Role Summary
The Application Security Engineer will support the development, enhancement, and operationalization of Malcode and CBOM capabilities. The role focuses on security assessment, risk validation, remediation guidance, and automation of security processes.
Key Responsibilities
Security Engineering & Development
- Develop and enhance Malcode and CBOM capabilities.
- Implement workflow automation and process improvements.
- Integrate security tools, repositories, and supporting platforms.
- Enhance analysis and reporting capabilities.
Security Assessment & Remediation
- Analyze findings for exploitability, severity, and business impact.
- Review source code, logs, and technical artifacts.
- Identify false positives and duplicate findings.
- Validate remediation activities and conduct retesting.
- Provide remediation guidance to application teams.
Governance & Operations
- Manage vulnerability and finding lifecycle processes.
- Track remediation progress and risk disposition.
- Produce operational and management reports.
- Support governance reviews and stakeholder engagements.
Required Skills
- Application Security Testing (SAST, DAST, SCA).
- Software Composition Analysis and dependency risk management.
- Secure SDLC practices.
- Source code review and vulnerability assessment.
- Automation and scripting (Python, PowerShell, or similar).
- Security reporting and analytics.
Preferred Qualifications
- CEH, GWAPT, CSSLP, OSCP, or equivalent certifications.
- Experience with SBOM/CBOM, malware analysis, and software supply-chain security.
- Prior experience in enterprise-scale application security programs.