Application Security Engineer II

Federal Home Loan Bank of Des MoinesDes Moines, IA
$102,210 - $121,374Hybrid

About The Position

The Application Security Engineer II serves as the technical subject matter expert for application security, partnering with software development and technology teams to embed security throughout the Software Development Life Cycle (SDLC). This role performs application security assessments, secure design reviews, DevSecOps initiatives, vulnerability management, and secure coding practices while helping developers deliver secure, resilient applications that protect the organization's information assets and support regulatory compliance.

Requirements

  • 3-5 years of experience in Application Security, Information Security, DevSecOps, or a related field.
  • Experience performing application security assessments and validating remediation efforts.
  • Experience working with software development teams throughout the SDLC.
  • Experience with development and security tooling leveraged in a Secure SDLC (such as code scanning, git, pipeline automation tools. etc.)
  • Experience reviewing vulnerabilities and providing remediation guidance.
  • Knowledge of common web application vulnerabilities (OWASP Top 10).
  • Familiarity with secure authentication, authorization, session management, and encryption principles.
  • Working knowledge of one programming or scripting language (Python, Java, C#, JavaScript, PowerShell, etc.).
  • Understanding of REST APIs and modern web application architectures.
  • Understanding of container technologies (Docker/Kubernetes), security concepts, and security tooling.
  • Familiarity with Infrastructure as Code concepts.
  • Strong written and verbal communication.
  • Ability to explain technical security risks to non-security stakeholders.
  • Strong analytical and problem-solving skills.
  • Ability to manage multiple projects simultaneously.
  • Self-directed with strong organizational skills.

Nice To Haves

  • Bachelor’s or master’s degree in computer science, Cybersecurity, Information Systems, Software Engineering, or a related technical discipline.
  • Experience implementing DevSecOps practices.
  • Experience developing custom security automation.
  • Experience administering application security tooling.
  • Experience performing secure code reviews.
  • Experience integrating security into CI/CD pipelines.
  • Experience building developer security training programs.
  • Experience with threat modeling methodologies.
  • Experience in Agile development environments.
  • Experience supporting cloud-native applications (Azure, AWS, GCP).
  • Working knowledge of one or more of the following: Web Application Firewalls (WAF). API Security platforms, Secrets Management, Kubernetes security, Supply Chai, Security (SBOM, dependency management), Software composition analysis, Threat modeling (STRIDE, PASTA), OWASP ASVS, OWASP SAMM, OWASP API Security Top 10, Secure SDLC maturity frameworks
  • Certifications CSSLP, GWAPT, GWEB, OSCP, CISSP, Security+, Azure/AWS security certifications

Responsibilities

  • Administer code and pipeline security tooling (SAST, DAST, SCA, etc.) as well as container security tooling (image runtime security, vulnerability assessments, etc.).
  • Maintain and enhance secure code training program.
  • Provide information security recommendations for code repository and development pipeline implementations.
  • Administer and secure enterprise source code repositories.
  • Integrate and automate security controls into CI/CD pipelines and developer workflows.
  • Partner with stakeholders to prioritize highest risk issues for remediation, disseminate the information and monitor progress for completion.
  • Serve as a point of contact with application development stakeholders to answer questions, provide security guidance, and foster a strong relationship between departments.
  • Define processes ensuring third party libraries originate from trusted, approved repositories
  • Secure Infrastructure as Code deployments to ensure successful system implementations.
  • Implement automated security scanning of IaC templates.
  • Identify architectural security risks early in the software development lifecycle
  • Review application architecture and solution designs for security risks.
  • Provide security guidance during application design and planning phases.
  • Contribute security best practice for Bank initiatives that involve updating or creating applications, pipelines, and/or repositories.
  • Assist in detection engineering/refinement to enable detection, prevention and response to incidents in development environments, pipelines, and developed applications.
  • Create scripts or tooling to improve application security processes.
  • Respond to security alerts relating to development environments, pipeline events, and application behavior.
  • Provide security best practice on code reviews where sensitive components of an application were changed or impacted.
  • Generate metrics demonstrating risks and remediation progress.
  • Continuously learn about emerging technologies, their risks, and how to securely leverage them.
  • Develop proposals and implement new tools and processes to mature the bank’s security program.
  • Advise and assist with operational security and response to information security incidents.
  • Provide information security requirement input in support of project initiatives.
  • Create, develop, implement, and maintain security standards, procedures, and guidelines to mitigate risk in the Bank's information security posture (internal/external).
  • Assist with information security strategies and organizational governance. Communicate security strategies and framework to staff, partners, and other stakeholders.
  • Promote security awareness through Bank-wide communication of policies and security threats.
  • Respond and investigate cybersecurity incidents, collect, and analyze information from multiple event sources and internal and external sources.
  • Examine incidents that may be related to ransomware, host compromise, account compromise, phishing, anomalous user behavior, third parties and data leakage.
  • Monitor for incidents with endpoints, databases, applications, networking, mobile and cloud services.
  • Monitor for vulnerabilities within applications, endpoints, databases, networking, and mobile and cloud services.
  • Collaborate as a purple team with colleagues in offense, defense, operators, threat intelligence and risk management roles.
  • Recommend tactical options to reduce attack surface, containment alternatives and impede attackers.
  • Monitor departmental internal controls and regulatory issues.
  • Other duties and projects as assigned.

Benefits

  • 11 paid holidays
  • 5 weeks of PTO
  • 401(k) match (100% of the first 6%)
  • 4% non-discretionary 401(k) contribution
  • Annual incentive plan eligibility
  • Hybrid work schedule eligibility
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service