Talent.com
Application Security Engineer
Application Security EngineerInvoiceCloud • Boston, MA, US
Application Security Engineer

Application Security Engineer

InvoiceCloud • Boston, MA, US
4 days ago
Job type
  • Full-time
Job description

Job Description

Job Description

About InvoiceCloud :

InvoiceCloud is a fast-growing fintech company with an award-winning culture and a leading disruptor in the electronic bill presentment and payment (EBPP) space. Serving more than 3,200 customers across the utility, government, and insurance industries, InvoiceCloud's secure and innovative SaaS platform enhances the customer experience, driving higher digital payment, AutoPay, and paperless adoption rates. By switching to InvoiceCloud, clients can improve customer engagement and satisfaction while lowering costs, accelerating payments, and reducing staff workloads. To learn more, visit InvoiceCloud.com.

Mission :

Excellence in technology, information security, and regulatory compliance are foundational to our success. While complex software development lifecycle (SDLC) processes are supported and automated by advanced systems, their effectiveness depends on consistent, reliable execution across all business functions. This challenge is amplified by variations in coding practices and development pipelines across teams and organizations. To meet these demands, a comprehensive and integrated application security program must be clearly defined, diligently maintained, effectively implemented, and consistently measured to ensure that every application we deliver achieves the level of security expected by both our company and our customers.

The Application Security Engineer plays a key role in reducing risk across InvoiceCloud's platform by driving the application security program. This role requires strong attention to detail, persistence, expertise in application security and programming languages, planning skills, self-motivation, organization, communication, and problem-solving abilities. The Application Security Engineer will own all aspects of creating, fostering, implementing, and maintaining an application security program across the firm. The primary objective of this position is to consistently identify, prioritize, and mitigate risks related to application security in an effective manner.

Responsibilities :

  • Lead application security reviews and threat modeling, including code review and dynamic testing.
  • Own and perform application security vulnerability management.
  • Lead product and development teams in application security.
  • Lead development of automated security testing to validate that secure coding best practices are being used.
  • Guide and advise product development teams as SMEs in the area of application security.
  • Work closely with developers to help improve the security of their products and services, as well as designing technical solutions to address security weaknesses, and working with relevant stakeholders to implement them.
  • Serve as the liaison between management and development resources for matters pertaining to application security initiatives.
  • Serve as the point of contact regarding overall application security program process.
  • Interact with development personnel, management, consultants, and other company personnel to proactively and reactively maintain security risk objectives.
  • Collaborate in the creation, maintenance of IT control matrices and IT process documentation for various compliance requirements (PCI DSS, NIST CSF, Enterprise Risk & Security and Operations, Applications, and ITGC procedures).

Qualifications :

This role has privileged access to highly sensitive information, intellectual property, legal matters, and complex business scenarios. The successful candidate has :

  • Bachelor's in Computer Science, Information Technology or related is preferred
  • 5+ years of application security experience
  • Hands-on experience across SDLC activities such as threat modeling, secure code review, vulnerability management, and penetration testing
  • Certifications such as CISSP, CSSLP, CEH, OSCP, or GIAC preferred
  • Upholds strong ethics when handling sensitive and confidential information.
  • Experience analyzing system services, spotting issues in code, networks and applications from a security perspective, has troubleshooting skills to recognize security issues that appear under new threat scenarios.
  • Demonstrated knowledge in resolving vulnerabilities in various programming languages including .net, JavaScript, and Python.
  • Demonstrated knowledge and ability to deploy tools, methodologies, and controls to reduce application security risk.
  • Possesses strong decision-making capabilities and an ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
  • Foundational knowledge of deploying and securing SaaS applications and cloud environments
  • Personal Skills

  • Optimistic, persistently driving for the positive outcome
  • Team player; collaborative and can work independently.
  • Excellent coordination and orchestration abilities
  • Strong work ethic, interpersonal skills, time management, planning and execution skills
  • Resourceful, collaborative, 'out of the box' thinking
  • Demonstrates a personal code of ethics, integrity, and trust
  • Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment
  • Efficient communications skills (written / verbal) and interpersonal savvy
  • Possess a good sense of self and a strong, approachable personal presence.
  • Possess the determination to get results without harm, provide transparent feedback, and prioritize a positive outcome.
  • Base salary is one component of total compensation. Employees may also be eligible for an annual bonus or commission. Some roles may also be eligible for overtime pay. The above represents the expected base compensation range for this job requisition. Ultimately, in determining your pay, we'll consider many factors including, but not limited to, skills, experience, qualifications, geographic location, and other job-related factors.

    Base Compensation Range

    $145,000—$170,000 USD

    InvoiceCloud is an Equal Opportunity Employer.

    InvoiceCloud provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

    This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

    If you have a disability under the Americans with Disabilities Act or similar law, or you require a religious accommodation, and you wish to discuss potential accommodations related to applying for employment at our company, please contact jobs@invoicecloud.com.

    Click here to review InvoiceCloud's Job Applicant Privacy Policy.

    To all recruitment agencies :  InvoiceCloud does not accept agency resumes. Please do not forward resumes to our job's alias, employees, or any other organization location. Invoice Cloud is not responsible for any fees related to unsolicited resumes.

    Create a job alert for this search

    Application Security Engineer • Boston, MA, US

    Related jobs
    Security Engineer

    Security Engineer

    Thrive • Foxborough, MA, US
    Full-time
    Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer...Show more
    Last updated: 19 days ago • Promoted
    Information Systems Security Engineer (ISSE)

    Information Systems Security Engineer (ISSE)

    STR • Woburn, MA, US
    Full-time
    The Security team at STR is comprised of highly skilled professionals who are responsible for maintaining compliance with Government protocol and directives. The Classified Cybersecurity (CCS) team ...Show more
    Last updated: 25 days ago • Promoted
    Information System Security Eng (ISSE) III

    Information System Security Eng (ISSE) III

    Global Resource Solutions, Inc. • North Lexington, MA, US
    Full-time
    Global Resource Solutions, Inc.GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Information System Security Engineer III.The Information Sy...Show more
    Last updated: 30+ days ago • Promoted
    Security Analyst

    Security Analyst

    Aquila Technology • Lexington, MA, US
    Full-time
    Must have a Top Secret Clearance to be considered for this opportunity and eligible for SCI.At Aquila Technology, you will see our team's passion every day, whether we are building a robust, po...Show more
    Last updated: 8 hours ago • Promoted • New!
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    Relativity • Boston, MA, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show more
    Last updated: 30+ days ago • Promoted
    Information Assurance (IA) System Security Engineer III

    Information Assurance (IA) System Security Engineer III

    gTANGIBLE Corporation • North Lexington, MA, US
    Full-time
    TANGIBLE Corporation (gTC), www.S corporation and a registered Government contractor that provides services and solutions in : . Professional, Administrative, and Management Support.Mission and Warfig...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Engineer IIInformation Technology • Somerville, MA • Full time • Remote

    Information Security Engineer IIInformation Technology • Somerville, MA • Full time • Remote

    Form Energy • Somerville, MA, United States
    Remote
    Full-time
    Are you ready to build America's energy future? Form Energy is an American manufacturing and energy technology company.We're revolutionizing energy storage with cost-effective, multi-day technology...Show more
    Last updated: 19 hours ago • Promoted • New!
    System Security Engineer

    System Security Engineer

    Draper Labs • Cambridge, MA, United States
    Full-time
    Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA.The 2,000+ employees of Draper tackle important national challenges with a promise of delivering ...Show more
    Last updated: 20 days ago • Promoted
    Senior Systems Engineer, SAP Security

    Senior Systems Engineer, SAP Security

    Moderna • Cambridge, MA, United States
    Permanent
    As the Senior Systems Engineer you will own and drive Moderna's SAP Security and GRC roadmap-driving access-management procedures, periodic access reviews, and audit readiness across our global SAP...Show more
    Last updated: 2 days ago • Promoted
    CFD Application Engineer

    CFD Application Engineer

    Flexcompute Inc. • Watertown, MA, United States
    Permanent
    Flexcompute is a solver technology company that specializes in ultra-fast, high-fidelity simulations.Our products are utilized by companies designing and optimizing advanced technologies, with appl...Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    Relativity • Boston, MA, United States
    Full-time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Lever Demo - IS Opportunities • Boston, Massachusetts, United States, 02108
    Full-time
    PLEASE READ : these jobs are testing jobs of Lever's testing environment - please do not apply for this job.Lever was founded ten years ago to tackle the most strategic challenge that companies face...Show more
    Last updated: 30+ days ago
    Security Installation Specialist

    Security Installation Specialist

    Jobot • Boston, MA, United States
    Full-time
    Security Installation Specialist- Worldwide leader in smart buildings and automation technology.This Jobot Job is hosted by : Jamal Elkhateib. Are you a fit? Easy Apply now by clicking the "Apply" bu...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    Robert Half • Boston, MA, US
    Full-time
    We are looking for a talented Cyber Security Engineer to join our team in Boston, Massachusetts.This role requires a proactive individual with strong technical expertise to design, implement, and m...Show more
    Last updated: 17 days ago • Promoted
    Application Engineer, Measurement Solutions

    Application Engineer, Measurement Solutions

    NECI • Foxborough, MA, US
    Full-time
    NECI is an Emerson Impact Partner and provider of industrial automation and digital transformation solutions and services. We solve process, automation, and data integration challenges in therapeuti...Show more
    Last updated: 11 days ago • Promoted
    Senior Integration Engineer - Security

    Senior Integration Engineer - Security

    Red Hat • Boston, MA, United States
    Full-time +1
    The Red Hat Engineering team is seeking a Senior Integration Engineer - Security with a deep understanding of security principles, and industry best practices to join our growing team.You will play...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer (Hybrid - US)

    Senior Application Security Engineer (Hybrid - US)

    Energy Solutions • Boston, MA, United States
    Full-time
    Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus ...Show more
    Last updated: 15 days ago • Promoted
    Telecom Security Architect

    Telecom Security Architect

    ANDREW, an Amphenol company • Nashua, NH, US
    Full-time
    Join our team and help shape the future of connectivity indoors and outdoors.Together, let's push the boundaries of technology and advance sustainable networks worldwide.How You'll Help Us ...Show more
    Last updated: 28 days ago • Promoted