- Company Name
- Checkout.com
- Job Title
- Application Security Specialist
- Job Description
-
**Job Title**: Application Security Specialist (Junior Level)
**Role Summary**
Assist in securing the company’s software applications throughout the Secure Software Development Life Cycle (SSDLC). Work closely with engineering and product teams to embed security controls, execute static and dynamic security testing, conduct threat modelling, triage vulnerabilities, and support secure coding standards and CI/CD pipelines.
**Expectations**
- 1–3 years of experience in application security, secure software development, or related IT/security roles.
- Basic knowledge of network technologies (HTTP, TCP/IP, DNS, OSI model).
- Understanding of common software vulnerabilities and mitigation techniques.
- Basic programming skills in a mainstream language (Python, JavaScript, or Go).
- Familiarity with CI/CD pipelines, DevSecOps principles, and GitHub security features.
- Basic experience with AWS services.
- Strong documentation and communication skills, able to work with both technical and non‑technical stakeholders.
**Key Responsibilities**
- Integrate security controls into the SSDLC and maintain secure coding guidelines (OWASP Top 10, CERT).
- Run Static Application Security Testing (SAST) and Software Composition Analysis (SCA) scans; conduct API security testing.
- Support CI/CD pipelines to ensure automated security checks are effective and enforceable.
- Participate in threat modelling sessions, document threats, assess risks, and recommend mitigations.
- Perform code and system reviews to analyze security posture of products.
- Triage, prioritize, track, verify, and certify remediation of vulnerabilities from automated scans.
- Automate application security pipelines and improve existing processes.
- Collaborate with engineering teams to embed security into product design and enhance existing systems.
- Deliver security awareness training and contribute to security documentation.
**Required Skills**
- Application security fundamentals and SDLC integration.
- Network protocol basics (HTTP, TCP/IP, DNS).
- Knowledge of OWASP, common vulnerability types, and mitigation strategies.
- Programming in at least one popular language (Python, JavaScript, Go).
- CI/CD and DevSecOps understanding; familiarity with GitHub security features.
- Basic AWS, Docker/Kubernetes, or Azure/GCP knowledge (nice to have).
- Excellent documentation, assessment, and communication abilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
- Professional cybersecurity certifications (e.g., CEH, CISSP, OSCP, GSEC) are not mandatory but desirable.