Remote Otter LogoRemoteOtter

Senior Application Security Engineer - Remote

Posted 1 week ago

Overview

Sagent is seeking an Experienced IS & Cyber Threat Analyst Principal Engineer to join a growing information security team responsible for securing next-generation, cloud-native financial technology systems, used by some of the largest mortgage lenders and loan servicers in Chennai India. As our Senior Application Security Engineer, you will be responsible for owning Sagent’s application security program. This role will entail delivering application security standards and solutions, driving engineering teams to evolve towards a DevSecOps model, building security automation wherever possible, and serving as formidable force for the ‘secure by default’ vision across the enterprise. This role will have abundant opportunities to challenge the “status-quo” and work with cutting-edge technologies, tools, and platforms across all 3 major cloud providers (Azure, GCP, AWS).

In Short

  • Develop and update application security standards, secure coding principles, and threat modeling processes.
  • Maintaining CI/CD integrated application security solutions, web application firewall technologies, and related.
  • Provide application security support to development teams, including reviewing and explaining application security tools and processes, providing vulnerability explanations and remediation guidance.
  • Integrate and mature application security testing and controls into different phases of teams’ development lifecycles.
  • Coordinate application security program metrics and reporting.
  • Support ongoing management of application security vulnerabilities through a centralized vulnerability tracking system and defect tracking system.
  • Develop application security training methods and mentoring of security champions.
  • Partner with third party vendors to deliver software security tools and services.
  • Coordinate and partner with third party offensive security (manual pen test) engagements.
  • Provide expert consultation on application security requirements and best practices in relation to vulnerability scanning and secure application design.
  • Partner closely on security operations tasks with cross-functional teammates in Information Security, IT, DevOps, Engineering, and Quality Assurance.
  • Engage with product owners, project managers and developers to integrate security best practices into product design.
  • Working Model: 16/5.

Requirements

  • Extensive combined hands-on experience in application security and software development.
  • Experience building, deploying, and maturing CI/CD integrated application security tools.
  • Solid understanding of web-based application technologies, web services/APIs, web-based authentication/single sign-on protocol and technologies.
  • Deep experience working with various development technologies including programming languages/frameworks supporting both backend and frontend development, source control management systems, and CI/CD tooling.
  • Ability to read and understand code at a high-level across most common programming languages, with any C#, Java, Javascript and NodeJS experience a plus.
  • Experience with application security tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Functional understanding in tooling integrations that support agile, CI/CD, and DevSecOps methodologies.
  • Fundamental understanding of major cloud providers (Azure, GCP, AWS).
  • Strong knowledge of software security risks and threats (OWASP top 10).
  • Familiarity with “secure by design” and “shift left” security principles.
  • Strong understanding of development methodologies, particularly Agile and DevOps.
  • Able to explain impact of vulnerabilities and mitigating strategies to both technical and non-technical stakeholders.
  • Capable taking ownership of the application security function, ability to work independently with minimal guidance and act as coach to other team members as necessary.

Benefits

  • Comprehensive package including Remote/Hybrid workplace options.
  • Group Medical Coverage.
  • Group Personal Accidental, Group Term Life Insurance Benefits.
  • Flexible Time Off.
  • Food@Work.
  • Career Pathing.
  • Summer Fridays.
  • Much more!

Similar Jobs:

T.T

Senior Application Security Engineer - Remote

Temporal Technologies

2 days ago

Join Temporal as a Senior Application Security Engineer to secure the development pipeline and enhance product security.

Application Security
Cybersecurity
Threat Modeling
Risk Assessment
USA
Full-time
Software Development
$160,000 - $225,000/year
Cloudflare logo

Senior Application Security Engineer - Remote

Cloudflare

4 days ago

Join Cloudflare as a Senior Application Security Engineer to help secure their products and platforms.

Application Security
Security Engineering
Threat Modeling
Code Review
Worldwide
Full-time
Software Development
Emburse logo

Senior Application Security Engineer - Remote

Emburse

1 week ago

The Senior Application Security Engineer will lead application security initiatives and work closely with engineering teams to enhance security practices.

Application Security
Secure Software Development
DevSecOps
CICD Pipelines
CA, Canada
Full-time
Software Development
Daxko logo

Senior Application Security Engineer - Remote

Daxko

1 week ago

Join Daxko as a Senior Application Security Engineer to protect applications and customer data through security best practices.

Application Security
SDLC
SAST
DAST
USA
Full-time
Software Development
$137,000 - $181,000/year
Sagent India logo

Senior Application Security Engineer - Remote

Sagent India

1 week ago

Join Sagent as a Senior Application Security Engineer to lead the application security program and drive DevSecOps practices.

Application Security
DevSecOps
Cloud-native
CI/CD
India
Full-time
DevOps / Sysadmin