Talent.com
Application Security Engineer

Application Security Engineer

ISC2Hartford, CT, US
3 days ago
Job type
  • Full-time
Job description

Overview

Your Future. Secured. ISC2 is a force for good. As the world's leading nonprofit member organization for cybersecurity professionals, our core values - Integrity, Advocacy, Commitment, Inclusion, and Excellence - drive everything we do in support of our vision of a safe and secure cyber world. Our globally recognized, award-winning portfolio of certifications provide an independent and globally recognized endorsement of cybersecurity knowledge, skills and experience for all career levels. Our charitable arm, the Center for Cyber Safety and Education, enables ISC2 and our members to serve the public by educating the most vulnerable about cyber risks and empowering access to enter and thrive in the cyber profession. Learn more at ISC2 online and connect with us on Twitter, Facebook and LinkedIn. When you join ISC2, you'll demonstrate your commitment to an inclusive and equitable environment. Your support of the unique perspectives and experiences shared by our global cybersecurity workforce and profession will be recognized. We invite you to take an active role in helping us create a true sense of belonging across our organization - an environment of authenticity, trust, empowerment and connectedness that empowers all of our successes. Learn more.

Position Summary

The Application Security Engineer will be an integral part of the security team and will work cross-functionally with several lines of business to ensure the secure delivery of products and applications. The Application Security Engineer will be expected to attend stand-ups and strategy sessions to identify areas of risk and offer consulting on best practices. The Application Security Engineer will act as a champion and will formalize the integration of application security into our current processes and tools.

Responsibilities

The Application Security Engineer will be expected to facilitate technical design reviews, perform code analysis, offer remediation recommendations, perform manual and dynamic security testing, and document and present all findings. The Application Security Engineer will work closely with the Development, Release, and QA teams to identify and coordinate security testing, validate, test, and vet both internally and externally developed applications. As an Application Security Engineer, you will act as a DevSecOps Engineer that will be responsible for secure application delivery as well as the underlying infrastructure. The Application Security Engineer must be comfortable with securing cloud-based products in environments such as AWS, Azure and Salesforce. Additionally, this position will provide security risk assessments, create threat models and assist the team with vulnerability testing.

Additionally, this position manages the ISC2 responsible reporting program that supports the organization's secure application delivery objectives. In addition to the daily duties described, the individual will assist the security engineering team in the management of security technologies administered by the group (e.g., WAF, Firewall, IDS, and SEIM). This would be an "as needed" function, which is primarily to provide coverage for those duties when individuals on the security engineering team are out of the office for training or vacation. Additionally, the Application Security Engineer will be expected to participate in the Incident Response team and act as a Subject Matter Expert when dealing with the continuity of our operations and when responding with cyber incidents.

Conduct security assessments : Perform comprehensive security assessments of applications, including static code analysis, dynamic application testing, and penetration testing. Identify vulnerabilities, weaknesses, and potential attack vectors.

Secure code review : Review application source code to identify security flaws, such as insecure authentication mechanisms, input validation vulnerabilities, and potential injection attacks. Provide recommendations for remediation and best practices for secure coding.

Threat modeling : Collaborate with development teams to identify and assess potential threats and risks associated with the application. Use threat modeling techniques to prioritize security controls and countermeasures.

Develop and implement security controls : Design, develop, and implement security controls and countermeasures to protect applications against common security threats, such as cross-site scripting (XSS), cross-site request forgery (CSRF), and SQL injection. Implement secure coding practices and security guidelines.

Vulnerability management : Establish and maintain a vulnerability management program for applications. Track and prioritize vulnerabilities based on their severity and impact. Coordinate with development teams to ensure timely remediation of identified vulnerabilities.

Security testing automation : Develop and maintain automated security testing tools and scripts to streamline the application security testing process. Integrate security testing into the continuous integration and deployment (CI / CD) pipeline.

Security training and awareness : Conduct security training and awareness programs and determine skills training needs for development teams, promoting secure coding practices andawareness of common security vulnerabilities. Stay updated with the latest security trends, attack techniques, and best practices.

Incident response : Provide support during security incidents or breaches related to applications. Participate in incident response activities, including containment, investigation, and remediation.

Compliance and regulatory requirements : Ensure that applications adhere to relevant security compliance standards, industry regulations, and data privacy requirements (e.g., GDPR (General Data Protection Regulation), HIPAA (Health Insurance Portability and Accountability)). Collaborate with compliance teams to address any compliance-related concerns.

Security documentation and reporting : Prepare and maintain security documentation, including security policies, procedures, and guidelines. Generate periodic reports on the security posture of applications and present findings to relevant stakeholders.

Other responsibilities include

Maintain and manage all pipelines from a security perspective.

Onboard new pipelines for security tooling.

Keep pipeline diagrams up to date with current security details.

Serve as the primary SME for the DAST scanner.This includes configuration, testing, vulnerability management, and remediation oversight.

Recommend continuous improvements for the SAST scanner.

Security code release approvals

Maintain and manage the WAF, including signatures, configuration, and threat intel feeds.

Serve as the SME and provide recommendations for ongoing improvements.

Establish baseline WAF signatures for XD Prod following the Silverline migration.

Baseline WAF signatures after code releases.

Serve as the primary point of contact for vetting bug reports and managing the informed disclosure process.

Assist with attestation data gathering.

Support and assist with threat modeling.

Act as the formal backup for the threat modeling and attestation processes.

Review and approve Security Assessment Review reports as needed.

Perform other duties as required.

Behavioral Competencies

Ability to demonstrate and support the ISC2 Core Values :   Integrity, Excellence, Inclusion, Advocacy and Commitment

Function as an architect, who can conduct architecture reviews of new systems and solutions.

Serve as a builder who can build and integrate application security in our SDLC.

Act as a collaborator, who likes to engage with the team and the industry.

Serve as a team player, who will jump in and assist in other security functions as needed.

Function as a leader, who will use your knowledge and to train and guide developers and engineers.

Demonstrate a passion for application security, creative and critical thinking, strong analysis skills, the ability to work in a fast-paced environment, and have familiarity with agile, continuous integration, and continuous deployment.

Experience in securing SaaS-delivered offerings in multiple cloud environments deployed with automation & orchestration.

Qualifications

Ability to write some code, as needed, to conduct security-focused testing.

Application Experience with common testing tools such as Veracode, Fortify, Zap, Burp, and fiddler, among others.

Application Understanding of common vulnerabilities & remediation.

Application Knowledge and understanding of automation and scripting languages.

Design & code review skills.

A solid understanding of Microsoft platforms such as .NET, Windows, C#, Azure.

General Knowledge of cloud security, API (Application Programming Interface) security, and associated best practices.

Education and Work Experience

Bachelor's degree in computer science, information systems, related engineering field. Will consider a high school diploma and 10+ years of relevant work experience, as well as current additional credentials (CCSP, GDSP, etc..) in lieu of a degree.

A CISSP and CSSLP are required for this position.

8+ years of experience in Information Security.

8+ years of experience with static and dynamic analysis for coding and vulnerability identification and remediation.

5+ years of Secure Development experience.

Application Experience with implementing Secure Development Lifecycle in an agile environment.

First-hand experience with architectural reviews, application reviews, and penetration testing.

Application Experience with Continuous Integration processes, particularly with building security practices into the pipeline.

Physical and Mental Demands

Ability to travel up to 10% of time. May also include overnight travel.

Work extended hours, when necessary.

Work in an office environment using dual monitor computer screens.

Sitting for extended periods.

Equal Employment Opportunity Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic as protected by applicable law. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

Job Locations US-Remote

Posted Date 9 hours ago (11 / 19 / 2025 1 : 29 PM)

Job ID 2025-2253

# of Openings 1

Category Information Security

Create a job alert for this search

Application Security Engineer • Hartford, CT, US

Related jobs
  • Promoted
Security Engineer

Security Engineer

Zoom CorporationHartford, CT, United States
Full-time
The Security Engineer is responsible for security design and reviews across our products and services, with a specific focus on Platform services and core infrastructure components.The ideal candid...Show moreLast updated: 30+ days ago
  • Promoted
Security Engineer - Nashville or Austin Location

Security Engineer - Nashville or Austin Location

OracleHartford, CT, United States
Full-time
Responsible for the planning, design and build of security architectures; oversees the implementation of network and computer security and ensures compliance with corporate security policies and pr...Show moreLast updated: 3 days ago
  • Promoted
Application Engineer

Application Engineer

Trumpf, Inc.Farmington, CT, United States
Full-time
As a family-run, high-tech company with nearly 19,000 employees at 71 locations worldwide, we are looking for forward thinkers with unconventional ideas and drive to join our team.Our company cultu...Show moreLast updated: 30+ days ago
  • Promoted
COMBAT ENGINEER

COMBAT ENGINEER

US ArmySpringfield, Massachusetts, United States
Full-time +1
THIS POSITION REQUIRES AN ENLISTMENT IN THE U.As a Combat Engineer, you’ll work quickly and skillfully to help Soldiers navigate while on combat missions by constructing bridges, clearing barriers ...Show moreLast updated: 3 days ago
  • Promoted
CT Technologist - Marlborough

CT Technologist - Marlborough

Middlesex HealthMarlborough, CT, US
Part-time
Diagnostic Imaging - Marlborough Medical Center.Part-Time / 24 hours (This is a benefits eligible position).Using independent judgment, the. CT imaging procedures in addition to : .Assists physicians an...Show moreLast updated: 1 day ago
Implementation Engineer

Implementation Engineer

Evo SecurityShelton, CT, US
Full-time
Quick Apply
Who We Are Evo Security is transforming how small and medium-sized businesses secure their digital assets.Our innovative cybersecurity solutions empower Managed Service Providers (MSPs) to pr...Show moreLast updated: 30+ days ago
Application Engineer-Residential Roofing - Urgently Hiring!

Application Engineer-Residential Roofing - Urgently Hiring!

HenkelRocky Hill, CT, United States
Full-time
At Henkel, you’ll be part of an organization that’s shaping the future through innovation, sustainability and collaboration. With our trusted brands like Persil®, ‘all®, Loctite®, Snuggle®, and Schw...Show moreLast updated: 30+ days ago
  • Promoted
Facilities Engineer

Facilities Engineer

HowmetWinsted, CT, United States
Full-time
Winsted Indust Pk, 145 Price Rd, Winsted, CT, 06098, US.Remote Work Schedule Availability?.This position entails access to export-controlled items and employment offers are conditioned upon an appl...Show moreLast updated: 16 days ago
  • Promoted
Precision CNC Machine Operator

Precision CNC Machine Operator

HowmetWinsted, CT, United States
Full-time
Winsted Indust Pk, 145 Price Rd, Winsted, CT, 06098, US.Remote Work Schedule Availability?.This position entails access to export-controlled items and employment offers are conditioned upon an appl...Show moreLast updated: 30+ days ago
Application Engineer-Residential Roofing

Application Engineer-Residential Roofing

HenkelRocky Hill, CT, United States
Full-time
At Henkel, you’ll be part of an organization that’s shaping the future through innovation, sustainability and collaboration. With our trusted brands like Persil®, ‘all®, Loctite®, Snuggle®, and Schw...Show moreLast updated: 30+ days ago
  • Promoted
Security Engineer

Security Engineer

METAHartford, CT, United States
Full-time
Meta), formerly known as Facebook Inc.When Facebook launched in 2004, it changed the way people connect.Apps and services like Messenger, Instagram, and WhatsApp further empowered billions around t...Show moreLast updated: 13 days ago
  • Promoted
Lead Adversarial Security Engineer

Lead Adversarial Security Engineer

TrellixHartford, CT, United States
Full-time
Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show moreLast updated: 2 days ago
Application Engineer-Residential Roofing - Now Hiring!

Application Engineer-Residential Roofing - Now Hiring!

HenkelRocky Hill, CT, United States
Full-time
At Henkel, you’ll be part of an organization that’s shaping the future through innovation, sustainability and collaboration. With our trusted brands like Persil®, ‘all®, Loctite®, Snuggle®, and Schw...Show moreLast updated: 30+ days ago
  • Promoted
Application Specialist

Application Specialist

Milestone Inc.Shelton, CT, US
Full-time
Milestone is an international company that specializes in innovative sample preparation solutions used in laboratories worldwide. With over 25 years of success, Milestone is built on a sustainable o...Show moreLast updated: 3 days ago
  • Promoted
Mobile App Product Manager, Vehicle Security

Mobile App Product Manager, Vehicle Security

Ford Motor CompanyHartford, CT, United States
Full-time
We are the movers of the world and the makers of the future.We get up every day, roll up our sleeves and build a better world together. At Ford, we're all a part of something bigger than ourselve...Show moreLast updated: 3 days ago
  • Promoted
Senior Cyber Security Engineer

Senior Cyber Security Engineer

BIC USA Inc.Shelton, CT, United States
Full-time
Senior Cyber Security Engineer.For over 75 years, BIC has been creating ingeniously simple and joyful products that are a part of every heart and home. As a member of our team, you'll be a part of r...Show moreLast updated: 30+ days ago
  • Promoted
Cyber Security Manager - Diego Garcia

Cyber Security Manager - Diego Garcia

AmentumHartford, CT, United States
Full-time
Please note this position is based on Contract Award and is located on the island of Diego Garcia.Facility-Related Control System (FRCS) Cybersecurity Manager. The Contractor shall provide a FRCS Cy...Show moreLast updated: 13 days ago
  • Promoted
Lead Cybersecurity Engineer; HP NonStop Systems

Lead Cybersecurity Engineer; HP NonStop Systems

Capital OneHartford, CT, United States
Full-time +1
Lead Cybersecurity Engineer; HP NonStop Systems.In this key technical Lead Cybersecurity role, you'll be responsible for the overall security architecture, design, and configuration of the PULSE HP...Show moreLast updated: 2 days ago