Application Security Engineer
Summary
The Application Security Engineer ensures secure SDLC practices, conducts threat modeling and vulnerability assessments, and supports development teams using Java or .NET technologies in a Cloud environment.
Mission:
Ensure that the products and applications developed by the organization incorporate security principles from design to operation, promoting secure development practices, coordinating vulnerability assessments and penetration testing, technically supporting development teams in risk remediation and contributing to the continuous evolution of application security maturity.
Intended profile:
Professional with previous experience in software development and application architecture, who has evolved into application security functions. Should have the ability to interact with development, architecture, operations and corporate security teams, simultaneously acting as a technical consultant, facilitator and promoter of good practices.
The candidate should be able to understand the code, architecture and development processes, being able to directly support the analysis and resolution of identified vulnerabilities.
Responsibilities:
Define and promote Secure SDLC practices.
Integrate security requirements into the development cycle.
Participate in architecture reviews and solution design.
Conduct threat modeling sessions.
Support teams in the implementation of authentication, authorization and data protection mechanisms.
Analyze results from Pentests, Vulnerability Assessments, SAST, DAST, Dependency Scanning and Container Scanning.
Classify and prioritize vulnerabilities.
Technically support remediation.
Monitor remediation plans and their SLAs.
Define the scope of Pentests tests.
Articulate with external vendors.
Teach Secure Coding workshops.
Promote OWASP Top 10 and secure development best practices.
Integrate security controls into CI/CD pipelines.
Define application security metrics and indicators.
Key Requirements:
Solid experience in at least one of the following stacks: Java - Spring Boot; REST APIs; Maven and/or C# - .NET Framework / .NET Core; ASP.NET.
Cloud knowledge (required), with experience in real application deployments.
Working knowledge of OWASP Top 10, OWASP ASVS and Secure Coding best practices.
Experience with tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, among others.
Good communication and influence skills without hierarchical authority.
Training and mentoring skills.
Ease in working with development teams.
Nice to Have:
Frontend experience (optional, desirable): Angular (JavaScript; TypeScript).
Desirable knowledge in at least one of the main cloud platforms, preferably AWS and/or Azure.
Strong analytical skills.
Pragmatism in risk management.
