
Senior Application Security Engineer
The University of Texas at Austin1 month ago
Responsibilities
- Develop and maintain Secure Software Development Lifecycle standards for Azure-hosted applications, Adobe Experience Cloud, and other platforms.
- Perform manual and automated secure code reviews aligned with OWASP Top 10 and CWE Top 25.
- Integrate SAST and SCA into CI/CD pipelines and partner with developers to remediate vulnerabilities.
- Configure and operate Burp Suite for DAST and authorized penetration testing, and use OWASP ZAP and Metasploit for application security testing.
- Triage, prioritize, track, and coordinate vulnerability remediation through a risk-based process.
- Assess Microsoft Azure, other cloud environments, Adobe Experience Cloud, SaaS/PaaS integrations, APIs, authentication, authorization, and data validation practices.
- Assess security for AI/ML models, data pipelines, generative AI applications, robotics and RPA platforms, biomedical systems, and connected medical devices.
- Support application security governance, third-party risk assessments, audits, HITRUST readiness, policies, standards, and procedures.
- Collaborate with development, infrastructure, platform engineering, cybersecurity, clinical, research, and operational teams on threat modeling, incident response, architecture reviews, and secure delivery.
- Communicate technical findings, security risks, recommendations, and risk assessments to technical and executive stakeholders.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field, or an equivalent combination of education and professional experience.
- At least eight years of experience in application security, secure code review, penetration testing, or secure software development.
- Hands-on experience with Burp Suite, OWASP ZAP, and Metasploit.
- Experience with SAST, DAST, and SCA tools such as Checkmarx, Veracode, SonarQube, or similar platforms.
- Experience securing Microsoft Azure and other cloud environments.
- Experience implementing secure coding practices across programming languages and web application frameworks.
- Knowledge of SSDLC methodologies, strong analytical and troubleshooting skills, and excellent written and verbal communication.
- Preferred qualifications include healthcare or higher-education experience, knowledge of HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165, and experience with AI/ML security, robotics, RPA, biomedical systems, connected medical devices, QA automation, threat modeling, secure architecture reviews, and TPRM.
- Preferred certifications include OSCP, GWAPT, CSSLP, CEH, and Microsoft Azure Security Engineer Associate (AZ-500).
Benefits
- Hybrid work environment in Austin, Texas, with on-site collaboration as business needs require.
- Regular staff position expected to continue, scheduled for 40 hours per week.
- Retirement plan eligibility through the Teacher Retirement System of Texas, subject to applicable hours and duration requirements.
- May participate in after-hours security testing, incident response, vulnerability remediation, or critical production support.
- A criminal history background check is required for finalists.
- Required application materials include a resume/CV, three work references, and a letter of interest.