
Application Security Engineer
ASX Limited2 hours ago
Sydney, AustraliaMid Level
Responsibilities
- Conduct targeted application security reviews and AI-assisted code analysis to identify exploitable vulnerabilities and structural weaknesses.
- Prioritise and drive remediation of critical and high-severity code-level vulnerabilities with engineering teams.
- Support threat modelling, secure design reviews and application security assessments.
- Provide secure coding guidance, remediation patterns and code-level recommendations.
- Contribute to pull requests where appropriate to support remediation and knowledge transfer.
- Define and embed security checkpoints, guardrails and automation within SDLC and CI/CD pipelines.
- Optimise AppSec tooling, including SAST, DAST, SCA and related security controls.
- Establish or uplift Security Champion practices and produce handover documentation, reusable patterns and enablement materials.
Requirements
- Demonstrated experience in application security, secure software engineering or hands-on vulnerability remediation.
- Strong knowledge of secure coding, common application vulnerability classes, OWASP Top 10 risks and secure design principles.
- Experience reviewing application code and partnering with engineering teams to remediate vulnerabilities.
- Practical understanding of SDLC security controls, DevSecOps practices, CI/CD security integration and automated application security testing.
- Hands-on experience with SAST, DAST, SCA, secret scanning, container security or cloud security assessment tools.
- Experience working across multiple applications, platforms or delivery teams with varying AppSec maturity.
- Ability to adapt security approaches to risk, complexity and delivery context and translate vulnerabilities into clear remediation guidance.
- Relevant security certification such as CSSLP, GWAPT, GWEB, OSWE or CISSP, or equivalent practical experience, is desirable.
- Experience in financial services, critical infrastructure or regulated technology environments is desirable.
- Exposure to AI-assisted security analysis, threat modelling, secure-by-design programs, DevOps pipelines, Java, Security Champion practices or developer mentoring is desirable.
Benefits
- Flexible working and hybrid working options are available.
- Part-time and other flexible working arrangements may be considered for roles advertised as full-time.
- Successful candidates undergo background checks, including reference and police checks.
- Candidates must be legally authorised to work permanently in Australia without restrictions.