Unknown Company

Application Security Engineer

Remote • Posted 4 days ago
Remote Contract Computer and Mathematical Occupations
Application Security Engineer

Client: Securian Financial

Location: Remote - Preferrably local to St. Paul, MN (Will consider A+ candidates from permissible locations). The manager sees value in being able to come onsite, but he is open to considering fully remote candidates

Permissible Locations: Alabama, Iowa, Nebraska, Tennessee, Alaska, Kansas, New Mexico (except San Bernalillo County), Utah, Arizona, Kentucky, North Carolina, West Virginia, Arkansas, Louisiana, North Dakota, Wisconsin, Florida, Minnesota, Oklahoma, Wyoming, Georgia, Mississippi, South Carolina, Idaho, Missouri, South Dakota, Indiana, Montana, Texas (except for Dallas, Austin & San Antonio)

Contract: May 1, 2023 - Aug 31, 2023 (4 months) This role is temporary to help the team with a surge in workload, as well as to bridge the gap while an FTE role is filled through our Talent Acquisition team. It is possible this role could be extended briefly until the FTE role is filled.

Interview Process: One & Done

The manager shared that the interview will likely be two hours in length and will include himself as well as an individual on his team that will be asking detailed technical questions. He prefers to get it done in one go vs having multiple interviews.

MUST HAVE:

  • 6+ years of coding experience with Java + Spring ecosystem is required
  • A proven ability to communicate effectively and regularly with internal and external stakeholders relating to incidents, problems, changes, and maintenance
  • DevOps pipeline experience related to the automation of application testing, delivery, and infrastructure as code (e.g., GitHub, Gradle, Puppet, Terraform, AWS CloudFormation)
  • Experience with Authentication and Authorization, JSON Signing and Validation, Encryption
  • Experience with AWS Cloud resources including EKS
  • Proven analytical, problem solving, and collaboration skills
  • Strong security aptitude and an ability to learn new technologies quickly

Position Summary: This role will focus on key cybersecurity technologies that support application development and application delivery; engineering security solutions in the DevOps pipeline; and designs to ensure security is built into the application solution and incorporated throughout the entire application development and deployment lifecycle.

Some of the things you’ll be doing:

  • Planning, implementing, and supporting key security controls for the application delivery pipeline
  • Designing processes, tools, and techniques to support security for the system/application lifecycle, while engaging infrastructure and application development teams
  • Planning, designing, and implementing solutions that integrate security technologies and processes that support automation
  • Supporting / coding custom Java and Python applications
  • Supporting infrastructure on AWS
  • Leveraging automation to implement and manage security solutions that support continuous integration/continuous delivery and security as code (i.e., DevSecOps)
  • Acting as a champion of security knowledge in all initiatives that involve application development efforts
  • Participating as a member of the Agile communities that support product delivery
  • Documenting and ensuring rigorous change and configuration management across all technologies and services

What skills and experiences are we looking for in a team member?

  • Prefer principal engineer or similar qualification, but still hands-on technical
  • 6+ years of coding experience with Java + Spring ecosystem is required
  • DevOps pipeline experience related to the automation of application testing, delivery, and infrastructure as code (e.g., GitHub, Gradle, Puppet, Terraform, AWS CloudFormation)
  • Experience with AWS Cloud resources including EKS
  • Experience with Authentication and Authorization, JSON Signing and Validation, Encryption
  • Familiarity with various application and code scanning technologies – SAST, DAST, SCA
  • Experience logging, identifying, tracking, and resolving cybersecurity vulnerabilities
  • Strong security aptitude and an ability to learn new technologies quickly
  • Proven analytical, problem solving, and collaboration skills
  • A proven ability to communicate effectively and regularly with internal and external stakeholders relating to incidents, problems, changes, and maintenance

Although not necessary, here are some experiences that would be considered a bonus.

Someone who has:

  • Worked closely with security architects to develop service and technology roadmaps
  • Identified and recommended new services and solutions
  • Defined cybersecurity requirements, standards, best practices, and procedures
  • Worked with vendor support to continuously improve product implementations, integrations, and utilization
  • Familiarity with cybersecurity and risk management frameworks like NIST CSF, ISO 27001, CIS and OWASP to better understand corporate policies and regulatory mandates
  • Communicated effectively and regularly with internal and external customers relating to incidents, problems, changes, and maintenance
  • Experience troubleshooting complex systems, remediating issues, and taking steps to prevent recurring issues.

Application Security Engineer in Remote at Unknown Company

This position is listed as contract and able to be worked remotely.

Back to Job Search