Application Security Engineer, Information Security
Application Security
Data Security
DevSecOps
Dynamic Application Security Testing
Information Security
InfoSec
Risk Management
Secure Software Development
Security
Security Compliance
Security Standards
Security Testing
Security Testing Tools
Software Security
Static Application Security Testing
Static Code Analysis
Web Security
Job Description
Onsite in Dresher, PA, you will help strengthen Ascensus’ application security program and support scrum teams with secure development practices. This role partners across security and development leadership to advance a DevSecOps approach across the SDLC, combining security analysis with practical guidance for building, testing, and operating web and API systems with confidentiality, integrity, and availability in mind.
What you’ll do
- Protect, secure, and ensure proper handling of confidential data to prevent unauthorized access, improper transmission, and unapproved disclosure that could harm Ascensus or its clients.
- Model Ascensus’ I-Client service philosophy and core values (People Matter, Quality First, and Integrity Always®) in day-to-day actions.
- Co-develop a comprehensive, agile, and innovative DevSecOps approach for all phases of the SDLC, including identifying and managing risk.
- Provide security consultation to scrum teams, application owners, and technology teams on security controls and secure SDLC processes.
- Join sprint planning and other decision-making sessions to ensure security requirements are integrated into development practices.
- Perform application security analysis, including architecture review, data flow analysis, penetration testing support, and threat modeling.
- Build and monitor compliance with application security policies, coding standards, and security controls that support threat mitigation.
- Deploy and integrate services supporting SAST, DAST, and SCA; assist development teams with static and dynamic testing, triage findings, and provide remediation guidance.
- Support additional tasks and projects as assigned.
What you bring
- Minimum 7 years of experience in Secure Software Development and/or DevSecOps (preferred).
- Ability to define software security and privacy requirements.
- Solid understanding of threat modeling, risk, and mitigation for internal and external threats.
- Experience with system security architecture diagrams and security architecture specifications aligned to security architecture standards.
- Experience performing software security design reviews.
- Experience running security testing tools in a CI/CD pipeline, including Static and Dynamic Application Security, plus SAST/DAST and SCA.
- Hands-on experience with application testing tools such as Burp Suite, Fiddler, ZAP, Wireshark, and Metasploit.
- Experience with WAF, API Gateway, and API security tools.
- Strong knowledge of common application and API security risks, including OWASP Top 10 and SANS/CWE Top 25.
- Understanding of application, database, and network vulnerability testing principles.
- Working knowledge of Microsoft Security Development Lifecycle (SDL), OWASP SAMM, or BSIMM.
- Experience assessing secure adoption of third-party components, including open source and commercial software.
- .NET/Java experience is a plus.
- Understanding of information security frameworks such as ISO27001, NIST, CSA, and working in environments regulated against FFIEC, SEC, and/or HIPAA requirements.
- Strong understanding of authentication and authorization systems.
- Solid understanding of cryptographic standards (encryption, hashing, key management, digital signatures, etc.).
- Ability to provide vulnerability remediation guidance and mentor product development software engineers.
- Ability to translate security risks into business impact.
- Experience running or managing vulnerability assessments with automated tools (for example, Nessus, Qualys) and managing penetration testing engagements.
- Understanding of privacy regulations related to handling and protecting information.
- Experience with fraud detection and analysis as it relates to custom developed applications.
- Experience integrating automated testing tools into CI/CD pipelines.
- Experience implementing Cloud security controls following CSA or CSP best practices (Azure, AWS, etc.).
- Experience implementing and supporting security automation tools, including K8 and CSP platform configuration, hardening, and monitoring.