The University of Texas at Austin

Senior Application Security Engineer

The University of Texas at Austin
Apply
1 month ago

Responsibilities

  • Develop and maintain Secure Software Development Lifecycle standards for Azure-hosted applications, Adobe Experience Cloud, and other platforms.
  • Perform manual and automated secure code reviews aligned with OWASP Top 10 and CWE Top 25.
  • Integrate SAST and SCA into CI/CD pipelines and partner with developers to remediate vulnerabilities.
  • Configure and operate Burp Suite for DAST and authorized penetration testing, and use OWASP ZAP and Metasploit for application security testing.
  • Triage, prioritize, track, and coordinate vulnerability remediation through a risk-based process.
  • Assess Microsoft Azure, other cloud environments, Adobe Experience Cloud, SaaS/PaaS integrations, APIs, authentication, authorization, and data validation practices.
  • Assess security for AI/ML models, data pipelines, generative AI applications, robotics and RPA platforms, biomedical systems, and connected medical devices.
  • Support application security governance, third-party risk assessments, audits, HITRUST readiness, policies, standards, and procedures.
  • Collaborate with development, infrastructure, platform engineering, cybersecurity, clinical, research, and operational teams on threat modeling, incident response, architecture reviews, and secure delivery.
  • Communicate technical findings, security risks, recommendations, and risk assessments to technical and executive stakeholders.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field, or an equivalent combination of education and professional experience.
  • At least eight years of experience in application security, secure code review, penetration testing, or secure software development.
  • Hands-on experience with Burp Suite, OWASP ZAP, and Metasploit.
  • Experience with SAST, DAST, and SCA tools such as Checkmarx, Veracode, SonarQube, or similar platforms.
  • Experience securing Microsoft Azure and other cloud environments.
  • Experience implementing secure coding practices across programming languages and web application frameworks.
  • Knowledge of SSDLC methodologies, strong analytical and troubleshooting skills, and excellent written and verbal communication.
  • Preferred qualifications include healthcare or higher-education experience, knowledge of HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165, and experience with AI/ML security, robotics, RPA, biomedical systems, connected medical devices, QA automation, threat modeling, secure architecture reviews, and TPRM.
  • Preferred certifications include OSCP, GWAPT, CSSLP, CEH, and Microsoft Azure Security Engineer Associate (AZ-500).

Benefits

  • Hybrid work environment in Austin, Texas, with on-site collaboration as business needs require.
  • Regular staff position expected to continue, scheduled for 40 hours per week.
  • Retirement plan eligibility through the Teacher Retirement System of Texas, subject to applicable hours and duration requirements.
  • May participate in after-hours security testing, incident response, vulnerability remediation, or critical production support.
  • A criminal history background check is required for finalists.
  • Required application materials include a resume/CV, three work references, and a letter of interest.
The University of Texas at Austin

About The University of Texas at Austin

201-500 employees
Contact me