Application Security Engineer, Vice President
Mitsubishi UFJ Financial Group2 hours ago
Jersey City, NJ, USAStaff+
Base Salary
$140k - $203k/yr
Responsibilities
- Conduct DAST scans with Invicti, SAST and SCA scans with Veracode, and manual authenticated testing with Burp Suite.
- Analyze scan results, identify root causes, reduce false negatives, and collaborate with developers on remediation.
- Integrate security testing into CI/CD pipelines and DevOps workflows.
- Write Java and Python code and scripts for security engineering and automation.
- Guide development teams on OWASP Top 10, SANS Top 25, secure coding, and vulnerability prevention.
- Ensure required release and periodic scans occur and findings are addressed within SLA.
- Review false positives, mitigated-by-design requests, and SDLC security tasks for DAST, SAST, and SCA.
- Maintain compliance with NIST, PCI-DSS, FFIEC, SOX, and CIS security frameworks.
- Organize security artifacts and improve security scanning automation and reporting.
- Collaborate with developers, DevOps teams, and application owners across the SDLC.
Requirements
- Bachelor’s degree in Computer Science or a closely related discipline, or an equivalent combination of formal education and experience.
- 5+ years of experience in application security, secure development, DAST, and SAST.
- Hands-on experience with DAST tools including Invicti/Netsparker, AppScan, Burp Suite, or Acunetix.
- Experience with SAST tools including Veracode and Fortify.
- Strong Java and Python development experience, with .NET experience accepted as an alternative, and the ability to write production-quality code and scripts.
- Strong knowledge of web security vulnerabilities, OWASP Top 10, SANS Top 25, and MITRE ATT&CK.
- Familiarity with SSDLC and CI/CD pipelines.
- Python, Bash, and PowerShell scripting skills for security-task automation.
- Relevant certifications such as OSCP, OSWE, GWAPT, or CEH are highly desirable.
- AI/ML security experience, including LLM application security, prompt-injection and data-leakage testing, and model or dependency supply-chain risk evaluation, is preferred.
- Cloud security experience with AWS, Azure, or Oracle Cloud is a plus.
- Strong collaboration, communication, technical reporting, analytical, and vulnerability-documentation skills.
Benefits
- Hybrid schedule requiring four days per week onsite and one day remote.
- Base pay range of $140k–$203K for New York/New Jersey, depending on qualifications and location.
- Eligibility for certain discretionary performance-based bonus or incentive compensation.
- Health and wellness benefits, retirement plans, educational assistance, and training programs.
- Income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays.