Application Security Engineer II
Application Security
Cloud Platforms
Cybersecurity Tools
Data Security
Dynamic Application Security Testing
Facilities Management
Information Security
InfoSec
Risk Management
Security
Security Automation
Security Operations
Security Standards
Security Testing
Software Security
Static Application Security Testing
Web Application Firewall
Job Description
American Specialty Health Incorporated is hiring an Application Security Engineer II to strengthen application security, regulatory compliance, and the organization’s cyber risk reduction efforts.
Responsibilities
- Perform day-to-day information security functions.
- Support documentation of improvements, including automation, for information security solutions in alignment with DevSecOps activities.
- Deploy and/or act as product owner for at least one product within the application security stack.
- Assist with administration of security-related systems, including security and compliance testing software, web application firewalls (WAF), open source software, attack simulation, and vulnerability management.
- Coordinate security issue identification and remediation efforts between ASH scrum teams.
- Serve as a point of contact for scrum teams regarding vulnerabilities and remediation options.
- Maintain current documentation for technical controls, processes, and procedures.
- Participate in incident response, security testing, penetration testing, and red teaming activities.
- Research and communicate current information security trends and evolving threat environments.
- Provide availability for after-hours work and occasional travel as needed.
- Complete other assigned duties.
- Comply with all policies and standards.
Requirements
- Bachelor’s Degree in an IT-related field, or relevant work experience; if using equivalent experience, a high school diploma is required.
- 5+ years in software development with a security focus, including systems/software security testing and/or security administration.
- High proficiency in programming/scripting automations across languages and platforms, including consuming and processing common API results.
- Medium proficiency providing security guidance and implementation steps to software development teams with limited oversight from a security supervisor.
- Medium proficiency implementing security technologies and solutions within the application security suite.
- High proficiency in web application vulnerabilities, OWASP recommendations, and mitigation strategies.
- Medium proficiency understanding network and software architectures and design.
- High proficiency with proxy tools such as BurpSuite or zap for manual validation of application security findings.
- High proficiency in end-to-end application testing covering API, logic flows, database, GraphQL, Windows networks/resources, Linux applications, and Azure cloud.
- High proficiency knowledge of static code analysis tools, including their limitations and pipeline integrations/actions.
- Medium proficiency with WAF technology setups and common limitations, plus understanding of runtime protection concepts and implementation.
Technologies
- DevSecOps
- Web application firewalls (WAF)
- Open source software
- Attack simulation
- Vulnerability management
- OWASP
- BurpSuite
- zap
- API
- GraphQL
- Static code analysis tools
- Runtime Protection
- Azure cloud
Remote Worker Guidelines
- Trained remotely; must be able to work from home (WFH) in a designated work area using company-provided technology equipment.
- Must have a stable Internet connection to participate by video in online meetings over a reliable network.
- Internet connection must meet a minimum of 50 Mbps down / 10 Mbps up.
- 100 Mbps down / 20 Mbps up is recommended for higher quality video meetings.
Core Competencies
- Ability to interact positively and respectfully, building and maintaining cooperative working relationships.
- Excellent customer service mindset for internal and external customer needs and expectations.
- Strong listening and interpersonal communication skills to identify critical competencies based on success factors and organizational environment.
- Ability to organize, prioritize, multi-task, and manage time effectively.
- Accuracy and productivity in a changing environment with frequent interruptions.
- Ability to analyze information, problems, issues, situations, and procedures to develop effective solutions.
- Ability to exercise strict confidentiality in all matters.
Mobility and Physical Requirements
- Primarily sedentary; able to sit for long periods.
- Ability to see, speak, and hear other personnel/objects.
- Ability to communicate verbally and in writing.
- Ability to travel within and around the facility or within the WFH environment.
- Capable of using a telephone, computer keyboard, and mouse.
- Ability to lift up to 10 lbs.
Environmental Conditions
- Work-from-home (WFH) environment.
Location: Remote (Remote)
Compensation: USD 89,300 - 120,000 per year