Talent.com
Senior Application Security Engineer
Senior Application Security EngineerM&T Bank • Wilmington, DE
Senior Application Security Engineer

Senior Application Security Engineer

M&T Bank • Wilmington, DE
Hace más de 30 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Overview:

Responsible for capturing and refining information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration. Provides advanced working guidance to technology teams and leadership in the areas of secure coding, application authentication, encryption, and quickly research and become competent in other areas as needed.

Primary Responsibilities:

  • Develop and implement engineering’s technical security policies and procedures, and performance of security measures,
  • Scan and test applications for potential vulnerabilities and non-compliance with security standards,
  • Partner with engineering teams during code reviews to identify potential security vulnerabilities and advise strategies to develop more secure code,
  • Integrate security tools and processes into the software development and operations (DevOps) pipeline, including automation of security checks and scans to identify and fix vulnerabilities early in the development process.
  • Lead training sessions for technology teams in one-on-one coaching and large team training sessions on secure coding practices and information system security best practices.
  • Configure and manage automated tools and solutions to address security weaknesses in applications, systems, and infrastructure.
  • Partner closely with incident response teams to mitigate the impact of incidents from application security vulnerabilities and identify necessary steps to remediate findings.
  • Proactively recommend process enhancements and implement prioritized improvements within Cybersecurity team to enhance application security capabilities.
  • Track current events, technological advancements, and changes in the secure application development landscape to anticipate how attackers may change their tactics, and implement adjustments to internal technologies, policies, and procedures.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports belonging and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:

  • Partners primarily with individual contributors and leaders within Cybersecurity and Technology, and occasionally senior leaders within Cybersecurity.
  • Determines and develops approach to solutions. Work is accomplished with periodic check-ins for alignment and limited direction. Work is evaluated upon completion to ensure objectives have been met.
  • Proficient ability to use multiple Cybersecurity tools, specific to function.
  • This role is used within Cybersecurity, typically in one of the following ways:Application Security – partners with engineers and developers to secure first-party and third-party code by reviewing the application, data, and systems it interacts with.Product Security – secures products by ensuring they are designed, developed, and delivered in a secure manner".

Manager Responsibilities:

No supervisory responsibilities

Education and Experience Required:

  • Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience, including a minimum of 5 years software development or application security
  • Prior experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
  • Intermediate understanding of the Software Development Life Cycle (SDLC)
  • Ability to train technologist and people leaders at various levels on secure application development, both in person and virtually
  • Excellent communication and interpersonal skills

Education and Experience Preferred:

  • Intermediate experience reviewing or fixing vulnerabilities identified using application security tools such as static application security testing (SAST), software composition analysis (SCA), interactive application security testing (IAST), dynamic application security testing (DAST), or application security posture management (ASPM) suite
  • Understanding of common software weaknesses that impact cloud and web applications, beyond the Open Worldwide Application Security Project (OWASP) Top 10
  • Demonstrable experience developing and maintaining automation for application security tasks and defect identification
  • Experience developing enterprise applications
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments
  • Certifications in the area of Application Security
  • Proficient persuasive communication skills to gain buy-in of others in cybersecurity and technology teams
  • Ability to create an effective learning environment that allows for maximum learner results
  • Must be comfortable with providing 1-1 coaching for all levels of individual contributors and up to SVP management
  • Ability to build and maintain effective relationships within and across multiple technical teams
  • Prior experience utilizing continuous integration and continuous deployment (CI/CD) pipeline instrumentation
  • Highly proficient at coding with one or two programming languages
  • Highly proficient with Agile development methodologies and version control systems
  • Experience defining and reviewing software security features and capabilities

#LI-JB3 #Hybrid

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $102,939.06 - $171,565.10 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Location

Wilmington, Delaware, United States of America
Crear una alerta de empleo para esta búsqueda

Senior Application Security Engineer • Wilmington, DE

Ofertas similares

Senior Appliance Repair Technician

Mr. ApplianceMiddletown, DE, US
A tiempo completo

Are you the technician others call when they are stuck? Do you get excited when teaching your knowledge of appliances to other technicians? Do you enjoy helping others and teaching your craft? Woul...Mostrar más

Active Directory Engineer

TEKsystemsWilmington, Delaware, United States
A tiempo completo

Work closely with Technology management ,Active Directory Engineers, and support teams on a regular basis to implement and manage the design, development, and execution of technical solutions that ...Mostrar más

 • Oferta promocionada

Senior Director of Software Engineering - Trust & Security, Fraud Technology

JPMorgan ChaseWilmington, DE, United States
A tiempo completo

Your opportunity to make a real impact and shape the future of financial services is waiting for you.Let's push the boundaries of what's possible together.As a Senior Director of Software Engineeri...Mostrar más

 • Oferta promocionada • Nueva oferta

Global Security Intelligence & Threat Analyst

Qurate Retail GroupWest Chester, PA, United States
A tiempo completo

Working at QVC Group means joining a live social shopping company with incredible teams, ambitious projects and amazing careers.Fortune 500 company with six leading retail brands - QVC, HSN, Ballar...Mostrar más

 • Oferta promocionada

25S Satellite Communication Systems Operator-Maintainer

Army National GuardSmyrna, DE
A tiempo parcial

Communication is a vital part of the military’s ability to run successful missions.It’s the role of the Satellite Communication Systems Operator-Maintainers to ensure the lines of communication are...Mostrar más

 • Oferta promocionada

Technology Programs - Entry Level Training Programs

DreamboundMiddletown, Delaware, United States
A tiempo completo

Note: This is an educational program, not a job.Successful completion of the program does not guarantee employment but will equip you with valuable skills for the technology job market.Are you pass...Mostrar más

 • Oferta promocionada

DOW SkillBridge Military Application (Delaware)

Builders FirstSourceMiddletown, Delaware, United States
A tiempo completo

Ignite your career at Builders FirstSource, America's largest supplier of building materials, value-added components and building services to the professional market.The #1 name in our industry, we...Mostrar más

 • Oferta promocionada

Remote Senior C Engineer - AI Trainer

SuperAnnotateMiddletown, Delaware, US
Teletrabajo
A tiempo completo

As a Senior C Engineer, you will work remotely on an hourly paid basis to review AI-generated C code, low-level systems designs, and technical explanations, as well as generate high-quality referen...Mostrar más

Senior Radar Engineer

Lockheed MartinWilmington, Delaware, United States
A tiempo completo

Here at Lockheed Martin Rotary and Mission Systems (RMS) we take on the biggest and baddest challenges in the world.We seek out innovative ideas and creative solutions to seemingly impossible probl...Mostrar más

 • Oferta promocionada • Nueva oferta

Commercial Applicator | FT, Year round

GpacMiddletown, Delaware, United States
A tiempo completo
Quick Apply

A well-established agricultural operation in Delaware is seeking a.This role is ideal for someone who enjoys hands-on fieldwork, modern equipment, and being part of a tight-knit, high-performing te...Mostrar más

Healthcare TPRM Analyst — Governance & Security

Fortified Health SecurityExton, Pennsylvania, United States
A tiempo completo

A leading health security firm is looking for a Third Party Risk Analyst to oversee Third-Party Risk Management assessments.Key responsibilities include delivering vendor assessment reports, managi...Mostrar más

 • Oferta promocionada

Remote Senior C++ Engineer - AI Trainer

SuperAnnotateSmyrna, Delaware, US
Teletrabajo
A tiempo completo

As a Senior C++ Engineer, you will work remotely on an hourly paid basis to review AI-generated C++ code, systems designs, and technical explanations, as well as generate high-quality reference imp...Mostrar más

Sr. Radar Systems Engineer

Lockheed MartinMontchanin, DE, United States
A tiempo completo

Here at Lockheed Martin Rotary and Mission Systems we take on the most demanding challenges in the world.We seek out innovative ideas and creative solutions to seemingly impossible problems facing ...Mostrar más

 • Oferta promocionada

Senior Director of Software Engineering – Trust & Security, Fraud Technology

JPMorganChaseWilmington, DE, United States
A tiempo completo

Your opportunity to make a real impact and shape the future of financial services is waiting for you.Let’s push the boundaries of what's possible together.As a Senior Director of Software Engineeri...Mostrar más

 • Oferta promocionada

Sr Engineer

ExelonOdessa, DE, United States
A tiempo completo

We're powering a cleaner, brighter future.Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers.Work with us to delive...Mostrar más

 • Oferta promocionada

Sr. Principal Industrial Security Analyst

Northrop GrummanElkton, MD, United States
A tiempo completo

Principal Industrial Security Analyst (Level 4).At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, ...Mostrar más

 • Oferta promocionada

Cybersecurity Engineer

SkillWilmington, Delaware, United States
A tiempo completo +1

Aquent is partnering with a leading financial institution dedicated to safeguarding its operations and customer data through robust cybersecurity measures.Are you a seasoned cybersecurity professio...Mostrar más

 • Oferta promocionada

Remote Risk Analyst - AI Trainer ($50-$60 per hour)

Data AnnotationMiddletown, DE, United States
Teletrabajo
A tiempo completo +1

DataAnnotation is committed to creating high-quality AI.Join our team to help train the next generation of AI while enjoying the flexibility of remote work and the freedom to set your own schedule....Mostrar más