About The Position | Major goals and objectives and location requirements People Inc is looking for an Application Security Engineer with a track record of innovative thinking, technical expertise, and collaboration. This role will be tasked with supporting software development teams, vulnerability management and remediation, and improving security coverage throughout the SDLC. As a valued member of the Security team, you will be responsible for helping to set technical direction, delivering technical projects, and collaborating with other groups within the organization. Hybrid 3x a week- (New York, NY) In-office Expectations: This position is hybrid in-office, with the ability to work remotely for up to 2 days per week. About The Positions Contributions: Weight % Accountabilities, Actions and Expected Measurable Results 50% - Solutions Function as a subject matter expert for security solutions within the organization’s platform. Integrate security solutions into the SDLC process. Work with development teams to improve the security of CI/CD processes by ensuring version control for source code, scanning code for vulnerabilities in the build pipeline, and ensuring public/private repositories are trusted and secure. Design and develop coding standards across infrastructure, application, and data security, building out guidelines and standards to drive a standardized set of security requirements that align with internal policies and meet external compliance/regulatory requirements. Help evolve application security functions and services. 50% - Vulnerability Assessment Prioritize, triage and remediate vulnerabilities and findings from security scans and bug bounty programs. Review security test results from vulnerability scans and penetration tests and propose appropriate remediation measures or mitigation controls, conduct a remediation plan and supervise its progress. Improve and support application security tool deployments including static analysis, dynamic testing and software composition analysis tools. Conduct security code reviews for various languages and frameworks of web and mobile applications. Identify security exposures and develop mitigation plans. Investigate and report vulnerabilities in systems and platforms. Assess the application threat landscape through threat modeling and architecture reviews. Develop metrics and reporting on the posture of the application security program.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
1,001-5,000 employees