Search jobs > Washington, DC > Application security

Application Security Engineer, Mobile

WarnerMedia Services, LLC
DC Washington 820 1st Street NE
$68.9K-$128K a year
Full-time

Who We Are

When we say, the stuff dreams are made of, we’re not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth.

Behind WBD’s vast portfolio of iconic content and beloved brands, are the bringing our characters to life, the bringing them to your living rooms and the creating what’s next

From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves.

Here you are supported, here you are celebrated, here you can thrive.

The Job

As an Application Security Engineer, you will be an important member of the Warner Bros. Discovery Global Information and Content Security (GICS) team.

This is a key role that will be focused on application security for Mobile Applications - native, native mobile, hybrid, etc.

The Sr. Application Security Engineer will be a valued partner to development and engineering teams to ensure secure architectures, patterns, and solutions are created and maintained.

This person will work closely with WBD’s product teams and will build relationships with engineering groups to support effective security solutions for our products.

Operations

  • Work collaboratively and proactively across the organization with Product / Application Teams on AppSec initiatives
  • Work collaboratively and proactively to grow the security culture across the organization
  • Be creative and solve problems with solutions that can scale
  • Maintain knowledge of current and emerging secure mobile application technologies / products / trends

Technical

  • Build, maintain, and utilize security tools for the Application Security program
  • Collaborate with development teams to ensure secure coding best practices are followed
  • Identify and define mobile application security requirements and security baselines
  • Perform security and risk assessments for consumer-facing mobile, native, or applications
  • Actively and continuously share role-specific knowledge with team members and product teams
  • Stay up to date with the latest application security threats, vulnerabilities, and exploits.

The Essentials

  • Strong understanding of application security standards and practices, such as the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Security Testing Guide (MSTG)
  • Proven experience building tools and automation to support an Application Security team
  • Strong understanding of software development and mobile development methodologies and secure coding practices
  • Strong understanding of the SDLC and CI / CD pipelines
  • Experience with developing iOS and Android mobile applications
  • Experience reading and comprehending code, discerning business logic, and identifying security flaws in mobile-relevant languages, such as Swift, Objective-C, Kotlin, Java, JavaScript, and TypeScript.
  • Understanding of common mobile application authentication and encryption methods, including OAuth and PKI
  • Understanding of protocol and network analysis using mitmproxy and Wireshark
  • Understanding of platform-specific security features and best practices, such as Apple's App Transport Security, Android's Network Security Configuration, and Samsung Knox.
  • Familiarity with platform-specific development environments, SDKs, and tools, such as Xcode for iOS, Android Studio for Android, and Samsung's Tizen Studio.
  • Hands-on experience working with DevOps and Agile-driven product teams
  • A strong desire to help engineering teams build consumer applications securely
  • Excellent written and verbal communication skills

The Nice to Haves

  • Knowledge of cloud architecture and security principles
  • Bachelor’s degree in IT, Computer Science, or Information Security preferred.
  • ISC2 CSSLP, GIAC (GMOB, GWEB, GCSA), or other Security Certifications

How We Get Things Done

This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done.

You can find them at along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.

The Legal Bits

In compliance with local law, we are disclosing the compensation, or a range thereof, for roles in locations where legally required.

Actual salaries will vary based on several factors, including but not limited to external market data, internal equity, location, skill set, experience, and / or performance.

Base pay is just one component of Warner Bros. Discovery’s total compensation package for employees. Pay Range : $68,904.

00 - $127,964.00 salary per year. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards.

In addition, Warner Bros. Discovery provides a variety of benefits to employees, including health insurance coverage, an employee wellness program, life and disability insurance, a retirement savings plan, paid holidays and sick time and vacation.

Warner Bros. Discovery embraces the opportunity to build a workforce that reflects the diversity of our society and the world around us.

Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.

30+ days ago
Related jobs
Promoted
VirtualVocations
Washington, District of Columbia

A company is looking for a Senior Application Security Engineer. ...

Promoted
TalentRemedy
Washington, District of Columbia

Development Operations, Software Engineering, Application Security and/or Information Security disciplines. Application Security Engineer. This individual will be at the forefront of our security efforts, partnering closely with product and application developers to establish and elevate best practi...

Promoted
VirtualVocations
Washington, District of Columbia

Key Responsibilities:Supporting an enterprise Zero Trust Architecture deploymentProviding technical leadership in application security, vulnerability management, and scanningAssessing applications for vulnerabilities and conducting manual secure code reviewsRequired Qualifications:6+ years of experi...

Promoted
TalentRemedy
Washington, District of Columbia

Development Operations, Software Engineering, Application Security and/or Information Security disciplines. Application Security Engineer. This individual will be at the forefront of our security efforts, partnering closely with product and application developers to establish and elevate best practi...

Promoted
VirtualVocations
Washington, District of Columbia

Key Responsibilities:Drive strategy for the security review functionDesign and implement solutions for integrating security services into CI/CD pipelinesLead security reviews for complex systems across multiple business unitsRequired Qualifications:Proficiency in Ruby or Python programming languages...

WarnerMedia Services, LLC
Washington, District of Columbia

Strong understanding of application security standards and practices, such as the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Security Testing Guide (MSTG). This is a key role that will be focused on application security for Mobile Applications - native, native mobile,...

CoStar Group
Washington, District of Columbia

Minimum 3 years total experience in a technical role such as software engineer or security engineer with. Application security testing (DAST) through Metasploit, Burpsuite, OWASP ZAP, Acunetix, etc. Experience coordinating with application teams to drive security by design principles. A self-starter...

WarnerMedia Services, LLC
Washington, District of Columbia

Strong understanding of application security standards and practices is preferred but not mandatory, such as the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Security Testing Guide (MSTG). Build and maintain mobile applications and security tools for the Application Sec...

Blackbaud
Washington, District of Columbia
Remote

You are either a security-minded software engineer who has been building modern services using a microservice architecture in an agile development environment or a development-interested security practitioner who understands security best practices, but wants to get closer to development and enginee...

Booz Allen Hamilton
Washington, District of Columbia

Remediate application security flaws in conjunction with the application security team. Perform dynamic and static application performance testing, perform security requirements creation or generation-level threat modeling leveraging tools, including SD Elements, and perform application-level testin...