- Company Name
- ACL Digital
- Job Title
- Senior Application Security Engineer / Security Engineer
- Job Description
-
**Job Title:** Senior Application Security Engineer
**Role Summary:**
Lead the design, testing, implementation, and ongoing management of application and infrastructure security controls in a 12‑month contract. Drive vulnerability management, incident response, and automation initiatives while collaborating with engineering, product, and operations teams to protect information assets.
**Expectations:**
- Deliver secure solutions that meet risk tolerance and compliance requirements.
- Perform continuous risk assessments, threat modeling, and penetration testing.
- Develop and maintain automated scripts for incident detection, triage, and response.
- Communicate findings and recommendations clearly to technical and non‑technical stakeholders.
- Stay current with evolving security threats, tools, and best practices.
**Key Responsibilities:**
- Design, evaluate, and deploy firewalls, IDS/IPS, encryption, and access‑control mechanisms.
- Conduct vulnerability scans, risk analyses, and security assessments of applications and environments.
- Investigate intrusion incidents, perform forensic analysis, and lead incident response activities.
- Create automation scripts (Python) to monitor, log, and remediate security events.
- Produce technical reports, test findings, and formal documentation.
- Develop and enforce corporate security policies, standards, and procedures.
- Coordinate with facilities, operations, and legal teams on physical security, disaster recovery, and regulatory compliance.
- Train staff on security awareness and best practices.
- Evaluate new security technologies and recommend improvements or purchases.
**Required Skills:**
- Proven experience as a software engineer or equivalent technical role.
- In‑depth knowledge of application security principles, OWASP Top 10, and secure coding practices.
- Hands‑on Python development and automation scripting.
- Proficiency with Git, source control, and build tools (GitHub, GitLab, Bitbucket, etc.).
- Experience configuring firewalls, IDS/IPS, and encryption solutions.
- Strong vulnerability assessment, penetration testing, and risk analysis capabilities.
- Incident response and forensic investigation skills.
- Ability to write clear technical documentation and reports.
- Excellent verbal and written communication, able to engage peers, product managers, and subject matter experts.
- Familiarity with compliance frameworks (ISO 27001, NIST, PCI‑DSS, etc.) is a plus.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Industry certifications such as CISSP, CISM, CEH, OSCP, or equivalent preferred.