- Company Name
- PEOPLE FORCE CONSULTING INC
- Job Title
- Senior Application Security Engineer
- Job Description
-
Job title: Senior Application Security Engineer
Role Summary: Lead the design, implementation, and continuous improvement of application security practices for a financial services client. Oversee secure code reviews, SAST/DAST, penetration testing, and incident response to maintain PCI DSS and SOC 2 compliance.
Expectations: Deliver tangible enhancements to security posture, mentor developers on secure coding, and ensure all application releases meet regulatory standards. Serve as the primary security authority for application environments with 9+ years of security experience and relevant certifications.
Key Responsibilities
- Conduct secure code reviews and static/dynamic application security testing (SAST/DAST) across Java, Python, JavaScript, R, Apex, Go, and other languages.
- Perform and coordinate penetration tests, report findings, and track remediation progress.
- Develop and evolve the application security program, establishing policies, controls, and best‑practice guidelines.
- Manage compliance with PCI DSS Level 1 and SOC 2, covering control retention, audits, and reporting.
- Respond to cybersecurity incidents, coordinating containment, analysis, and post‑incident reviews.
- Interface with engineering teams to explain security decisions and recommend mitigations.
- Evaluate and integrate security tools (e.g., Veracode, Tenable, Azure Security Center) and operating environments including UNIX/BSD/Linux, Azure Data Lakes, Windows SQL, and PostgreSQL.
Required Skills
- 9+ years in a security role with deep knowledge of web application security.
- Proficiency in coding languages: Java, Python, JavaScript, R, Apex, Go or equivalent.
- Experience with SAST/DAST tools, secure code review, and penetration testing.
- Strong reasoning around security architecture, threat modeling, and risk mitigation.
- Excellent written and verbal communication to convey complex security concepts to development teams.
- Familiarity with Azure services, Veracode, Tenable, UNIX/BSD/Linux, Azure Data Lakes, Windows SQL, PostgreSQL.
- Ability to manage and improve security processes, tools, and incident response.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Security, or related field (minimum).
- CISSP – mandatory.
- CISLP, CISM, CISA, PMP, CIPP, TOGAF, CEH – preferred.
---