Application Security Engineer
Job Description
Wawa is hiring an Application Security Engineer to run day-to-day application security operations and strengthen secure software practices across the SDLC.
Responsibilities
- Collaborate with developers and product owners to apply application security best practices throughout the software development lifecycle
- Research and communicate current and emerging application security threats plus recommended solutions
- Maintain and iterate on secure coding practices, policies, standards, and procedures
- Test applications for security threats and vulnerabilities
- Support application security vulnerability management
- Create and deliver security presentations for technical and non-technical internal audiences
- Find security design gaps in existing and proposed applications and recommend enhancements
- Identify gaps and inefficiencies in the Application Security Program and propose improvements
- Participate in and support application security reviews, penetration tests, and threat modeling
- Contribute to the direction of internal security-focused programs
- Assist with development of metrics and a reporting framework to measure program effectiveness
- Support technology security policies and standards and help ensure they apply to technology architectures
- Assist in ensuring ongoing compliance with regulatory obligations and internal policies/standards
- Provide support to the Technology Security Incident Response team during cyber incidents
- Maintain internal networks across information security, information technology, and development to align on initiatives
- Maintain external networks with industry peers, ecosystem partners, vendors, and other parties to track common trends, findings, and risks
- Act as a technical resource for business teams and IT to plan, implement, and support new and existing software
- Support IT audit and assessment activities, including annual PCI audit and IT general controls review
- Provide application security guidance for IT and business-related projects as required, and participate in security-related projects
- Work with business units to support application security engineering requirements and advocate secure development best practices
Requirements
- Minimum 2 years of experience in a complex technology environment in the application security engineering field
- Proven experience securing custom software
- Ability to work individually and in a team environment
- Ability to learn on the job; ability to track task progress effectively
- Experience working with teams of developers and product owners
- Excellent written and verbal communication, interpersonal and collaborative skills; ability to communicate application security and risk concepts to diverse audiences
- Ability to remain calm and competent in high-pressure situations
- Critical thinker with strong problem-solving skills
- Ability to manage multiple projects under strict timelines in a dynamic environment
- Ability to engage in internal security technology and security remediation projects
- Ability to understand large technology implementations spanning hundreds of physical and virtual environments
- High personal integrity; ability to handle confidential matters with appropriate judgment and maturity
- High initiative and dependability; ability to work with little supervision and adapt to change
- Ability to participate in on-call rotation (24x7x365) for information security incidents
- Advanced knowledge of containers and container security
- Solid knowledge of cloud technology and security
- Solid knowledge of Java; basic knowledge of Golang
- Basic knowledge of React and React Native
- Experience reading and writing enterprise software
- Experience preventing and remediating software security flaws in enterprise software
- Up-to-date knowledge of common security weaknesses and how to prevent/remediate
- Advanced knowledge of OWASP guidance
- Solid knowledge of web-related protocols: TCP/IP, HTTP, HTTPS, REST, etc.
- Understanding of relevant legal/regulatory requirements such as Payment Card Industry Data Security Standard
- Degree in computer science preferred or equivalent professional experience
- Professional security management certification preferred (examples listed): CISSP, CISM, GDSA, CSSLP, CEH, etc.
- Solid knowledge of security management frameworks such as Critical Security Controls, NIST 800-53, and Cybersecurity Framework
- Significant knowledge of application security concepts/technologies including SAST, DAST, SCA, IaC, cryptography, authn/authz, API security, etc.
- Strong understanding of cloud, application security, and software engineering principles
- Experience with scripting/automation (examples listed): Python, PowerShell, Unix shell, JavaScript, TypeScript, etc.
- Proven experience and strong understanding of DevSecOps and SAFE Agile working methodologies
- Ability to maintain a positive attitude by committing to new ideas, being enthusiastic, and being helpful and considerate across the organization
Technologies
- container security
- Java
- Golang
- React
- React Native
- OWASP guidance
- TCP/IP
- HTTP
- HTTPS
- REST
- Payment Card Industry Data Security Standard
- Critical Security Controls
- NIST 800-53
- Cybersecurity Framework
- SAST
- DAST
- SCA
- IaC
- cryptography
- authn/authz
- API security
- Python
- PowerShell
- Unix shell
- JavaScript
- TypeScript
- DevSecOps
- SAFE Agile
- PCI audit
- IT general controls review
Location and Experience
- Location: Media, PA (onsite)
- Minimum experience: 2 years
- Education: Degree in computer science (preferred) or equivalent professional experience