Application Security Engineer
Intermedia Intelligent Communications5 months ago
Remote, United KingdomMid Level / Senior
Responsibilities
- Perform design and architecture reviews for new features and recommend security requirements.
- Advise engineering and DevOps teams on application security features, secure coding, and SDLC practices.
- Use static and dynamic security scanning tools, review findings, and coordinate remediation.
- Perform ongoing manual application security assessments.
- Review external penetration-test results and communicate recommended fixes to development teams.
- Provide on-demand application security support and drive process improvements.
- Vet and intake defects submitted by third-party security researchers through the Bug Bounty program.
Requirements
- Require 3–5 years of experience in application security.
- Require a bachelor’s or master’s degree in a related field.
- Know secure coding best practices and standards such as OWASP and apply them across programming languages.
- Have familiarity with SDLC and DevSecOps and hands-on implementation experience.
- Have knowledge or hands-on experience identifying AI threats in security environments.
- Have experience with static and dynamic security scanning tools such as BurpSuite, ZAP, and Snyk.
- Python programming experience is preferred.
- Be able to explain application security threats and mitigation options to developers and project managers.
- Have strong written and verbal English communication skills.
- Have experience or knowledge securing applications on AWS and Azure and in Docker and Kubernetes environments.
- Participation in CTF challenges and bug-bounty programs is expected or valued.