Application Security

AIA SingaporeSingapore, Michigan, Singapore
Full-time
Associate Director, Application Security.At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. As pioneering innovators for over 100 years, we’re now...Show moreLast updated: 30+ days ago
Application Security Officer (Cloud Security, Cyber-Security, DevOps Infrastructure Security)

Application Security Officer (Cloud Security, Cyber-Security, DevOps Infrastructure Security)

Antaes Consulting SASingapore, Michigan, Singapore
Permanent
Application Security Officer (Cloud Security, Cyber-Security, DevOps Infrastructure Security).Manage the risks of the Cloud-related projects. Act as an IT Risk, Continuity & CyberSecurity Lead on th...Show moreLast updated: 30+ days ago
Application Security Engineer

Application Security Engineer

PodiumUS
Remote
Full-time
At Podium, our mission is to help local businesses win.Our lead conversion platform, powered by AI and integrations, helps local businesses convert leads faster, communicate easier, and make more s...Show moreLast updated: 30+ days ago
Mobility Application Security

Mobility Application Security

GBIT,US
Full-time
Mobility Application Security requirements (Mobility Development Security Life cycle, Encryptions, Regularity compliance, offline storage etc. Mobility Device Management requirements - MDM .Secured ...Show moreLast updated: 30+ days ago
Application for school Security Officer

Application for school Security Officer

Loyola High School of Los AngelesLos Angeles, CA, US
Full-time
Loyola High School has a COVID vaccine mandate.Livescan, and proof of eligibility to work in the United States.Show moreLast updated: 30+ days ago
Application Security Engineer

Application Security Engineer

ASM ResearchRemote, US
Remote
Full-time
Evaluates application security in all phases of the software development life cycle.Works closely with team members to define application security best practices, performs software architecture and...Show moreLast updated: 30+ days ago
Data & Application Security Engineer

Data & Application Security Engineer

Louisiana-Pacific CorporationRemote, US
Full-time
The Data and Application Security Engineer will oversee and implement all aspects of data and information security for LP. This role will also serve in a support capacity for our third-party applica...Show moreLast updated: 30+ days ago
Application Security Engineer

Application Security Engineer

Magnum HuntWoodland Hills, USA
Permanent
DUTIES & ESSENTIAL JOB FUNCTIONS.Identify risks and areas of exposure in applications developed and / or used by BlackLine. Perform security reviews of source code, stored procedures, and server / servi...Show moreLast updated: 30+ days ago
Manager, Application Security

Manager, Application Security

Starhub LtdSingapore, Michigan, Singapore
Full-time
Press Tab to Move to Skip to Content Link.Select how often (in days) to receive an alert : .The role is responsible for designing, developing, and implementing secured application architecture.As an ...Show moreLast updated: 30+ days ago
Senior Application Security Engineer

Senior Application Security Engineer

Lorven TechnologiesUnited States
Full-time
Senior Application Security Engineer.Below is the detail requirement.Senior Application Security Engineer.Our team is looking for a Senior Application Security Engineer with extensive product secur...Show moreLast updated: 30+ days ago
Senior Application Security Engineer

Senior Application Security Engineer

BoxUS Remote
Remote
Full-time
Box is the world’s leading Content Cloud.We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industrie...Show moreLast updated: 30+ days ago
Senior Application Security Engineer

Senior Application Security Engineer

WomenTech NetworkRemote, US
Remote
Full-time
Your opportunity New Relic is hiring a security engineer to join our Product Security Team! The Infrastructure Assurance team is responsible for safeguarding New Relic's global infrastructure (incl...Show moreLast updated: 30+ days ago
Lead Application Security Engineer

Lead Application Security Engineer

EpamRemote, US
Remote
Full-time
We are in search of a Lead Application Security Engineer to become a part of our team.The preferred candidate should possess a background in software development along with substantial experience i...Show moreLast updated: 30+ days ago
NBCUniversal, Security Engineer, Content Security - Application via WayUp

NBCUniversal, Security Engineer, Content Security - Application via WayUp

MediabistroLos Angeles, CA, United States
Full-time
NBCUniversal, Security Engineer, Content Security - Application via WayUp.NBCUniversal, Security Engineer, Content Security - Application via WayUp. Be among the first 25 applicants This role is wit...Show moreLast updated: 4 days ago