Application Security Engineer
Job Description
PACCAR is seeking an Application Security Engineer to support the IT Division’s Global Security group. The position focuses on providing security guidance across the application portfolio, with hands-on work spanning secure code review, automated security testing, vulnerability assessment, and SDLC risk analysis.
Onsite Location
Renton, WA, US (onsite)
Compensation
USD 90,000 - 141,000 per year
Role Responsibilities
- Conduct source code reviews using manual analysis and Static Application Security Testing (SAST) tools to identify vulnerabilities.
- Perform web security assessments on websites, web applications, web services, and APIs using Dynamic Application Security Testing (DAST) tools.
- Review results from automated security tools, confirm automated tests complete successfully, and identify and remove false positives from tool reports.
- Develop and review threat models to proactively surface security risks.
- Partner with development teams to support vulnerability remediation through consultation or hands-on assistance.
- Help developers understand security defects, associated risk, and define acceptable solutions to remediate issues.
- Collaborate with teams to embed secure coding practices and security tooling into CI/CD pipelines.
- Contribute to code reviews and design discussions while applying a security lens.
- Support application security controls and contribute to risk analysis of applications throughout the SDLC.
- Contribute to the creation, maintenance, and communication of PACCAR secure coding standards, guidelines, and examples.
- Assist in implementation of secure design principles aligned to organizational policies, standards, and application security patterns.
- Create technical security documents, including assessment reports and remediation guidance.
- Share application security knowledge with engineering teams through brown bags, secure coding tournaments, and developer outreach activities.
- Help improve security culture and awareness across the organization.
- Participate in security incident response when needed.
- Maintain and tune Secure SDLC tools including SAST, DAST, and Software Composition Analysis (SCA) platforms.
- Support integration of security tooling and automated security checks within CI/CD.
- Stay current with application security technologies, products, and emerging trends.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or a related field.
- 5+ years of professional experience in application or software security, including hands-on work in secure code review, vulnerability assessment, threat analysis, or secure development practices.
- Hands-on experience with application security testing tools, including DAST platforms (e.g., Burp Suite, WebInspect, OWASP ZAP) and SAST/SCA tools (e.g., Fortify, Checkmarx, SonarQube).
- Proficiency in one or more programming languages: C#, JavaScript, and/or Python.
- Strong working knowledge of web application technologies including HTTP, HTML, CSS, JavaScript.
- Expert-level understanding of the OWASP Top 10 and common web application vulnerabilities, including website security concepts such as headers, cookies, CORS, XSS, and CSRF.
- Familiarity with web authentication technologies such as OAuth and/or SAML.
- Experience with SDLC and development methodologies such as Waterfall and Agile.
- Experience with control systems including Git, GitHub, Azure DevOps.
- Experience working in a large enterprise environment.
- Experience with penetration testing or security tools (e.g., Kali Linux, Nmap).
- Familiarity with cloud environments such as Azure, AWS, or GCP.
- Certifications: CSSLP, CISSP, and CompTIA Security+.
Skills and Tools
Secure SDLC tools including SAST, DAST, and SCA; Burp Suite, WebInspect, OWASP ZAP, Fortify, Checkmarx, and SonarQube; programming languages and web technologies including C#, JavaScript, Python, HTTP, HTML, CSS; security concepts including headers, cookies, CORS, XSS, and CSRF; authentication technologies including OAuth and SAML; SDLC and development methodologies including Waterfall and Agile; Git, GitHub, Azure DevOps; penetration testing tools such as Kali Linux and Nmap; cloud environments including Azure, AWS, and GCP; and CI/CD.
Benefits
- 401k with up to a 5% company match
- Employee Stock Purchase Program (ESPP)
- Fully funded pension plan providing monthly benefits after retirement
- Comprehensive paid time off: minimum 10 paid vacation days, 12 paid holidays, and sick time (additional vacation days provided with additional seniority/years of service)
- Tuition reimbursement for continued education
- Medical, dental, and vision plans for you and your family
- Flexible spending accounts (FSA) and health savings account (HSA)
- Paid short- and long-term disability programs
- Life and accidental death and dismemberment insurance
- EAP services including wellness plans, estate planning, financial counseling, and more
Equal Opportunity and Work Authorization
- PACCAR is an Equal Opportunity Employer and a Protected Veteran/Disability employer.
- Applicants and employees for this position will not be sponsored for work authorization, including H-1B visas, now or in the future.
Additional Notice
The role salary range is $90,000 - $141,000 annually, and the position is eligible for the full range of benefit options listed above.