Talent.com
Application Security Engineer

Application Security Engineer

InvoiceCloudBoston, MA, US
20 hours ago
Job type
  • Full-time
Job description

Job Description

Job Description

About InvoiceCloud :

InvoiceCloud is a fast-growing fintech company with an award-winning culture and a leading disruptor in the electronic bill presentment and payment (EBPP) space. Serving more than 3,200 customers across the utility, government, and insurance industries, InvoiceCloud's secure and innovative SaaS platform enhances the customer experience, driving higher digital payment, AutoPay, and paperless adoption rates. By switching to InvoiceCloud, clients can improve customer engagement and satisfaction while lowering costs, accelerating payments, and reducing staff workloads. To learn more, visit InvoiceCloud.com.

Mission :

Excellence in technology, information security, and regulatory compliance are foundational to our success. While complex software development lifecycle (SDLC) processes are supported and automated by advanced systems, their effectiveness depends on consistent, reliable execution across all business functions. This challenge is amplified by variations in coding practices and development pipelines across teams and organizations. To meet these demands, a comprehensive and integrated application security program must be clearly defined, diligently maintained, effectively implemented, and consistently measured to ensure that every application we deliver achieves the level of security expected by both our company and our customers.

The Application Security Engineer plays a key role in reducing risk across InvoiceCloud's platform by driving the application security program. This role requires strong attention to detail, persistence, expertise in application security and programming languages, planning skills, self-motivation, organization, communication, and problem-solving abilities. The Application Security Engineer will own all aspects of creating, fostering, implementing, and maintaining an application security program across the firm. The primary objective of this position is to consistently identify, prioritize, and mitigate risks related to application security in an effective manner.

Responsibilities :

  • Lead application security reviews and threat modeling, including code review and dynamic testing.
  • Own and perform application security vulnerability management.
  • Lead product and development teams in application security.
  • Lead development of automated security testing to validate that secure coding best practices are being used.
  • Guide and advise product development teams as SMEs in the area of application security.
  • Work closely with developers to help improve the security of their products and services, as well as designing technical solutions to address security weaknesses, and working with relevant stakeholders to implement them.
  • Serve as the liaison between management and development resources for matters pertaining to application security initiatives.
  • Serve as the point of contact regarding overall application security program process.
  • Interact with development personnel, management, consultants, and other company personnel to proactively and reactively maintain security risk objectives.
  • Collaborate in the creation, maintenance of IT control matrices and IT process documentation for various compliance requirements (PCI DSS, NIST CSF, Enterprise Risk & Security and Operations, Applications, and ITGC procedures).

Qualifications :

This role has privileged access to highly sensitive information, intellectual property, legal matters, and complex business scenarios. The successful candidate has :

  • Bachelor's in Computer Science, Information Technology or related is preferred
  • 5+ years of application security experience
  • Hands-on experience across SDLC activities such as threat modeling, secure code review, vulnerability management, and penetration testing
  • Certifications such as CISSP, CSSLP, CEH, OSCP, or GIAC preferred
  • Upholds strong ethics when handling sensitive and confidential information.
  • Experience analyzing system services, spotting issues in code, networks and applications from a security perspective, has troubleshooting skills to recognize security issues that appear under new threat scenarios.
  • Demonstrated knowledge in resolving vulnerabilities in various programming languages including .net, JavaScript, and Python.
  • Demonstrated knowledge and ability to deploy tools, methodologies, and controls to reduce application security risk.
  • Possesses strong decision-making capabilities and an ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
  • Foundational knowledge of deploying and securing SaaS applications and cloud environments
  • Personal Skills

  • Optimistic, persistently driving for the positive outcome
  • Team player; collaborative and can work independently.
  • Excellent coordination and orchestration abilities
  • Strong work ethic, interpersonal skills, time management, planning and execution skills
  • Resourceful, collaborative, 'out of the box' thinking
  • Demonstrates a personal code of ethics, integrity, and trust
  • Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment
  • Efficient communications skills (written / verbal) and interpersonal savvy
  • Possess a good sense of self and a strong, approachable personal presence.
  • Possess the determination to get results without harm, provide transparent feedback, and prioritize a positive outcome.
  • Base salary is one component of total compensation. Employees may also be eligible for an annual bonus or commission. Some roles may also be eligible for overtime pay. The above represents the expected base compensation range for this job requisition. Ultimately, in determining your pay, we'll consider many factors including, but not limited to, skills, experience, qualifications, geographic location, and other job-related factors.

    Base Compensation Range

    $145,000—$170,000 USD

    InvoiceCloud is an Equal Opportunity Employer.

    InvoiceCloud provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

    This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

    If you have a disability under the Americans with Disabilities Act or similar law, or you require a religious accommodation, and you wish to discuss potential accommodations related to applying for employment at our company, please contact jobs@invoicecloud.com.

    Click here to review InvoiceCloud's Job Applicant Privacy Policy.

    To all recruitment agencies :  InvoiceCloud does not accept agency resumes. Please do not forward resumes to our job's alias, employees, or any other organization location. Invoice Cloud is not responsible for any fees related to unsolicited resumes.

    Create a job alert for this search

    Application Security Engineer • Boston, MA, US

    Related jobs
    • Promoted
    Security Engineer

    Security Engineer

    ThriveFoxborough, MA, US
    Full-time
    Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer...Show moreLast updated: 11 days ago
    • Promoted
    Information Systems Security Engineer (ISSE)

    Information Systems Security Engineer (ISSE)

    STRWoburn, MA, US
    Full-time
    The Security team at STR is comprised of highly skilled professionals who are responsible for maintaining compliance with Government protocol and directives. The Classified Cybersecurity (CCS) team ...Show moreLast updated: 18 days ago
    • Promoted
    Information System Security Eng (ISSE) III

    Information System Security Eng (ISSE) III

    Global Resource Solutions, Inc.North Lexington, MA, US
    Full-time
    Global Resource Solutions, Inc.GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Information System Security Engineer III.The Information Sy...Show moreLast updated: 30+ days ago
    • Promoted
    Security Design Engineer

    Security Design Engineer

    ADRM CareersWoburn, MA, US
    Full-time
    ADRM is a leading physical security consulting firm with a bold vision to be the most trusted security firm in the industry. Our mission is to disrupt the security landscape, drive change, and creat...Show moreLast updated: 1 day ago
    • Promoted
    Information System Security Engineer

    Information System Security Engineer

    Iron MountainBoston, MA, United States
    Full-time
    At Iron Mountain we know that work, when done well, makes a positive impact for our customers, our employees, and our planet. We provide expert, sustainable solutions in records and information mana...Show moreLast updated: 3 days ago
    • Promoted
    Senior Principal Security Engineer

    Senior Principal Security Engineer

    Red Hat, Inc.Boston, MA, United States
    Full-time +1
    The Red Hat Emerging Technologies team within the Office of the CTO is looking for a Senior Principal Software Engineer for security and AI safety related innovation. In this role, you will be invol...Show moreLast updated: 16 days ago
    • Promoted
    Senior Embedded Security Engineer

    Senior Embedded Security Engineer

    Webster & Webster AssociatesBoston, MA, United States
    Full-time
    Webster & Webster Associates has been engaged by a company at the forefront of embedded technology to identify an accomplished Senior Embedded Security Engineer. This role offers a unique opportunit...Show moreLast updated: 30+ days ago
    • Promoted
    Information Assurance (IA) System Security Engineer III

    Information Assurance (IA) System Security Engineer III

    gTANGIBLE CorporationNorth Lexington, MA, US
    Full-time
    TANGIBLE Corporation (gTC), www.S corporation and a registered Government contractor that provides services and solutions in : . Professional, Administrative, and Management Support.Mission and Warfig...Show moreLast updated: 30+ days ago
    • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    VeracodeBurlington, MA, US
    Full-time
    Looking for an innovative, high-growth, multi-award-winning company in one of the hottest segments of the security market? Look no further than Veracode!. Veracode is a global leader in Appl...Show moreLast updated: 12 days ago
    Security Engineer

    Security Engineer

    Lever Demo - IS OpportunitiesBoston, Massachusetts, United States, 02108
    Full-time
    PLEASE READ : these jobs are testing jobs of Lever's testing environment - please do not apply for this job.Lever was founded ten years ago to tackle the most strategic challenge that companies face...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Software Engineer (PKI & Security)

    Software Engineer (PKI & Security)

    zeroRISCBoston, MA, US
    Full-time
    RISC is redefining chip security and supply chain integrity by empowering device owners and operators in crucial sectors like silicon production, IoT, and critical infrastructure with full device o...Show moreLast updated: 20 hours ago
    • Promoted
    Security Architect - Onsite - Boston, MA - Direct Client - JOBID639

    Security Architect - Onsite - Boston, MA - Direct Client - JOBID639

    Outcome Logix ( A Tech 50 Finalist company 2022, by Pittsburgh Technology Council )Boston, MA, United States
    Full-time
    Security Architect - Exp in New Relic, OWASP, Burp Suite - Onsite - Boston, MA - Direct Client - JOBID639.Independently analyze and respond to bot attacks in real-time, ensuring minimal disruption ...Show moreLast updated: 14 days ago
    • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    Robert HalfBoston, MA, US
    Full-time
    We are looking for a talented Cyber Security Engineer to join our team in Boston, Massachusetts.This role requires a proactive individual with strong technical expertise to design, implement, and m...Show moreLast updated: 10 days ago
    • Promoted
    Senior Microelectronics Assembly Engineer

    Senior Microelectronics Assembly Engineer

    RaytheonAndover, MA, US
    Full-time
    MA112 : Andover MA 358 Lowell St Dukes 358 Lowell Street Dukes, Andover, MA, 01810 USA.Person, or Immigration Status Requirements : . The ability to obtain and maintain a U.At Raytheon, the foundation ...Show moreLast updated: 25 days ago
    • Promoted
    Security & Emergency Planning Engineer

    Security & Emergency Planning Engineer

    Trc Companies, Inc.Boston, MA, United States
    Full-time +1
    TRC has long set the bar for clients who require more than just engineering, combining science with the latest technology to devise innovative solutions that stand the test of time.From pipelines t...Show moreLast updated: 28 days ago
    • Promoted
    Telecom Security Architect

    Telecom Security Architect

    ANDREW, an Amphenol companyNashua, NH, US
    Full-time
    Join our team and help shape the future of connectivity indoors and outdoors.Together, let's push the boundaries of technology and advance sustainable networks worldwide.How You'll Help Us ...Show moreLast updated: 20 days ago
    • Promoted
    Enterprise Security Sr Analyst

    Enterprise Security Sr Analyst

    EnbridgeWaltham, MA, US
    Full-time
    Join Our Enbridge Team as an Enterprise Security Sr Analyst!.Are you ready to play a vital role in shaping and strengthening the security backbone of a dynamic organization? Then look no further as...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. Security Design Engineer

    Sr. Security Design Engineer

    ADRM CareersWoburn, MA, US
    Full-time
    ADRM is a leading physical security consulting firm with a bold vision to be the most trusted security firm in the industry. Our mission is to disrupt the security landscape, drive change, and creat...Show moreLast updated: 1 day ago