Talent.com
Application Security Engineer
Application Security EngineerISC2 • Concord, NH, US
No longer accepting applications
Application Security Engineer

Application Security Engineer

ISC2 • Concord, NH, US
6 days ago
Job type
  • Full-time
Job description

Overview

Your Future. Secured. ISC2 is a force for good. As the world's leading nonprofit member organization for cybersecurity professionals, our core values - Integrity, Advocacy, Commitment, Inclusion, and Excellence - drive everything we do in support of our vision of a safe and secure cyber world. Our globally recognized, award-winning portfolio of certifications provide an independent and globally recognized endorsement of cybersecurity knowledge, skills and experience for all career levels. Our charitable arm, the Center for Cyber Safety and Education, enables ISC2 and our members to serve the public by educating the most vulnerable about cyber risks and empowering access to enter and thrive in the cyber profession. Learn more at ISC2 online and connect with us on Twitter, Facebook and LinkedIn. When you join ISC2, you'll demonstrate your commitment to an inclusive and equitable environment. Your support of the unique perspectives and experiences shared by our global cybersecurity workforce and profession will be recognized. We invite you to take an active role in helping us create a true sense of belonging across our organization - an environment of authenticity, trust, empowerment and connectedness that empowers all of our successes. Learn more.

Position Summary

The Application Security Engineer will be an integral part of the security team and will work cross-functionally with several lines of business to ensure the secure delivery of products and applications. The Application Security Engineer will be expected to attend stand-ups and strategy sessions to identify areas of risk and offer consulting on best practices. The Application Security Engineer will act as a champion and will formalize the integration of application security into our current processes and tools.

Responsibilities

The Application Security Engineer will be expected to facilitate technical design reviews, perform code analysis, offer remediation recommendations, perform manual and dynamic security testing, and document and present all findings. The Application Security Engineer will work closely with the Development, Release, and QA teams to identify and coordinate security testing, validate, test, and vet both internally and externally developed applications. As an Application Security Engineer, you will act as a DevSecOps Engineer that will be responsible for secure application delivery as well as the underlying infrastructure. The Application Security Engineer must be comfortable with securing cloud-based products in environments such as AWS, Azure and Salesforce. Additionally, this position will provide security risk assessments, create threat models and assist the team with vulnerability testing.

Additionally, this position manages the ISC2 responsible reporting program that supports the organization's secure application delivery objectives. In addition to the daily duties described, the individual will assist the security engineering team in the management of security technologies administered by the group (e.g., WAF, Firewall, IDS, and SEIM). This would be an "as needed" function, which is primarily to provide coverage for those duties when individuals on the security engineering team are out of the office for training or vacation. Additionally, the Application Security Engineer will be expected to participate in the Incident Response team and act as a Subject Matter Expert when dealing with the continuity of our operations and when responding with cyber incidents.

Conduct security assessments : Perform comprehensive security assessments of applications, including static code analysis, dynamic application testing, and penetration testing. Identify vulnerabilities, weaknesses, and potential attack vectors.

Secure code review : Review application source code to identify security flaws, such as insecure authentication mechanisms, input validation vulnerabilities, and potential injection attacks. Provide recommendations for remediation and best practices for secure coding.

Threat modeling : Collaborate with development teams to identify and assess potential threats and risks associated with the application. Use threat modeling techniques to prioritize security controls and countermeasures.

Develop and implement security controls : Design, develop, and implement security controls and countermeasures to protect applications against common security threats, such as cross-site scripting (XSS), cross-site request forgery (CSRF), and SQL injection. Implement secure coding practices and security guidelines.

Vulnerability management : Establish and maintain a vulnerability management program for applications. Track and prioritize vulnerabilities based on their severity and impact. Coordinate with development teams to ensure timely remediation of identified vulnerabilities.

Security testing automation : Develop and maintain automated security testing tools and scripts to streamline the application security testing process. Integrate security testing into the continuous integration and deployment (CI / CD) pipeline.

Security training and awareness : Conduct security training and awareness programs and determine skills training needs for development teams, promoting secure coding practices andawareness of common security vulnerabilities. Stay updated with the latest security trends, attack techniques, and best practices.

Incident response : Provide support during security incidents or breaches related to applications. Participate in incident response activities, including containment, investigation, and remediation.

Compliance and regulatory requirements : Ensure that applications adhere to relevant security compliance standards, industry regulations, and data privacy requirements (e.g., GDPR (General Data Protection Regulation), HIPAA (Health Insurance Portability and Accountability)). Collaborate with compliance teams to address any compliance-related concerns.

Security documentation and reporting : Prepare and maintain security documentation, including security policies, procedures, and guidelines. Generate periodic reports on the security posture of applications and present findings to relevant stakeholders.

Other responsibilities include

Maintain and manage all pipelines from a security perspective.

Onboard new pipelines for security tooling.

Keep pipeline diagrams up to date with current security details.

Serve as the primary SME for the DAST scanner.This includes configuration, testing, vulnerability management, and remediation oversight.

Recommend continuous improvements for the SAST scanner.

Security code release approvals

Maintain and manage the WAF, including signatures, configuration, and threat intel feeds.

Serve as the SME and provide recommendations for ongoing improvements.

Establish baseline WAF signatures for XD Prod following the Silverline migration.

Baseline WAF signatures after code releases.

Serve as the primary point of contact for vetting bug reports and managing the informed disclosure process.

Assist with attestation data gathering.

Support and assist with threat modeling.

Act as the formal backup for the threat modeling and attestation processes.

Review and approve Security Assessment Review reports as needed.

Perform other duties as required.

Behavioral Competencies

Ability to demonstrate and support the ISC2 Core Values :   Integrity, Excellence, Inclusion, Advocacy and Commitment

Function as an architect, who can conduct architecture reviews of new systems and solutions.

Serve as a builder who can build and integrate application security in our SDLC.

Act as a collaborator, who likes to engage with the team and the industry.

Serve as a team player, who will jump in and assist in other security functions as needed.

Function as a leader, who will use your knowledge and to train and guide developers and engineers.

Demonstrate a passion for application security, creative and critical thinking, strong analysis skills, the ability to work in a fast-paced environment, and have familiarity with agile, continuous integration, and continuous deployment.

Experience in securing SaaS-delivered offerings in multiple cloud environments deployed with automation & orchestration.

Qualifications

Ability to write some code, as needed, to conduct security-focused testing.

Application Experience with common testing tools such as Veracode, Fortify, Zap, Burp, and fiddler, among others.

Application Understanding of common vulnerabilities & remediation.

Application Knowledge and understanding of automation and scripting languages.

Design & code review skills.

A solid understanding of Microsoft platforms such as .NET, Windows, C#, Azure.

General Knowledge of cloud security, API (Application Programming Interface) security, and associated best practices.

Education and Work Experience

Bachelor's degree in computer science, information systems, related engineering field. Will consider a high school diploma and 10+ years of relevant work experience, as well as current additional credentials (CCSP, GDSP, etc..) in lieu of a degree.

A CISSP and CSSLP are required for this position.

8+ years of experience in Information Security.

8+ years of experience with static and dynamic analysis for coding and vulnerability identification and remediation.

5+ years of Secure Development experience.

Application Experience with implementing Secure Development Lifecycle in an agile environment.

First-hand experience with architectural reviews, application reviews, and penetration testing.

Application Experience with Continuous Integration processes, particularly with building security practices into the pipeline.

Physical and Mental Demands

Ability to travel up to 10% of time. May also include overnight travel.

Work extended hours, when necessary.

Work in an office environment using dual monitor computer screens.

Sitting for extended periods.

Equal Employment Opportunity Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic as protected by applicable law. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

Job Locations US-Remote

Posted Date 2 days ago (11 / 19 / 2025 1 : 29 PM)

Job ID 2025-2253

# of Openings 1

Category Information Security

Create a job alert for this search

Application Security Engineer • Concord, NH, US

Related jobs
Travel Certified Surgical Technologist

Travel Certified Surgical Technologist

LanceSoft • New London, NH, US
Permanent
LanceSoft is seeking a travel Certified Surgical Technologist for a travel job in New London, New Hampshire.Job Description & Requirements. Certified Surgical Technologist.Minimum of 2 years CUR...Show more
Last updated: 30+ days ago • Promoted
Sr. Security Engineer

Sr. Security Engineer

Nutanix • Concord, NH, United States
Full-time
Hungry, Humble, Honest, with Heart.Are you a proactive and strategic Security Engineer with a passion for identity and access management, data loss prevention, and a strong ability to lead collabor...Show more
Last updated: 2 days ago • Promoted
FedRAMP Senior Cyber Engineer (Multiple Levels)

FedRAMP Senior Cyber Engineer (Multiple Levels)

Noblis • Concord, NH, United States
Full-time +1
Are you a Cyber Security professional or a Cloud Computing Engineer / Architect interested in Cyber Security? Are you looking to make an impact across the entire federal government? Do you want to he...Show more
Last updated: 30+ days ago • Promoted
Senior ServiceNow Security Operations Engineer

Senior ServiceNow Security Operations Engineer

Southern New Hampshire University • Hooksett, NH, United States
Full-time
Southern New Hampshire University is a team of innovators.Individuals who believe in progress with purpose.Since 1932, our people-centered strategy has defined us - and helped us grow a team that n...Show more
Last updated: 1 day ago • Promoted
Senior Security Engineer - Data Loss Prevention Operations

Senior Security Engineer - Data Loss Prevention Operations

Oracle • Concord, NH, United States
Full-time
Our rapidly growing team specializes in threat hunting, analyzing indicators of compromise (IOCs), investigating security incidents, managing incident responses, and conducting digital forensics ac...Show more
Last updated: 2 days ago • Promoted
Security Engineer

Security Engineer

Nutanix • Concord, NH, United States
Full-time
Hungry, Humble, Honest, with Heart.Are you a forward-thinking security professional with a passion for implementing cutting-edge technology and a strong understanding of Zero Trust principles? If s...Show more
Last updated: 13 hours ago • Promoted • New!
Director, Hyperscale Data Center Security Operations

Director, Hyperscale Data Center Security Operations

Oracle • Concord, NH, United States
Full-time
The physical security operations team is the primary interface with all clients and ensures.Oracle is now looking for a senior security professional to join our team. Oracle utilizes internal owned....Show more
Last updated: 2 days ago • Promoted
Travel Certified Surgical Technologist

Travel Certified Surgical Technologist

Nightingale Nurses - Allied • New London, NH, US
Full-time
Nightingale Nurses - Allied is seeking a travel Certified Surgical Technologist for a travel job in New London, New Hampshire. Job Description & Requirements.Certified Surgical Technologist.Show more
Last updated: 20 days ago • Promoted
Security Engineer II

Security Engineer II

Trustmark • Concord, NH, United States
Full-time
Trustmark's mission is to improve wellbeing - for everyone.It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust.Tr...Show more
Last updated: 30+ days ago • Promoted
Lead Adversarial Security Engineer

Lead Adversarial Security Engineer

Trellix • Concord, NH, United States
Full-time
Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show more
Last updated: 2 days ago • Promoted
Detection & Response Security Engineer, Threat Intelligence

Detection & Response Security Engineer, Threat Intelligence

META • Concord, NH, United States
Full-time
Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a...Show more
Last updated: 2 days ago • Promoted
Lead Cybersecurity Engineer; HP NonStop Systems

Lead Cybersecurity Engineer; HP NonStop Systems

Capital One • Concord, NH, United States
Full-time +1
Lead Cybersecurity Engineer; HP NonStop Systems.In this key technical Lead Cybersecurity role, you'll be responsible for the overall security architecture, design, and configuration of the PULSE HP...Show more
Last updated: 2 days ago • Promoted
Travel Radiology Technologist

Travel Radiology Technologist

LanceSoft • Plymouth, NH, US
Permanent
LanceSoft is seeking a travel Radiology Technologist for a travel job in Plymouth, New Hampshire.Job Description & Requirements. NH State Medical Imaging License.New Hampshire (Compact License A...Show more
Last updated: 20 days ago • Promoted
Travel CT Technologist

Travel CT Technologist

American Traveler • New London, NH, US
Full-time
American Traveler is seeking a travel CT Technologist for a travel job in New London, New Hampshire.Job Description & Requirements. American Traveler is seeking an experienced CT / X-Ray Technolog...Show more
Last updated: 30+ days ago • Promoted
Security Engineer

Security Engineer

Epic • Manchester, NH, United States
Full-time
Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.Please note that this position is based on our campus in Madison, WI, and requires relocation to the a...Show more
Last updated: 4 days ago • Promoted
Sr. Security Research Engineer

Sr. Security Research Engineer

Proofpoint • Concord, NH, United States
Full-time
We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead...Show more
Last updated: 2 days ago • Promoted
Travel Nuclear Medicine Technologist

Travel Nuclear Medicine Technologist

LanceSoft • Laconia, NH, US
Permanent
LanceSoft is seeking a travel Nuclear Medicine Technologist for a travel job in Laconia, New Hampshire.Job Description & Requirements. Up to date resume that includes years of experience in (spe...Show more
Last updated: 13 days ago • Promoted
Consulting Hardware Security Engineer

Consulting Hardware Security Engineer

Oracle • Concord, NH, United States
Full-time
The Oracle Cloud Infrastructure (OCI) team can provide you the opportunity to build and operate a suite of massive scale, integrated cloud services in a broadly distributed, multi-tenant cloud envi...Show more
Last updated: 13 hours ago • Promoted • New!