Senior Application Security Engineer

Western Governors UniversitySalt Lake, UT
11hOnsite

About The Position

The Senior IT Security Analyst uses their knowledge of current security methods and standards to gather operational information and assess and analyst tools, systems, and processes in defense of applications, systems, and networks and collaborate with Infrastructure and business teams. The Senior IT Security Analyst is a lead support role for the IT Security team. They will provide mentorship, administrative service and support for monitoring systems, security breaches, providing investigative analysis and supporting incident response plans, security awareness, risk assessments, document review, vendor risk, vulnerability management and threat hunting. They will also engage in the support of other security focused tools and services and other duties as assigned. In addition, they may be asked to assist with risk assessments, forensics analysis, data collection, user training and other security related tasks. You’ll collaborate on security-focused tools and services while helping shape security documentation and standards. As a Senior Application Security Engineer, you will play a critical role in strengthening WGU’s security posture by reviewing access requests, guiding vulnerability remediation, and contributing to security policies and standards. Your expertise will help ensure our applications and systems remain secure, resilient, and aligned with best practices. You will safeguard systems and applications by identifying, analyzing, and mitigating security vulnerabilities throughout the full software development lifecycle (SDLC).

Requirements

  • Bachelor’s degree in a related field or equivalent experience.
  • 5+ years of information security experience.
  • Meaningful experience in software development, including proficiency in languages such as Python, Java, JavaScript, Go, C/C++, etc.
  • Security Knowledge: In-depth knowledge of OWASP Top 10, web application security, API security, and secure architecture principles.
  • Strong understanding of SDLC processes
  • Comfort with CLI and experience using open-source security tools (e.g., Kali, Nessus, Burp, NMap, Metasploit, Wireshark).
  • Excellent written and verbal communication skills, with the ability to simplify technical details for executive audiences.

Nice To Haves

  • Security certifications such as CISSP, CSSLP, OSCP, CEH, or similar.
  • Experience with cloud infrastructure security.
  • Familiarity with tools like Burp Suite, Snyk, Checkmarx, or similar SAST/DAST tools.

Responsibilities

  • Analyze source code to identify security flaws such as injection flaws and broken authentication.
  • Oversee vulnerability scanning of applications and APIs.
  • Perform threat modeling to identify potential attack vectors and security weaknesses during system design
  • Perform architecture reviews and create security documentation for new projects
  • Build, configure, and maintain application security tools (e.b., SAST, DAST, IAST, SCA) and integrate them into CI/CD pipelines
  • Collaborate with engineering teams to prioritize and fix security vulnerabilities.
  • Educate developers on secure coding practices and emerging threats.
  • Assess user access to software-related systems to ensure least-privilege access and provide appropriate risk mitigation.
  • Contribute to the development and improvement of security policies, standards, and procedures.
  • Identify gaps and help develop standards, guidelines, and procedures to strengthen WGU’s security framework.

Benefits

  • Comprehensive healthcare
  • HSA and FSA options
  • Life and disability insurance
  • Legal assistance and identity protection
  • Retirement savings plan
  • Wellbeing programs
  • Discounted WGU tuition for you and your family
  • Flexible PTO and Sick time
  • 11 paid holidays
  • Additional paid leaves, including parental leave
  • bonuses; medical, dental, vision, telehealth and mental healthcare; health savings account and flexible spending account; basic and voluntary life insurance; disability coverage; accident, critical illness and hospital indemnity supplemental coverages; legal and identity theft coverage; retirement savings plan; wellbeing program; discounted WGU tuition; and flexible paid time off for rest and relaxation with no need for accrual, flexible paid sick time with no need for accrual, 11 paid holidays, and other paid leaves, including up to 12 weeks of parental leave
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service