Unknown Company

Senior Security Engineer

new york, ny • Posted 5 days ago
Hybrid Full Time IT & Technology

Position: Senior Security Engineer - Application Security

Location: New York City, NY (HYBRID: 4 days a week in office)

Duration: DIRECT HIRE – FULL TIME

Summary:

We are seeking an experienced Application Security professional to protect applications, cloud infrastructure, systems, and customer data. As part of a lean security team, this individual will contribute across application security, cloud security, security operations, IT security, and compliance while helping design and implement new security solutions.

Skills/Experience Needed:

  • 4+ years of experience in application, product, or software security, or software engineering experience followed by a transition into security.
  • Strong understanding of application security vulnerabilities and attack techniques, including the OWASP Top 10 and API security risks.
  • Experience manually testing modern web applications, APIs, and distributed systems.
  • Ability to assess application architecture and source code for security weaknesses.
  • Experience integrating application security tools into modern CI/CD workflows.
  • Familiarity with SAST, DAST, secrets detection, container security, dependency scanning, and Infrastructure-as-Code scanning.
  • Understanding of authentication, authorization, session management, cryptography, secrets management, and secure API design.
  • Strong cloud security experience with AWS, Google Cloud Platform, or Azure.
  • Proficiency with modern programming languages and familiarity with generative coding tools and their security implications.
  • Experience researching, establishing, and implementing enterprise-wide security policies and guidelines

Responsibilities:

  • Develop and implement application security controls throughout the Software Development Lifecycle (SDLC).
  • Partner with engineering teams to incorporate security into architecture, design, development, testing, and deployment.
  • Perform hands-on security testing of web applications, APIs, cloud-native services, and supporting infrastructure.
  • Build and improve automated security testing within CI/CD pipelines, including static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing.
  • Evaluate application security tools, improve the quality of results, reduce false positives, and minimize developer friction.
  • Review application architecture and source code for security weaknesses.
  • Develop secure coding standards and developer-focused documentation.
  • Support vulnerability management, security investigations, incident response, and post-incident reviews.
  • Evaluate third-party applications, libraries, APIs, and integrations for security risks.
  • Ensure compliance with applicable healthcare and data-protection requirements, including HIPAA and GDPR.

#J-18808-Ljbffr

Senior Security Engineer in new york at Unknown Company

This position is listed as full time and hybrid.

Back to Job Search