
10873 -Senior Applications Security Engineer - Cyber Defense
Hyundai AutoEver America1 month ago
Irvine, CA, USASenior
Base Salary
$103k - $159k/yr
Responsibilities
- Define, document, and maintain Secure SDLC policies, standards, procedures, and security controls.
- Partner with Engineering, Platform, and AppDev teams to integrate practical and scalable security requirements into development workflows.
- Develop, manage, and maintain hardened cloud container image repositories and approved image patterns.
- Define container-image security baselines covering base-image selection, hardening, patching, dependencies, and runtime security.
- Implement and integrate SAST, DAST, and open-source dependency vulnerability scanning into CI/CD pipelines.
- Tune security tools and rules to balance coverage, accuracy, and developer experience.
- Triage, prioritize, assign, track, and validate remediation of application-security findings within agreed SLAs and timelines.
- Support application-security reviews, threat modeling, secure coding guidance, vulnerability remediation, and secure release decisions.
- Contribute to continuous improvement of application-security tooling, processes, metrics, and governance.
Requirements
- 5+ years of experience in Application Security, Product Security, or Secure Software Engineering, including hands-on Secure SDLC implementation.
- Experience integrating SAST, DAST, and open-source vulnerability scanning into CI/CD pipelines.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent work experience.
- Practical experience securing containerized applications and managing hardened container images.
- Strong understanding of common application vulnerabilities, including the OWASP Top 10, modern CI/CD workflows, DevOps practices, secure coding, and build processes.
- Strong troubleshooting, stakeholder-management, collaboration, and communication skills, with professional proficiency in English.
- Preferred experience with industry-leading application-security tools for SAST, DAST, and open-source scanning.
- Preferred experience with Docker, Kubernetes, container platforms, registries, and cloud-native application environments.
- Working knowledge of application threat-modeling techniques is preferred.
- A master's degree or higher, equivalent work experience, and credentials such as CISSP, CISM, CSSLP, or GWAPT are desirable.